Hi everyone! I’m Mahesh Dhakad, Cyber Security Researcher and a Part time bounty hunter, and today, I’m kicking off an exciting journey —…Continue reading on Medium » (https://medium.com/@mahhesshh/day-0-the-100-day-bug-bounty-challenge-sharing-100-vulnerabilities-in-100-days-17308f82d741?source=rss------bug_bounty-5)
Day 0. The 100-Day Bug Bounty Challenge: Sharing 100 Vulnerabilities in 100 Days
Hi everyone! I’m Mahesh Dhakad, Cyber Security Researcher and a Part time bounty hunter, and today, I’m kicking off an exciting journey —…Continue reading on Medium »
Read more...
Hi everyone! I’m Mahesh Dhakad, Cyber Security Researcher and a Part time bounty hunter, and today, I’m kicking off an exciting journey —…Continue reading on Medium »
Read more...
Medium
Day 0. The 100-Day Bug Bounty Challenge: Sharing 100 Vulnerabilities in 100 Days
Hi everyone! I’m Mahesh Dhakad, Cyber Security Researcher and a Part time bounty hunter, and today, I’m kicking off an exciting journey —…
I don't know how to start red teaming
https://www.reddit.com/r/redteamsec/comments/1hwhz1j/i_dont_know_how_to_start_red_teaming/
<!-- SC_OFF -->Some people say I should start with programming such as python, C++ and bash. then take the pen testing route, then take OWASP TOP 10 and practice it, then take OSCP then CRTP and CRTE and now I am officially a red teamer but that's not logical, so what is the actual route that I should follow? only red teamers answer please.. <!-- SC_ON --> submitted by /u/Soft_Ad2049 (https://www.reddit.com/user/Soft_Ad2049)
[link] (https://www.reddit.com/r/redteamsec/comments/1hwhz1j/i_dont_know_how_to_start_red_teaming/) [comments] (https://www.reddit.com/r/redteamsec/comments/1hwhz1j/i_dont_know_how_to_start_red_teaming/)
https://www.reddit.com/r/redteamsec/comments/1hwhz1j/i_dont_know_how_to_start_red_teaming/
<!-- SC_OFF -->Some people say I should start with programming such as python, C++ and bash. then take the pen testing route, then take OWASP TOP 10 and practice it, then take OSCP then CRTP and CRTE and now I am officially a red teamer but that's not logical, so what is the actual route that I should follow? only red teamers answer please.. <!-- SC_ON --> submitted by /u/Soft_Ad2049 (https://www.reddit.com/user/Soft_Ad2049)
[link] (https://www.reddit.com/r/redteamsec/comments/1hwhz1j/i_dont_know_how_to_start_red_teaming/) [comments] (https://www.reddit.com/r/redteamsec/comments/1hwhz1j/i_dont_know_how_to_start_red_teaming/)
Automate-XSS Five-In-One Tool
This toolautomates various methods of detecting cross-site scripting (XSS) vulnerabilities using different tools. It allows the user to…Continue reading on Medium »
Read more...
This toolautomates various methods of detecting cross-site scripting (XSS) vulnerabilities using different tools. It allows the user to…Continue reading on Medium »
Read more...
Medium
Automate-XSS Five-In-One Tool
This toolautomates various methods of detecting cross-site scripting (XSS) vulnerabilities using different tools. It allows the user to…
The Rate Limit bypass which almost killed my brain
My name is Sirat, im an active bug hunter on hackerone. I have previously shared some rate limit stories and how to bypass them, today I…Continue reading on Medium »
Read more...
My name is Sirat, im an active bug hunter on hackerone. I have previously shared some rate limit stories and how to bypass them, today I…Continue reading on Medium »
Read more...
Medium
The Rate Limit bypass which almost killed my brain
My name is Sirat, im an active bug hunter on hackerone.
I have previously shared some rate limit stories and how to bypass them, today I…
I have previously shared some rate limit stories and how to bypass them, today I…
Android RAT !!
https://www.reddit.com/r/Pentesting/comments/1hwjj67/android_rat/
<!-- SC_OFF -->Hy guys , any best Android RAT's out there !! <!-- SC_ON --> submitted by /u/Odd_District_1837 (https://www.reddit.com/user/Odd_District_1837)
[link] (https://www.reddit.com/r/Pentesting/comments/1hwjj67/android_rat/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hwjj67/android_rat/)
https://www.reddit.com/r/Pentesting/comments/1hwjj67/android_rat/
<!-- SC_OFF -->Hy guys , any best Android RAT's out there !! <!-- SC_ON --> submitted by /u/Odd_District_1837 (https://www.reddit.com/user/Odd_District_1837)
[link] (https://www.reddit.com/r/Pentesting/comments/1hwjj67/android_rat/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hwjj67/android_rat/)
Why Companies Should Adopt a Bug Bounty Program
A bug bounty program is not just a security initiative — it’s a business strategy. By inviting ethical hackers to collaborate with your…Continue reading on Medium »
Read more...
A bug bounty program is not just a security initiative — it’s a business strategy. By inviting ethical hackers to collaborate with your…Continue reading on Medium »
Read more...
Medium
Why Companies Should Adopt a Bug Bounty Program
A bug bounty program is not just a security initiative — it’s a business strategy. By inviting ethical hackers to collaborate with your…
Leaky Response, Easy Takeover!
Happy New Year, everyone! 🎉 I hope you’re all doing great. A huge thank you for 200+ followers – I’m truly grateful that you enjoy my…Continue reading on Medium »
Read more...
Happy New Year, everyone! 🎉 I hope you’re all doing great. A huge thank you for 200+ followers – I’m truly grateful that you enjoy my…Continue reading on Medium »
Read more...
Medium
Leaky Response, Easy Takeover!
Happy New Year, everyone! 🎉 I hope you’re all doing great. A huge thank you for 200+ followers – I’m truly grateful that you enjoy my…
Available for Freelance Penetration Testing – Experienced Security Professional
https://www.reddit.com/r/Pentesting/comments/1hwksml/available_for_freelance_penetration_testing/
<!-- SC_OFF -->Hi, I’m Parv Bajaj, a certified Application Security Engineer with over 3 years of experience in cybersecurity. I specialize in: •Web, Mobile, and API Penetration Testing •Network Vulnerability Assessments •Red Teaming and Threat Modeling •Source Code and Cloud Security Reviews •Secure Configuration Assessments I’ve conducted comprehensive security assessments on 35+ products, streamlined penetration testing processes with automation, and helped secure diverse systems, including thick clients, APIs, and mobile apps. Certifications: •eWPTX v2 •eJPT •CEH v11 •AWS Cloud Graduate •CCNA I bring hands-on expertise with tools like Burp Suite, Nessus, Wireshark, and Postman, and have experience working with frameworks like OWASP, MITRE ATT&CK, and PCI DSS. 📍 Open to remote projects worldwide. 💰 Rate: Negotiable based on project scope. Feel free to message me here to discuss your security needs. Let’s collaborate to make your systems more secure! <!-- SC_ON --> submitted by /u/Parvinhisprime (https://www.reddit.com/user/Parvinhisprime)
[link] (https://www.reddit.com/r/Pentesting/comments/1hwksml/available_for_freelance_penetration_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hwksml/available_for_freelance_penetration_testing/)
https://www.reddit.com/r/Pentesting/comments/1hwksml/available_for_freelance_penetration_testing/
<!-- SC_OFF -->Hi, I’m Parv Bajaj, a certified Application Security Engineer with over 3 years of experience in cybersecurity. I specialize in: •Web, Mobile, and API Penetration Testing •Network Vulnerability Assessments •Red Teaming and Threat Modeling •Source Code and Cloud Security Reviews •Secure Configuration Assessments I’ve conducted comprehensive security assessments on 35+ products, streamlined penetration testing processes with automation, and helped secure diverse systems, including thick clients, APIs, and mobile apps. Certifications: •eWPTX v2 •eJPT •CEH v11 •AWS Cloud Graduate •CCNA I bring hands-on expertise with tools like Burp Suite, Nessus, Wireshark, and Postman, and have experience working with frameworks like OWASP, MITRE ATT&CK, and PCI DSS. 📍 Open to remote projects worldwide. 💰 Rate: Negotiable based on project scope. Feel free to message me here to discuss your security needs. Let’s collaborate to make your systems more secure! <!-- SC_ON --> submitted by /u/Parvinhisprime (https://www.reddit.com/user/Parvinhisprime)
[link] (https://www.reddit.com/r/Pentesting/comments/1hwksml/available_for_freelance_penetration_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1hwksml/available_for_freelance_penetration_testing/)
Blind OS Command Injection with Output Redirection
Today, we’ll be diving into another blind vulnerability — a scenario more like what you’ll find while testing applications in the…Continue reading on OSINT Team »
Read more...
Today, we’ll be diving into another blind vulnerability — a scenario more like what you’ll find while testing applications in the…Continue reading on OSINT Team »
Read more...
Medium
Blind OS Command Injection with Output Redirection
Today, we’ll be diving into another blind vulnerability — a scenario more like what you’ll find while testing applications in the…
Exploiting and Detecting Palo Alto Networks CVE-2024-0012
https://www.reddit.com/r/redteamsec/comments/1hwk0bj/exploiting_and_detecting_palo_alto_networks/
submitted by /u/Infosecsamurai (https://www.reddit.com/user/Infosecsamurai)
[link] (https://youtu.be/RgSGjn_Z1dg) [comments] (https://www.reddit.com/r/redteamsec/comments/1hwk0bj/exploiting_and_detecting_palo_alto_networks/)
https://www.reddit.com/r/redteamsec/comments/1hwk0bj/exploiting_and_detecting_palo_alto_networks/
submitted by /u/Infosecsamurai (https://www.reddit.com/user/Infosecsamurai)
[link] (https://youtu.be/RgSGjn_Z1dg) [comments] (https://www.reddit.com/r/redteamsec/comments/1hwk0bj/exploiting_and_detecting_palo_alto_networks/)
How I Ethically Hacked the Indian Army for the Second Time
Hello, Infosec Community!Continue reading on Cyber Security Write-ups »
Read more...
Hello, Infosec Community!Continue reading on Cyber Security Write-ups »
Read more...
Medium
How I Ethically Hacked the Indian Army for the Second Time
Hello, Infosec Community!
Stories of a sporadic bug bounty hunter pt II
Yo, welcome back, everyone, and Happy New Year!Continue reading on Medium »
Read more...
Yo, welcome back, everyone, and Happy New Year!Continue reading on Medium »
Read more...
Medium
Stories of a sporadic bug bounty hunter pt II
Yo, welcome back, everyone, and Happy New Year!
Exposing HTML Injection:$500 Bounty (6/30DAYS)
How a Researcher Earned $500 for Uncovering a Dangerous HTML Injection Flaw !!!Continue reading on Medium »
Read more...
How a Researcher Earned $500 for Uncovering a Dangerous HTML Injection Flaw !!!Continue reading on Medium »
Read more...
Medium
Exposing HTML Injection:$500 Bounty (6/30DAYS)
How a Researcher Earned $500 for Uncovering a Dangerous HTML Injection Flaw !!!
Breaking Barriers: Understanding and Mastering WAF Bypass Techniques
Unveiling the Art of WAF Bypass: Techniques, Payloads, and Ethical Insights for Modern Penetration TestingContinue reading on Medium »
Read more...
Unveiling the Art of WAF Bypass: Techniques, Payloads, and Ethical Insights for Modern Penetration TestingContinue reading on Medium »
Read more...
Medium
Breaking Barriers: Understanding and Mastering WAF Bypass Techniques
Unveiling the Art of WAF Bypass: Techniques, Payloads, and Ethical Insights for Modern Penetration Testing
CISA Alerts: Critical Oracle WebLogic & Mitel Vulnerabilities Exploited!
WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium »
Read more...
WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium »
Read more...
Medium
🚨 CISA Alerts: Critical Oracle WebLogic & Mitel Vulnerabilities Exploited! 🚨
WIRE TOR — The Ethical Hacking Services
Automate-XSS Five-In-One Tool
https://medium.com/@saket590/automate-xss-five-in-one-tool-95a947545b2c?source=rss------bug_bounty-5
This toolautomates various methods of detecting cross-site scripting (XSS) vulnerabilities using different tools. It allows the user to…Continue reading on Medium » (https://medium.com/@saket590/automate-xss-five-in-one-tool-95a947545b2c?source=rss------bug_bounty-5)
https://medium.com/@saket590/automate-xss-five-in-one-tool-95a947545b2c?source=rss------bug_bounty-5
This toolautomates various methods of detecting cross-site scripting (XSS) vulnerabilities using different tools. It allows the user to…Continue reading on Medium » (https://medium.com/@saket590/automate-xss-five-in-one-tool-95a947545b2c?source=rss------bug_bounty-5)
The Rate Limit bypass which almost killed my brain
https://siratsami71.medium.com/this-rate-limit-bypass-which-almost-killed-my-brain-1905749a5f4d?source=rss------bug_bounty-5
https://siratsami71.medium.com/this-rate-limit-bypass-which-almost-killed-my-brain-1905749a5f4d?source=rss------bug_bounty-5
My name is Sirat, im an active bug hunter on hackerone.
I have previously shared some rate limit stories and how to bypass them, today I…Continue reading on Medium » (https://siratsami71.medium.com/this-rate-limit-bypass-which-almost-killed-my-brain-1905749a5f4d?source=rss------bug_bounty-5)
I have previously shared some rate limit stories and how to bypass them, today I…Continue reading on Medium » (https://siratsami71.medium.com/this-rate-limit-bypass-which-almost-killed-my-brain-1905749a5f4d?source=rss------bug_bounty-5)
Why Companies Should Adopt a Bug Bounty Program
https://medium.com/@hackrate/why-companies-should-adopt-a-bug-bounty-program-cd4e1a492989?source=rss------bug_bounty-5
https://medium.com/@hackrate/why-companies-should-adopt-a-bug-bounty-program-cd4e1a492989?source=rss------bug_bounty-5