How i found my first open redirect
https://medium.com/@yagomartins30/how-i-found-my-first-open-redirect-cd9ca60d307d?source=rss------bug_bounty-5
https://medium.com/@yagomartins30/how-i-found-my-first-open-redirect-cd9ca60d307d?source=rss------bug_bounty-5
Yago Martins.Continue reading on Medium » (https://medium.com/@yagomartins30/how-i-found-my-first-open-redirect-cd9ca60d307d?source=rss------bug_bounty-5)
Close to Domain Admin
https://www.reddit.com/r/Pentesting/comments/1g0rrg2/close_to_domain_admin/
<!-- SC_OFF -->Hello all so I'm conducting an internal pt and I'm really really close to get domain admin. The user that i compromised can RDP into 4 machines and i have local admin on 2 other machines. thing is, the 2 machines that i have local admin on have sessions of global admins but there are 2 AVs in place as well as an EDR. i managed to get mimikatz over to the machine without getting deleted but when i try to run it. it gives me access denied although im a local admin with a high mandatory shell 😀 Any ideas on how i can proceed? Thanks in advance <!-- SC_ON --> submitted by /u/Business_Space798 (https://www.reddit.com/user/Business_Space798)
[link] (https://www.reddit.com/r/Pentesting/comments/1g0rrg2/close_to_domain_admin/) [comments] (https://www.reddit.com/r/Pentesting/comments/1g0rrg2/close_to_domain_admin/)
https://www.reddit.com/r/Pentesting/comments/1g0rrg2/close_to_domain_admin/
<!-- SC_OFF -->Hello all so I'm conducting an internal pt and I'm really really close to get domain admin. The user that i compromised can RDP into 4 machines and i have local admin on 2 other machines. thing is, the 2 machines that i have local admin on have sessions of global admins but there are 2 AVs in place as well as an EDR. i managed to get mimikatz over to the machine without getting deleted but when i try to run it. it gives me access denied although im a local admin with a high mandatory shell 😀 Any ideas on how i can proceed? Thanks in advance <!-- SC_ON --> submitted by /u/Business_Space798 (https://www.reddit.com/user/Business_Space798)
[link] (https://www.reddit.com/r/Pentesting/comments/1g0rrg2/close_to_domain_admin/) [comments] (https://www.reddit.com/r/Pentesting/comments/1g0rrg2/close_to_domain_admin/)
Some recommend introductory books on hacker penetration testing please
https://www.reddit.com/r/Pentesting/comments/1g127ww/some_recommend_introductory_books_on_hacker/
<!-- SC_OFF -->What are some introductory books on hacker penetration testing? I studied operating systems, computer networks, databases, and programming languages such as C, C++, and Java in college. <!-- SC_ON --> submitted by /u/hyperiontri (https://www.reddit.com/user/hyperiontri)
[link] (https://www.reddit.com/r/Pentesting/comments/1g127ww/some_recommend_introductory_books_on_hacker/) [comments] (https://www.reddit.com/r/Pentesting/comments/1g127ww/some_recommend_introductory_books_on_hacker/)
https://www.reddit.com/r/Pentesting/comments/1g127ww/some_recommend_introductory_books_on_hacker/
<!-- SC_OFF -->What are some introductory books on hacker penetration testing? I studied operating systems, computer networks, databases, and programming languages such as C, C++, and Java in college. <!-- SC_ON --> submitted by /u/hyperiontri (https://www.reddit.com/user/hyperiontri)
[link] (https://www.reddit.com/r/Pentesting/comments/1g127ww/some_recommend_introductory_books_on_hacker/) [comments] (https://www.reddit.com/r/Pentesting/comments/1g127ww/some_recommend_introductory_books_on_hacker/)
Bug Hunting Recon Methodology | Part2 | LegionHunter
Part1: https://medium.com/system-weakness/bug-hunting-recon-methodology-part1-legionhunter-975b7bbe3231Continue reading on OSINT Team »
Read more...
Part1: https://medium.com/system-weakness/bug-hunting-recon-methodology-part1-legionhunter-975b7bbe3231Continue reading on OSINT Team »
Read more...
Effective Port Scanning for Finding Vulnerabilities in Bug Bounties
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Effective Port Scanning for Finding Vulnerabilities in Bug Bounties
Introduction
How I Made $6,200 in a Single Bug Bounty Using SubdomainRadar.io
As a cybersecurity researcher, I’m always on the lookout for tools that can help me uncover hidden vulnerabilities.Continue reading on Medium »
Read more...
As a cybersecurity researcher, I’m always on the lookout for tools that can help me uncover hidden vulnerabilities.Continue reading on Medium »
Read more...
Medium
How I Made $6,200 in a Single Bug Bounty Using SubdomainRadar.io
As a cybersecurity researcher, I’m always on the lookout for tools that can help me uncover hidden vulnerabilities. Recently, I had a major…
How to Find SQL Vulnerabilities in Web Applications and Websites and Earn up to $500—$10,000
SQL injection (SQLi) is one of the most common and dangerous vulnerabilities found in web applications, allowing attackers to manipulate…Continue reading on Medium »
Read more...
SQL injection (SQLi) is one of the most common and dangerous vulnerabilities found in web applications, allowing attackers to manipulate…Continue reading on Medium »
Read more...
Medium
How to Find SQL Vulnerabilities in Web Applications and Websites and Earn up to $500—$10,000
SQL injection (SQLi) is one of the most common and dangerous vulnerabilities found in web applications, allowing attackers to manipulate…
Building an EDR From Scratch Part 3 - Creating The Agent (Endpoint Detection and Response)
https://www.reddit.com/r/redteamsec/comments/1g11djn/building_an_edr_from_scratch_part_3_creating_the/
submitted by /u/Incodenito (https://www.reddit.com/user/Incodenito)
[link] (https://youtu.be/XAX19jmMiOs) [comments] (https://www.reddit.com/r/redteamsec/comments/1g11djn/building_an_edr_from_scratch_part_3_creating_the/)
https://www.reddit.com/r/redteamsec/comments/1g11djn/building_an_edr_from_scratch_part_3_creating_the/
submitted by /u/Incodenito (https://www.reddit.com/user/Incodenito)
[link] (https://youtu.be/XAX19jmMiOs) [comments] (https://www.reddit.com/r/redteamsec/comments/1g11djn/building_an_edr_from_scratch_part_3_creating_the/)
Bug Hunting Recon Methodology | Part2 | LegionHunter
https://osintteam.blog/bug-hunting-recon-methodology-part2-legionhunter-4bb925e3e1bf?source=rss------bug_bounty-5
https://osintteam.blog/bug-hunting-recon-methodology-part2-legionhunter-4bb925e3e1bf?source=rss------bug_bounty-5
Effective Port Scanning for Finding Vulnerabilities in Bug Bounties
https://bevijaygupta.medium.com/effective-port-scanning-for-finding-vulnerabilities-in-bug-bounties-0c16871a7e0b?source=rss------bug_bounty-5
https://bevijaygupta.medium.com/effective-port-scanning-for-finding-vulnerabilities-in-bug-bounties-0c16871a7e0b?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://bevijaygupta.medium.com/effective-port-scanning-for-finding-vulnerabilities-in-bug-bounties-0c16871a7e0b?source=rss------bug_bounty-5)
How I Made $6,200 in a Single Bug Bounty Using SubdomainRadar.io
https://medium.com/@alexandrevandammepro/how-i-made-6-200-in-a-single-bug-bounty-using-subdomainradar-io-a557f2baae0b?source=rss------bug_bounty-5
As a cybersecurity researcher, I’m always on the lookout for tools that can help me uncover hidden vulnerabilities.Continue reading on Medium » (https://medium.com/@alexandrevandammepro/how-i-made-6-200-in-a-single-bug-bounty-using-subdomainradar-io-a557f2baae0b?source=rss------bug_bounty-5)
https://medium.com/@alexandrevandammepro/how-i-made-6-200-in-a-single-bug-bounty-using-subdomainradar-io-a557f2baae0b?source=rss------bug_bounty-5
As a cybersecurity researcher, I’m always on the lookout for tools that can help me uncover hidden vulnerabilities.Continue reading on Medium » (https://medium.com/@alexandrevandammepro/how-i-made-6-200-in-a-single-bug-bounty-using-subdomainradar-io-a557f2baae0b?source=rss------bug_bounty-5)
How to Find SQL Vulnerabilities in Web Applications and Websites and Earn up to $500—$10,000
https://medium.com/@anandrishav2228/how-to-find-sql-vulnerabilities-in-web-applications-and-websites-and-earn-up-to-500-10-000-f0935e9d4892?source=rss------bug_bounty-5
https://medium.com/@anandrishav2228/how-to-find-sql-vulnerabilities-in-web-applications-and-websites-and-earn-up-to-500-10-000-f0935e9d4892?source=rss------bug_bounty-5
SQL injection (SQLi) is one of the most common and dangerous vulnerabilities found in web applications, allowing attackers to manipulate…Continue reading on Medium » (https://medium.com/@anandrishav2228/how-to-find-sql-vulnerabilities-in-web-applications-and-websites-and-earn-up-to-500-10-000-f0935e9d4892?source=rss------bug_bounty-5)
CVE-2024–0195 Improper Control of Generation of Code (‘Code Injection’)
CVE-2024–0195 OverviewContinue reading on InfoSec Write-ups »
Read more...
CVE-2024–0195 OverviewContinue reading on InfoSec Write-ups »
Read more...
Medium
CVE-2024–0195 Improper Control of Generation of Code (‘Code Injection’)
CVE-2024–0195 Overview