How a CSRF Vulnerability Can Be Exploited to Target Email Accounts — A Practical Walkthrough
In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…Continue reading on Medium »
Read more...
In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…Continue reading on Medium »
Read more...
Medium
How a CSRF Vulnerability Can Be Exploited to Target Email Accounts — A Practical Walkthrough
In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…
How a CSRF Vulnerability Can Be Exploited to Target Email Accounts — A Practical Walkthrough
https://medium.com/@muhammedgalal66/how-a-csrf-vulnerability-can-be-exploited-to-target-email-accounts-a-practical-walkthrough-60e6c2eac31f?source=rss------bug_bounty-5
In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…Continue reading on Medium » (https://medium.com/@muhammedgalal66/how-a-csrf-vulnerability-can-be-exploited-to-target-email-accounts-a-practical-walkthrough-60e6c2eac31f?source=rss------bug_bounty-5)
https://medium.com/@muhammedgalal66/how-a-csrf-vulnerability-can-be-exploited-to-target-email-accounts-a-practical-walkthrough-60e6c2eac31f?source=rss------bug_bounty-5
In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…Continue reading on Medium » (https://medium.com/@muhammedgalal66/how-a-csrf-vulnerability-can-be-exploited-to-target-email-accounts-a-practical-walkthrough-60e6c2eac31f?source=rss------bug_bounty-5)
From User to Admin: The Art of Privilege Escalation
https://bootcampsecurity.medium.com/from-user-to-admin-the-art-of-privilege-escalation-b80a4cd1e89b?source=rss------bug_bounty-5
“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?Continue reading on Medium » (https://bootcampsecurity.medium.com/from-user-to-admin-the-art-of-privilege-escalation-b80a4cd1e89b?source=rss------bug_bounty-5)
https://bootcampsecurity.medium.com/from-user-to-admin-the-art-of-privilege-escalation-b80a4cd1e89b?source=rss------bug_bounty-5
“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?Continue reading on Medium » (https://bootcampsecurity.medium.com/from-user-to-admin-the-art-of-privilege-escalation-b80a4cd1e89b?source=rss------bug_bounty-5)
Enumeração de subdomínios através da homepage
https://medium.com/@sarkis093/enumera%C3%A7%C3%A3o-de-subdom%C3%ADnios-atrav%C3%A9s-da-homepage-971d7aa341bf?source=rss------bug_bounty-5
https://medium.com/@sarkis093/enumera%C3%A7%C3%A3o-de-subdom%C3%ADnios-atrav%C3%A9s-da-homepage-971d7aa341bf?source=rss------bug_bounty-5
Dica de enumeração de subdomínios através da homepage de um alvo utilizando nada menos do que somente um terminal linux e o básico de…Continue reading on Medium » (https://medium.com/@sarkis093/enumera%C3%A7%C3%A3o-de-subdom%C3%ADnios-atrav%C3%A9s-da-homepage-971d7aa341bf?source=rss------bug_bounty-5)
From User to Admin: The Art of Privilege Escalation
“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?Continue reading on Medium »
Read more...
“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?Continue reading on Medium »
Read more...
Medium
From User to Admin: The Art of Privilege Escalation
“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?
Enumeração de subdomínios através da homepage
Dica de enumeração de subdomínios através da homepage de um alvo utilizando nada menos do que somente um terminal linux e o básico de…Continue reading on Medium »
Read more...
Dica de enumeração de subdomínios através da homepage de um alvo utilizando nada menos do que somente um terminal linux e o básico de…Continue reading on Medium »
Read more...
Medium
Enumeração de subdomínios através da homepage
Dica de enumeração de subdomínios através da homepage de um alvo utilizando nada menos do que somente um terminal linux e o básico de…
Critical Authentication Vulnerability in SAP BusinessObjects Business Intelligence Platform (CVE-2024-41730, CVSS 9.8/10)
https://www.reddit.com/r/Pentesting/comments/1guu7ac/critical_authentication_vulnerability_in_sap/
https://www.reddit.com/r/Pentesting/comments/1guu7ac/critical_authentication_vulnerability_in_sap/
Exploiting Business Logic Flaws in e-commerce platforms
Exploiting business logic flaws involves identifying weaknesses in the platform’s workflows or processes that can be manipulated by…Continue reading on Medium »
Read more...
Exploiting business logic flaws involves identifying weaknesses in the platform’s workflows or processes that can be manipulated by…Continue reading on Medium »
Read more...
Medium
Exploiting Business Logic Flaws in e-commerce platforms
Exploiting business logic flaws involves identifying weaknesses in the platform’s workflows or processes that can be manipulated by…
Common Security Risks in Browser Extensions
In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…Continue reading on Medium »
Read more...
In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…Continue reading on Medium »
Read more...
Medium
Common Security Risks in Browser Extensions
In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…
HOW I FOUND A BUG IN NASA
Hello, everyone! I hope you’re doing great. Today, I’m excited to share an incredible story about my recent experience hunting bugs in…Continue reading on Medium »
Read more...
Hello, everyone! I hope you’re doing great. Today, I’m excited to share an incredible story about my recent experience hunting bugs in…Continue reading on Medium »
Read more...
Medium
HOW I FOUND A BUG IN NASA 🚀
Hello, everyone!
I hope you’re doing great. Today, I’m excited to share an incredible story about my recent experience hunting bugs in…
I hope you’re doing great. Today, I’m excited to share an incredible story about my recent experience hunting bugs in…
Exploiting Business Logic Flaws in e-commerce platforms
https://medium.com/@Pentestforge/exploiting-business-logic-flaws-in-e-commerce-platforms-c3042a240c4a?source=rss------bug_bounty-5
https://medium.com/@Pentestforge/exploiting-business-logic-flaws-in-e-commerce-platforms-c3042a240c4a?source=rss------bug_bounty-5
Exploiting business logic flaws involves identifying weaknesses in the platform’s workflows or processes that can be manipulated by…Continue reading on Medium » (https://medium.com/@Pentestforge/exploiting-business-logic-flaws-in-e-commerce-platforms-c3042a240c4a?source=rss------bug_bounty-5)
Common Security Risks in Browser Extensions
https://medium.com/@Parag_Bagul/common-security-risks-in-browser-extensions-e61422499f7c?source=rss------bug_bounty-5
In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…Continue reading on Medium » (https://medium.com/@Parag_Bagul/common-security-risks-in-browser-extensions-e61422499f7c?source=rss------bug_bounty-5)
https://medium.com/@Parag_Bagul/common-security-risks-in-browser-extensions-e61422499f7c?source=rss------bug_bounty-5
In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…Continue reading on Medium » (https://medium.com/@Parag_Bagul/common-security-risks-in-browser-extensions-e61422499f7c?source=rss------bug_bounty-5)
Pentesting Advice for Startup
https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/
<!-- SC_OFF -->We're a small startup and about to select a vendor for a pentest. Our quotes are ranging from $1k to $12k. We are looking for a blackbox test on 3 URLs and network vulnerability. Of course, we want to keep costs low, but our colleague is suggesting that we need to use a reputable company that is public facing (has a website) and based in the US or first-world country. We work with small financial institutions, so his rationale is that the stamp on the pentest report will matter (I don't think it does), and also that if you allow a company or person in 3rd world countries that you're exposing yourself to risk if they are able collect the data, and they could share our vulnerabilities with others that can hack us. Suggestions? <!-- SC_ON --> submitted by /u/Brain-Abject (https://www.reddit.com/user/Brain-Abject)
[link] (https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/) [comments] (https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/)
https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/
<!-- SC_OFF -->We're a small startup and about to select a vendor for a pentest. Our quotes are ranging from $1k to $12k. We are looking for a blackbox test on 3 URLs and network vulnerability. Of course, we want to keep costs low, but our colleague is suggesting that we need to use a reputable company that is public facing (has a website) and based in the US or first-world country. We work with small financial institutions, so his rationale is that the stamp on the pentest report will matter (I don't think it does), and also that if you allow a company or person in 3rd world countries that you're exposing yourself to risk if they are able collect the data, and they could share our vulnerabilities with others that can hack us. Suggestions? <!-- SC_ON --> submitted by /u/Brain-Abject (https://www.reddit.com/user/Brain-Abject)
[link] (https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/) [comments] (https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/)
How I Uncovered an Unsubscribe Exploit While Checking My Internship Applications
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
How I Uncovered an Unsubscribe Exploit While Checking My Internship Applications
Introduction
Chinese Hackers Exploit Fortinet VPN Zero-Day to Steal Credentials
WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium »
Read more...
WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium »
Read more...
Medium
🚨 Chinese Hackers Exploit Fortinet VPN Zero-Day to Steal Credentials 🔓
WIRE TOR — The Ethical Hacking Services