Lap 1: JWT authentication bypass via unverified signature
https://abdelrahmansalaheldeen.medium.com/lap-1-jwt-authentication-bypass-via-unverified-signature-8e450a7b2f59?source=rss------bug_bounty-5
https://abdelrahmansalaheldeen.medium.com/lap-1-jwt-authentication-bypass-via-unverified-signature-8e450a7b2f59?source=rss------bug_bounty-5
PortSwigger JWT attacks lap one writeup بالعربيContinue reading on Medium » (https://abdelrahmansalaheldeen.medium.com/lap-1-jwt-authentication-bypass-via-unverified-signature-8e450a7b2f59?source=rss------bug_bounty-5)
Lap 1: JWT authentication bypass via unverified signature
PortSwigger JWT attacks lap one writeup بالعربيContinue reading on Medium »
Read more...
PortSwigger JWT attacks lap one writeup بالعربيContinue reading on Medium »
Read more...
Medium
Lap 1: JWT authentication bypass via unverified signature
PortSwigger JWT attacks lap one writeup بالعربي
0-Click Mass Account Takeover via Password Reset Functionality
In the name of Allah, the Most Beneficent, the Most MercifulContinue reading on Medium »
Read more...
In the name of Allah, the Most Beneficent, the Most MercifulContinue reading on Medium »
Read more...
Medium
0-Click Mass Account Takeover via Password Reset Functionality
In the name of Allah, the Most Beneficent, the Most Merciful
0-Click Mass Account Takeover via Password Reset Functionality
https://0d-samii.medium.com/0-click-mass-account-takeover-via-password-reset-functionality-68cdf27e028d?source=rss------bug_bounty-5
https://0d-samii.medium.com/0-click-mass-account-takeover-via-password-reset-functionality-68cdf27e028d?source=rss------bug_bounty-5
In the name of Allah, the Most Beneficent, the Most MercifulContinue reading on Medium » (https://0d-samii.medium.com/0-click-mass-account-takeover-via-password-reset-functionality-68cdf27e028d?source=rss------bug_bounty-5)
How I Become Google HOF
Clickjack in Google Extension Made me Google HOFContinue reading on Medium »
Read more...
Clickjack in Google Extension Made me Google HOFContinue reading on Medium »
Read more...
Medium
How I Become Google HOF
Clickjack in Google Extension Made me Google HOF
Nmap: The Best Network Scanning Utility for Security Expert
What is Nmap?Continue reading on Medium »
Read more...
What is Nmap?Continue reading on Medium »
Read more...
Medium
Nmap: The Best Network Scanning Utility for Security Expert
What is Nmap?
Found Bugs, Got Paid, Stayed Poor: Making a Living with Bug Bounties
In recent years, bug bounties have emerged as a popular way for cybersecurity enthusiasts to earn money by finding vulnerabilities in…Continue reading on Medium »
Read more...
In recent years, bug bounties have emerged as a popular way for cybersecurity enthusiasts to earn money by finding vulnerabilities in…Continue reading on Medium »
Read more...
Medium
Found Bugs, Got Paid, Stayed Poor: Making a Living with Bug Bounties
In recent years, bug bounties have emerged as a popular way for cybersecurity enthusiasts to earn money by finding vulnerabilities in…
Discovering a Stored XSS Vulnerability on a Bug Bounty Program
Hello AppSec folks, I hope everyone is doing great! This is Anmol, also known as Nishachar or Asmodeus. Let’s dive straight into my recent…Continue reading on Medium »
Read more...
Hello AppSec folks, I hope everyone is doing great! This is Anmol, also known as Nishachar or Asmodeus. Let’s dive straight into my recent…Continue reading on Medium »
Read more...
Medium
Discovering a Stored XSS Vulnerability on a Bug Bounty Program
Hello AppSec folks, I hope everyone is doing great! This is Anmol, also known as Nishachar or Asmodeus. Let’s dive straight into my recent…
How To Stay Ahead of 99% of Bug Bounty Hunters
The bug bounty ecosystem has exploded in recent years, providing security researchers, ethical hackers, and cybersecurity enthusiasts with…Continue reading on Medium »
Read more...
The bug bounty ecosystem has exploded in recent years, providing security researchers, ethical hackers, and cybersecurity enthusiasts with…Continue reading on Medium »
Read more...
Medium
How To Stay Ahead of 99% of Bug Bounty Hunters
The bug bounty ecosystem has exploded in recent years, providing security researchers, ethical hackers, and cybersecurity enthusiasts with…
How EDR really works
https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/
submitted by /u/NagateTanikaze (https://www.reddit.com/user/NagateTanikaze)
[link] (https://blog.deeb.ch/posts/how-edr-works) [comments] (https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/)
https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/
submitted by /u/NagateTanikaze (https://www.reddit.com/user/NagateTanikaze)
[link] (https://blog.deeb.ch/posts/how-edr-works) [comments] (https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/)
Pentesting and Ethical Hacking
https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/
<!-- SC_OFF -->I am currently pursuing a course on SOC
I would like to improve my skills on Pentesting/Hacking also
Can i get to know the resources that can be used for free.
Any youtube playlist or free textbooks or anything for starting <!-- SC_ON --> submitted by /u/Fragrant-Sympathy244 (https://www.reddit.com/user/Fragrant-Sympathy244)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/)
https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/
<!-- SC_OFF -->I am currently pursuing a course on SOC
I would like to improve my skills on Pentesting/Hacking also
Can i get to know the resources that can be used for free.
Any youtube playlist or free textbooks or anything for starting <!-- SC_ON --> submitted by /u/Fragrant-Sympathy244 (https://www.reddit.com/user/Fragrant-Sympathy244)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/)
My recon methodology for hunting CVE-2021–42063 led to discovering an RXSS vulnerability in the…
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.Continue reading on Medium »
Read more...
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.Continue reading on Medium »
Read more...
Medium
My recon methodology for hunting CVE-2021–42063 led to discovering an RXSS vulnerability in the Tata Play program Part -2 .
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.
Day 30of 30 Day — 30 Vulnerabilities | Cross-Site Request Forgery (CSRF)
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
Medium
Day 30of 30 Day — 30 Vulnerabilities | Cross-Site Request Forgery (CSRF)
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCs
The Weak Link in Two-Factor Authentication: Exploiting Reusable OTPs
During a recent penetration test, I was tasked with evaluating the authentication security of an application. These tests are always…Continue reading on Medium »
Read more...
During a recent penetration test, I was tasked with evaluating the authentication security of an application. These tests are always…Continue reading on Medium »
Read more...
Medium
The Weak Link in Two-Factor Authentication: Exploiting Reusable OTPs
During a recent penetration test, I was tasked with evaluating the authentication security of an application. These tests are always…
Question
https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/
<!-- SC_OFF -->Ok I don't have a degree and iam bout to take a bunch of free courses for pentesting what are my chances of landing a job <!-- SC_ON --> submitted by /u/Zealousideal_Ease_78 (https://www.reddit.com/user/Zealousideal_Ease_78)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/)
https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/
<!-- SC_OFF -->Ok I don't have a degree and iam bout to take a bunch of free courses for pentesting what are my chances of landing a job <!-- SC_ON --> submitted by /u/Zealousideal_Ease_78 (https://www.reddit.com/user/Zealousideal_Ease_78)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/)