Discovering a Stored XSS Vulnerability on a Bug Bounty Program
Hello AppSec folks, I hope everyone is doing great! This is Anmol, also known as Nishachar or Asmodeus. Let’s dive straight into my recent…Continue reading on Medium »
Read more...
Hello AppSec folks, I hope everyone is doing great! This is Anmol, also known as Nishachar or Asmodeus. Let’s dive straight into my recent…Continue reading on Medium »
Read more...
Medium
Discovering a Stored XSS Vulnerability on a Bug Bounty Program
Hello AppSec folks, I hope everyone is doing great! This is Anmol, also known as Nishachar or Asmodeus. Let’s dive straight into my recent…
How To Stay Ahead of 99% of Bug Bounty Hunters
The bug bounty ecosystem has exploded in recent years, providing security researchers, ethical hackers, and cybersecurity enthusiasts with…Continue reading on Medium »
Read more...
The bug bounty ecosystem has exploded in recent years, providing security researchers, ethical hackers, and cybersecurity enthusiasts with…Continue reading on Medium »
Read more...
Medium
How To Stay Ahead of 99% of Bug Bounty Hunters
The bug bounty ecosystem has exploded in recent years, providing security researchers, ethical hackers, and cybersecurity enthusiasts with…
How EDR really works
https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/
submitted by /u/NagateTanikaze (https://www.reddit.com/user/NagateTanikaze)
[link] (https://blog.deeb.ch/posts/how-edr-works) [comments] (https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/)
https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/
submitted by /u/NagateTanikaze (https://www.reddit.com/user/NagateTanikaze)
[link] (https://blog.deeb.ch/posts/how-edr-works) [comments] (https://www.reddit.com/r/redteamsec/comments/1fbtmzm/how_edr_really_works/)
Pentesting and Ethical Hacking
https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/
<!-- SC_OFF -->I am currently pursuing a course on SOC
I would like to improve my skills on Pentesting/Hacking also
Can i get to know the resources that can be used for free.
Any youtube playlist or free textbooks or anything for starting <!-- SC_ON --> submitted by /u/Fragrant-Sympathy244 (https://www.reddit.com/user/Fragrant-Sympathy244)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/)
https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/
<!-- SC_OFF -->I am currently pursuing a course on SOC
I would like to improve my skills on Pentesting/Hacking also
Can i get to know the resources that can be used for free.
Any youtube playlist or free textbooks or anything for starting <!-- SC_ON --> submitted by /u/Fragrant-Sympathy244 (https://www.reddit.com/user/Fragrant-Sympathy244)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbr2pd/pentesting_and_ethical_hacking/)
My recon methodology for hunting CVE-2021–42063 led to discovering an RXSS vulnerability in the…
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.Continue reading on Medium »
Read more...
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.Continue reading on Medium »
Read more...
Medium
My recon methodology for hunting CVE-2021–42063 led to discovering an RXSS vulnerability in the Tata Play program Part -2 .
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.
Day 30of 30 Day — 30 Vulnerabilities | Cross-Site Request Forgery (CSRF)
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
Medium
Day 30of 30 Day — 30 Vulnerabilities | Cross-Site Request Forgery (CSRF)
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCs
The Weak Link in Two-Factor Authentication: Exploiting Reusable OTPs
During a recent penetration test, I was tasked with evaluating the authentication security of an application. These tests are always…Continue reading on Medium »
Read more...
During a recent penetration test, I was tasked with evaluating the authentication security of an application. These tests are always…Continue reading on Medium »
Read more...
Medium
The Weak Link in Two-Factor Authentication: Exploiting Reusable OTPs
During a recent penetration test, I was tasked with evaluating the authentication security of an application. These tests are always…
Question
https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/
<!-- SC_OFF -->Ok I don't have a degree and iam bout to take a bunch of free courses for pentesting what are my chances of landing a job <!-- SC_ON --> submitted by /u/Zealousideal_Ease_78 (https://www.reddit.com/user/Zealousideal_Ease_78)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/)
https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/
<!-- SC_OFF -->Ok I don't have a degree and iam bout to take a bunch of free courses for pentesting what are my chances of landing a job <!-- SC_ON --> submitted by /u/Zealousideal_Ease_78 (https://www.reddit.com/user/Zealousideal_Ease_78)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbwupx/question/)
OWASP top 10 A08:Software and Data Integrity Failures
In modern software development, ensuring the integrity of software and data has become a major challenge due to the prevalence of rapid…Continue reading on Medium »
Read more...
In modern software development, ensuring the integrity of software and data has become a major challenge due to the prevalence of rapid…Continue reading on Medium »
Read more...
Medium
OWASP top 10 A08:Software and Data Integrity Failures
In modern software development, ensuring the integrity of software and data has become a major challenge due to the prevalence of rapid…
My recon methodology for hunting CVE-2021–42063 led to discovering an RXSS vulnerability in the…
https://medium.com/@karthithehacker/my-recon-methodology-for-hunting-cve-2021-42063-led-to-discovering-an-rxss-vulnerability-in-the-27a7aa435fd3?source=rss------bug_bounty-5
https://medium.com/@karthithehacker/my-recon-methodology-for-hunting-cve-2021-42063-led-to-discovering-an-rxss-vulnerability-in-the-27a7aa435fd3?source=rss------bug_bounty-5
If you’re new to this writeup, I suggest you read part 1 where I shared some valuable info about my recon and other processes.Continue reading on Medium » (https://medium.com/@karthithehacker/my-recon-methodology-for-hunting-cve-2021-42063-led-to-discovering-an-rxss-vulnerability-in-the-27a7aa435fd3?source=rss------bug_bounty-5)
Day 30of 30 Day — 30 Vulnerabilities | Cross-Site Request Forgery (CSRF)
https://medium.com/@kumawatabhijeet2002/day-30of-30-day-30-vulnerabilities-cross-site-request-forgery-csrf-062ff53c5efd?source=rss------bug_bounty-5
https://medium.com/@kumawatabhijeet2002/day-30of-30-day-30-vulnerabilities-cross-site-request-forgery-csrf-062ff53c5efd?source=rss------bug_bounty-5
Day 30: Mastering Account Takeover through CSRF Token Reuse — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium » (https://medium.com/@kumawatabhijeet2002/day-30of-30-day-30-vulnerabilities-cross-site-request-forgery-csrf-062ff53c5efd?source=rss------bug_bounty-5)
How i found xss in goverment website with one tools.
https://medium.com/@sulthanyluthfi/how-i-found-xss-in-goverment-website-with-one-tools-5dd5d431ed03?source=rss------bug_bounty-5
https://medium.com/@sulthanyluthfi/how-i-found-xss-in-goverment-website-with-one-tools-5dd5d431ed03?source=rss------bug_bounty-5
The Weak Link in Two-Factor Authentication: Exploiting Reusable OTPs
https://medium.com/@tusharpuri6/the-weak-link-in-two-factor-authentication-exploiting-reusable-otps-ed30bd8bf4da?source=rss------bug_bounty-5
https://medium.com/@tusharpuri6/the-weak-link-in-two-factor-authentication-exploiting-reusable-otps-ed30bd8bf4da?source=rss------bug_bounty-5