I discovered a Server-Side Request Forgery (SSRF) vulnerability in the Radio Player WordPress plugin, assigned as CVE-2024–54385Continue reading on Medium » (https://medium.com/@malvinval/cve-2024-54385-wordpress-plugin-7ff0f8e5ad1d?source=rss------bug_bounty-5)
Utilizing MITRE ATT&CK Framework: Examples and Practical Applications
https://medium.com/@paritoshblogs/utilizing-mitre-att-ck-framework-examples-and-practical-applications-0c4ea468ad53?source=rss------bug_bounty-5
https://medium.com/@paritoshblogs/utilizing-mitre-att-ck-framework-examples-and-practical-applications-0c4ea468ad53?source=rss------bug_bounty-5
The MITRE ATT&CK framework stands as a cornerstone for cybersecurity teams looking to enhance their defensive strategies. By understanding…Continue reading on Medium » (https://medium.com/@paritoshblogs/utilizing-mitre-att-ck-framework-examples-and-practical-applications-0c4ea468ad53?source=rss------bug_bounty-5)
Bypassing crowdstrike falcon
https://www.reddit.com/r/redteamsec/comments/1hg4d5g/bypassing_crowdstrike_falcon/
<!-- SC_OFF -->Hi, I’m conducting an internal red teaming activity on a Windows machine protected by Falcon. I can’t run PowerView or any tools as they’re getting blocked immediately. Is there any bypass or workaround to get these tools working? <!-- SC_ON --> submitted by /u/Cute_Biscotti_7016 (https://www.reddit.com/user/Cute_Biscotti_7016)
[link] (http://hha.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1hg4d5g/bypassing_crowdstrike_falcon/)
https://www.reddit.com/r/redteamsec/comments/1hg4d5g/bypassing_crowdstrike_falcon/
<!-- SC_OFF -->Hi, I’m conducting an internal red teaming activity on a Windows machine protected by Falcon. I can’t run PowerView or any tools as they’re getting blocked immediately. Is there any bypass or workaround to get these tools working? <!-- SC_ON --> submitted by /u/Cute_Biscotti_7016 (https://www.reddit.com/user/Cute_Biscotti_7016)
[link] (http://hha.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1hg4d5g/bypassing_crowdstrike_falcon/)
What other position after pentester?
https://www.reddit.com/r/Pentesting/comments/1hg1zuk/what_other_position_after_pentester/
<!-- SC_OFF -->I know this easy to find but I want to here from the real life experience I have worked in penetration tester role for almost 2 years and now want to try something new what position should I looking for to learn more in this field I do have experience in Pentest (main job), bug bounty(free time), 2 CVE What do you think? <!-- SC_ON --> submitted by /u/diamond1750 (https://www.reddit.com/user/diamond1750)
[link] (https://www.reddit.com/r/Pentesting/comments/1hg1zuk/what_other_position_after_pentester/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hg1zuk/what_other_position_after_pentester/)
https://www.reddit.com/r/Pentesting/comments/1hg1zuk/what_other_position_after_pentester/
<!-- SC_OFF -->I know this easy to find but I want to here from the real life experience I have worked in penetration tester role for almost 2 years and now want to try something new what position should I looking for to learn more in this field I do have experience in Pentest (main job), bug bounty(free time), 2 CVE What do you think? <!-- SC_ON --> submitted by /u/diamond1750 (https://www.reddit.com/user/diamond1750)
[link] (https://www.reddit.com/r/Pentesting/comments/1hg1zuk/what_other_position_after_pentester/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hg1zuk/what_other_position_after_pentester/)
Open Redirect to XSS: Chaining Vulnerabilities for Maximum Impact
https://medium.com/@iPsalmy/open-redirect-to-xss-chaining-vulnerabilities-for-maximum-impact-36ae8dd9f198?source=rss------bug_bounty-5
https://medium.com/@iPsalmy/open-redirect-to-xss-chaining-vulnerabilities-for-maximum-impact-36ae8dd9f198?source=rss------bug_bounty-5
Hello guys! I’m back again with a real-life example of how I turned a simple open redirect vulnerability into a reflected XSS exploit.Continue reading on Medium » (https://medium.com/@iPsalmy/open-redirect-to-xss-chaining-vulnerabilities-for-maximum-impact-36ae8dd9f198?source=rss------bug_bounty-5)
Open Redirect to XSS: Chaining Vulnerabilities for Maximum Impact
Hello guys! I’m back again with a real-life example of how I turned a simple open redirect vulnerability into a reflected XSS exploit.Continue reading on Medium »
Read more...
Hello guys! I’m back again with a real-life example of how I turned a simple open redirect vulnerability into a reflected XSS exploit.Continue reading on Medium »
Read more...
Medium
Open Redirect to XSS: Chaining Vulnerabilities for Maximum Impact
Hello guys! I’m back again with a real-life example of how I turned a simple open redirect vulnerability into a reflected XSS exploit.
API Keys Attack: How to Find and Exploit Secrets in Web Applications
API keys play a crucial role in web application security, serving as access credentials for APIs. However, improper implementation or…Continue reading on Medium »
Read more...
API keys play a crucial role in web application security, serving as access credentials for APIs. However, improper implementation or…Continue reading on Medium »
Read more...
Medium
API Keys Attack: How to Find and Exploit Secrets in Web Applications
API keys play a crucial role in web application security, serving as access credentials for APIs. However, improper implementation or…
GitHub - NtDallas/Svartalfheim: Stage 0 Shellcode to Download a Remote Payload and Execute it in Memory
https://www.reddit.com/r/redteamsec/comments/1hg5z44/github_ntdallassvartalfheim_stage_0_shellcode_to/
submitted by /u/intuentis0x0 (https://www.reddit.com/user/intuentis0x0)
[link] (https://github.com/NtDallas/Svartalfheim) [comments] (https://www.reddit.com/r/redteamsec/comments/1hg5z44/github_ntdallassvartalfheim_stage_0_shellcode_to/)
https://www.reddit.com/r/redteamsec/comments/1hg5z44/github_ntdallassvartalfheim_stage_0_shellcode_to/
submitted by /u/intuentis0x0 (https://www.reddit.com/user/intuentis0x0)
[link] (https://github.com/NtDallas/Svartalfheim) [comments] (https://www.reddit.com/r/redteamsec/comments/1hg5z44/github_ntdallassvartalfheim_stage_0_shellcode_to/)
How I Broke the Speed Limit: A Bug Bounty Tale of Bypassing Rate Limiting
You know that feeling when you’re staring at a secure application, a masterpiece of security controls? Every endpoint you poke at seems…Continue reading on InfoSec Write-ups »
Read more...
You know that feeling when you’re staring at a secure application, a masterpiece of security controls? Every endpoint you poke at seems…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Broke the Speed Limit: A Bug Bounty Tale of Bypassing Rate Limiting
You know that feeling when you’re staring at a secure application, a masterpiece of security controls? Every endpoint you poke at seems…
Exposing Facebook’s Hidden Goldmine: Creators’ Private Data at Risk
This bug revealed sensitive data such as email addresses, phone numbers, birthdays, associated pages and apps, banking details and many…Continue reading on Medium »
Read more...
This bug revealed sensitive data such as email addresses, phone numbers, birthdays, associated pages and apps, banking details and many…Continue reading on Medium »
Read more...
Medium
Exposing Facebook’s Hidden Goldmine: Creators’ Private Data at Risk
This bug revealed sensitive data such as email addresses, phone numbers, birthdays, associated pages and apps, banking details and many…
Top 9 Books to Master Bug Hunting and Penetration Testing
What is Bug Bounty and Penetration Testing?Continue reading on OSINT Team »
Read more...
What is Bug Bounty and Penetration Testing?Continue reading on OSINT Team »
Read more...
Medium
Top 9 Books to Master Bug Hunting and Penetration Testing
What is Bug Bounty and Penetration Testing?
How I Broke the Speed Limit: A Bug Bounty Tale of Bypassing Rate Limiting
You know that feeling when you’re staring at a secure application, a masterpiece of security controls? Every endpoint you poke at seems…Continue reading on InfoSec Write-ups »
Read more...
You know that feeling when you’re staring at a secure application, a masterpiece of security controls? Every endpoint you poke at seems…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Broke the Speed Limit: A Bug Bounty Tale of Bypassing Rate Limiting
You know that feeling when you’re staring at a secure application, a masterpiece of security controls? Every endpoint you poke at seems…
How I got Appreciation Letters for finding bugs.
How you can get yours too.Continue reading on InfoSec Write-ups »
Read more...
How you can get yours too.Continue reading on InfoSec Write-ups »
Read more...
Medium
How I got Appreciation Letters for finding bugs.
How you can get yours too.
API Keys Attack: How to Find and Exploit Secrets in Web Applications
https://medium.com/@bootstrapsecurity/api-keys-attack-how-to-find-and-exploit-secrets-in-web-applications-1896d75d716b?source=rss------bug_bounty-5
API keys play a crucial role in web application security, serving as access credentials for APIs. However, improper implementation or…Continue reading on Medium » (https://medium.com/@bootstrapsecurity/api-keys-attack-how-to-find-and-exploit-secrets-in-web-applications-1896d75d716b?source=rss------bug_bounty-5)
https://medium.com/@bootstrapsecurity/api-keys-attack-how-to-find-and-exploit-secrets-in-web-applications-1896d75d716b?source=rss------bug_bounty-5
API keys play a crucial role in web application security, serving as access credentials for APIs. However, improper implementation or…Continue reading on Medium » (https://medium.com/@bootstrapsecurity/api-keys-attack-how-to-find-and-exploit-secrets-in-web-applications-1896d75d716b?source=rss------bug_bounty-5)
Exposing Facebook’s Hidden Goldmine: Creators’ Private Data at Risk
https://gtm0x01.medium.com/exposing-facebooks-hidden-goldmine-creators-private-data-at-risk-01317f3f0031?source=rss------bug_bounty-5
https://gtm0x01.medium.com/exposing-facebooks-hidden-goldmine-creators-private-data-at-risk-01317f3f0031?source=rss------bug_bounty-5
This bug revealed sensitive data such as email addresses, phone numbers, birthdays, associated pages and apps, banking details and many…Continue reading on Medium » (https://gtm0x01.medium.com/exposing-facebooks-hidden-goldmine-creators-private-data-at-risk-01317f3f0031?source=rss------bug_bounty-5)