My First Year in Bug Bounty
Hello everyone, in this writeup I will summarize my first year as a bug bounty hunter working only in Bugcrowd.Continue reading on Medium »
Read more...
Hello everyone, in this writeup I will summarize my first year as a bug bounty hunter working only in Bugcrowd.Continue reading on Medium »
Read more...
Medium
My First Year in Bug Bounty 👾
Hello everyone, in this writeup I will summarize my first year as a bug bounty hunter working only in Bugcrowd.
Anyone available for a chat?
https://www.reddit.com/r/Pentesting/comments/1htn4yw/anyone_available_for_a_chat/
<!-- SC_OFF -->Hi all, Im a recent cybersecurity graduate and working as a full time soc analyst , im about 7 months into my OSCP training and am purchasing the offsec exam voucher with 3 months access to their course materials at the end of the week. I was wondering if I could schedule maybe a 20-30 minute call via discord or whatever to anyone who has recently passed the test to give me some final words of wisdom before I dive deep for the next 3 months. Pm me if you can! Thanks!! <!-- SC_ON --> submitted by /u/balls-deep_in-Cum (https://www.reddit.com/user/balls-deep_in-Cum)
[link] (https://www.reddit.com/r/Pentesting/comments/1htn4yw/anyone_available_for_a_chat/) [comments] (https://www.reddit.com/r/Pentesting/comments/1htn4yw/anyone_available_for_a_chat/)
https://www.reddit.com/r/Pentesting/comments/1htn4yw/anyone_available_for_a_chat/
<!-- SC_OFF -->Hi all, Im a recent cybersecurity graduate and working as a full time soc analyst , im about 7 months into my OSCP training and am purchasing the offsec exam voucher with 3 months access to their course materials at the end of the week. I was wondering if I could schedule maybe a 20-30 minute call via discord or whatever to anyone who has recently passed the test to give me some final words of wisdom before I dive deep for the next 3 months. Pm me if you can! Thanks!! <!-- SC_ON --> submitted by /u/balls-deep_in-Cum (https://www.reddit.com/user/balls-deep_in-Cum)
[link] (https://www.reddit.com/r/Pentesting/comments/1htn4yw/anyone_available_for_a_chat/) [comments] (https://www.reddit.com/r/Pentesting/comments/1htn4yw/anyone_available_for_a_chat/)
How I Found P1 Vulnerability Using Google Dork
Hello Everyone! 😊Continue reading on Medium »
Read more...
Hello Everyone! 😊Continue reading on Medium »
Read more...
Medium
How I Found P1 Vulnerability Using Google Dork
Hello Everyone! 😊
What Is Cross Site Request Forgery?
ALL LINKS IN THIS ARTICLE ARE FAKE, BUT DO NOT INTERACT WITH THEMContinue reading on Medium »
Read more...
ALL LINKS IN THIS ARTICLE ARE FAKE, BUT DO NOT INTERACT WITH THEMContinue reading on Medium »
Read more...
Medium
What Is Cross Site Request Forgery?
ALL LINKS IN THIS ARTICLE ARE FAKE, BUT DO NOT INTERACT WITH THEM
My First Bug Report in Microsoft Windows Task Manager
Bug: Unclickable Right-Click Option for Microsoft Teams in Task Manager but clickable button in aboveContinue reading on Medium »
Read more...
Bug: Unclickable Right-Click Option for Microsoft Teams in Task Manager but clickable button in aboveContinue reading on Medium »
Read more...
Medium
My First Bug Report in Microsoft Windows Task Manager
Bug: Unclickable Right-Click Option for Microsoft Teams in Task Manager but clickable button in above
Detecting GraphQL Injection: Tools and Techniques for Security Testers
https://medium.com/infosecmatrix/detecting-graphql-injection-tools-and-techniques-for-security-testers-f3742d0388aa?source=rss------bug_bounty-5
https://medium.com/infosecmatrix/detecting-graphql-injection-tools-and-techniques-for-security-testers-f3742d0388aa?source=rss------bug_bounty-5
A Comprehensive Guide to Identifying and Exploiting GraphQL Injection Vulnerabilities ResponsiblyContinue reading on Infosec Matrix » (https://medium.com/infosecmatrix/detecting-graphql-injection-tools-and-techniques-for-security-testers-f3742d0388aa?source=rss------bug_bounty-5)
Find XSS Vulnerabilities in Minutes
https://medium.com/@phirojshah20/find-xss-vulnerabilities-in-minutes-912d02d2b848?source=rss------bug_bounty-5
Cross-Site Scripting (XSS) remains one of the most prevalent vulnerabilities in web applications. As a red teamer or a bug bounty hunter…Continue reading on Medium » (https://medium.com/@phirojshah20/find-xss-vulnerabilities-in-minutes-912d02d2b848?source=rss------bug_bounty-5)
https://medium.com/@phirojshah20/find-xss-vulnerabilities-in-minutes-912d02d2b848?source=rss------bug_bounty-5
Cross-Site Scripting (XSS) remains one of the most prevalent vulnerabilities in web applications. As a red teamer or a bug bounty hunter…Continue reading on Medium » (https://medium.com/@phirojshah20/find-xss-vulnerabilities-in-minutes-912d02d2b848?source=rss------bug_bounty-5)
New Android Malware Alert: FireScam Targets RuStore Users!
https://medium.com/@wiretor/new-android-malware-alert-firescam-targets-rustore-users-b5de983bd805?source=rss------bug_bounty-5
https://medium.com/@wiretor/new-android-malware-alert-firescam-targets-rustore-users-b5de983bd805?source=rss------bug_bounty-5
WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium » (https://medium.com/@wiretor/new-android-malware-alert-firescam-targets-rustore-users-b5de983bd805?source=rss------bug_bounty-5)
Bad Tenable Plugin Updates Take Down Nessus Agents Worldwide
https://medium.com/@wiretor/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide-baf7c48c34a3?source=rss------bug_bounty-5
https://medium.com/@wiretor/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide-baf7c48c34a3?source=rss------bug_bounty-5
WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium » (https://medium.com/@wiretor/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide-baf7c48c34a3?source=rss------bug_bounty-5)
Nikto : VulnerabilityScanner COMMANDS
https://jawstar.medium.com/nikto-vulnerabilityscanner-commands-578b76344097?source=rss------bug_bounty-5
https://jawstar.medium.com/nikto-vulnerabilityscanner-commands-578b76344097?source=rss------bug_bounty-5
Auth : JawstarContinue reading on Medium » (https://jawstar.medium.com/nikto-vulnerabilityscanner-commands-578b76344097?source=rss------bug_bounty-5)
Why Does Windows Defender Detect Sliver C2 Implants While SentinelOne Does Not?
https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/
<!-- SC_OFF -->I recently discovered something surprising: SentinelOne was unable to detect an EXE implant generated using Sliver C2, while Windows Defender flagged it without issue. I'm trying to understand why this might be the case. Could it be related to differences in detection methodologies between the two? Perhaps Windows Defender has certain signatures or behavioral analysis techniques that SentinelOne doesn't employ? I'm looking for insights or recommendations, especially since I'm preparing to advise a client on endpoint security solutions and want to ensure I'm considering all the nuances. Any thoughts or similar experiences with SentinelOne or other tools in detecting Sliver C2 implants? <!-- SC_ON --> submitted by /u/Survival9421 (https://www.reddit.com/user/Survival9421)
[link] (https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/) [comments] (https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/)
https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/
<!-- SC_OFF -->I recently discovered something surprising: SentinelOne was unable to detect an EXE implant generated using Sliver C2, while Windows Defender flagged it without issue. I'm trying to understand why this might be the case. Could it be related to differences in detection methodologies between the two? Perhaps Windows Defender has certain signatures or behavioral analysis techniques that SentinelOne doesn't employ? I'm looking for insights or recommendations, especially since I'm preparing to advise a client on endpoint security solutions and want to ensure I'm considering all the nuances. Any thoughts or similar experiences with SentinelOne or other tools in detecting Sliver C2 implants? <!-- SC_ON --> submitted by /u/Survival9421 (https://www.reddit.com/user/Survival9421)
[link] (https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/) [comments] (https://www.reddit.com/r/Pentesting/comments/1htxnps/why_does_windows_defender_detect_sliver_c2/)
Is it possible to man in the middle a pppoe connection?
https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/
<!-- SC_OFF -->Im trying to monitor a pppoe connection between my router and the wall with a bridged device running ettercap, but it fails after the pado packet. I see a packet padt with: generic-error: Bye-bye Did it detect that im listening and is mocking me? 😂 <!-- SC_ON --> submitted by /u/Zakiyo (https://www.reddit.com/user/Zakiyo)
[link] (https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/)
https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/
<!-- SC_OFF -->Im trying to monitor a pppoe connection between my router and the wall with a bridged device running ettercap, but it fails after the pado packet. I see a packet padt with: generic-error: Bye-bye Did it detect that im listening and is mocking me? 😂 <!-- SC_ON --> submitted by /u/Zakiyo (https://www.reddit.com/user/Zakiyo)
[link] (https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hu1ew1/is_it_possible_to_man_in_the_middle_a_pppoe/)