How i Found X-Forwarded Header Injection — Server Be Like, ‘Ab Toh Trust Issues Ho Rahe Hain!’
Introduction:Continue reading on Medium »
Read more...
Introduction:Continue reading on Medium »
Read more...
Medium
How i Found X-Forwarded Header Injection — Server Be Like, ‘Ab Toh Trust Issues Ho Rahe Hain!’ 😂
Exploiting Trust Issues: How Misconfigured X-Forwarded Headers Can Lead to Security Vulnerabilities
How I Bypassed View-Only Mode with a Simple Trick ( duplicate bug )
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………Continue reading on Medium »
Read more...
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………Continue reading on Medium »
Read more...
Medium
How I Bypassed View-Only Mode with a Simple Trick ( duplicate bug 😒🐱🏍 )
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………
Where to find a professional to pentest a web application?
https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/
<!-- SC_OFF -->Hi all, I've an MVP NextJS project hosted on Heroku where users are authenticated with their Google accounts. I've 25 API end points. I've only a few test users for now and before adding more users, I would like a cost-friendly professional to test the system. I basically need to be sure that users can only fetch / edit their own data. Data is encrypted in the database (AES 256 GCM) and I also need to make sure it cannot be decrypted in some way. Where do I look to find such individual please? Thanks! <!-- SC_ON --> submitted by /u/olaf13 (https://www.reddit.com/user/olaf13)
[link] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/)
https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/
<!-- SC_OFF -->Hi all, I've an MVP NextJS project hosted on Heroku where users are authenticated with their Google accounts. I've 25 API end points. I've only a few test users for now and before adding more users, I would like a cost-friendly professional to test the system. I basically need to be sure that users can only fetch / edit their own data. Data is encrypted in the database (AES 256 GCM) and I also need to make sure it cannot be decrypted in some way. Where do I look to find such individual please? Thanks! <!-- SC_ON --> submitted by /u/olaf13 (https://www.reddit.com/user/olaf13)
[link] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hhtk1s/where_to_find_a_professional_to_pentest_a_web/)
How I Bypassed View-Only Mode with a Simple Trick ( duplicate bug )
https://medium.com/@mahdisalhi0500/how-i-bypassed-view-only-mode-with-a-simple-trick-duplicate-bug-92e1ec91a8d7?source=rss------bug_bounty-5
https://medium.com/@mahdisalhi0500/how-i-bypassed-view-only-mode-with-a-simple-trick-duplicate-bug-92e1ec91a8d7?source=rss------bug_bounty-5
…………إِنَّ اللَّهَ وَمَلائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّيَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا……………Continue reading on Medium » (https://medium.com/@mahdisalhi0500/how-i-bypassed-view-only-mode-with-a-simple-trick-duplicate-bug-92e1ec91a8d7?source=rss------bug_bounty-5)
Zero-Click Account Takeover Through Response Manipulation
https://medium.com/@abdullayman04/zero-click-account-takeover-through-response-manipulation-ee786a7a06dd?source=rss------bug_bounty-5
https://medium.com/@abdullayman04/zero-click-account-takeover-through-response-manipulation-ee786a7a06dd?source=rss------bug_bounty-5
Hi Everyone!Continue reading on Medium » (https://medium.com/@abdullayman04/zero-click-account-takeover-through-response-manipulation-ee786a7a06dd?source=rss------bug_bounty-5)
HTML Injection to Mass Phishing
https://infosecwriteups.com/html-injection-to-mass-phishing-5701d495cdc2?source=rss------bug_bounty-5
https://infosecwriteups.com/html-injection-to-mass-phishing-5701d495cdc2?source=rss------bug_bounty-5
HTML Injection vulnerabilities, although often underestimated, can be leveraged for significant attacks such as phishing campaigns.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/html-injection-to-mass-phishing-5701d495cdc2?source=rss------bug_bounty-5)
Installing Xposed Framework for Enhanced Penetration Testing (SSLunpinning)
https://medium.com/@sumith.ec12/installing-xposed-framework-for-enhanced-penetration-testing-sslunpinning-d50fbb2354c6?source=rss------bug_bounty-5
https://medium.com/@sumith.ec12/installing-xposed-framework-for-enhanced-penetration-testing-sslunpinning-d50fbb2354c6?source=rss------bug_bounty-5
ObjectiveContinue reading on Medium » (https://medium.com/@sumith.ec12/installing-xposed-framework-for-enhanced-penetration-testing-sslunpinning-d50fbb2354c6?source=rss------bug_bounty-5)
Subdomain Takeover guides, methodology and exploit POCs
https://aditya-narayan.medium.com/subdomain-takeover-guides-methodology-and-exploit-pocs-9f5dd632c175?source=rss------bug_bounty-5
https://aditya-narayan.medium.com/subdomain-takeover-guides-methodology-and-exploit-pocs-9f5dd632c175?source=rss------bug_bounty-5
Another day in Bug Bounty journey, today I learned about Subdomain TakeOver vulnerability.Continue reading on Medium » (https://aditya-narayan.medium.com/subdomain-takeover-guides-methodology-and-exploit-pocs-9f5dd632c175?source=rss------bug_bounty-5)
Zero-Click Account Takeover Through Response Manipulation
Hi Everyone!Continue reading on Medium »
Read more...
Hi Everyone!Continue reading on Medium »
Read more...
Medium
Zero-Click Account Takeover Through Response Manipulation
Hi Everyone!
HTML Injection to Mass Phishing
HTML Injection vulnerabilities, although often underestimated, can be leveraged for significant attacks such as phishing campaigns.Continue reading on InfoSec Write-ups »
Read more...
HTML Injection vulnerabilities, although often underestimated, can be leveraged for significant attacks such as phishing campaigns.Continue reading on InfoSec Write-ups »
Read more...
Medium
HTML Injection to Mass Phishing
HTML Injection vulnerabilities, although often underestimated, can be leveraged for significant attacks such as phishing campaigns.
Installing Xposed Framework for Enhanced Penetration Testing (SSLunpinning)
ObjectiveContinue reading on Medium »
Read more...
ObjectiveContinue reading on Medium »
Read more...
Medium
Installing Xposed Framework for Enhanced Penetration Testing (SSLunpinning)
Objective