A deep dive into my methodical approach, unique tricks, and how I exploited a misimplementation of PayU on a target website for a big…Continue reading on Medium » (https://eulex.medium.com/how-i-made-9-000-in-one-month-from-bug-bounty-9403147b4d07?source=rss------bug_bounty-5)
From LFI to RCE: How I Turned a File Read into Shell Access
https://medium.com/@sujeetkamblesrk/from-lfi-to-rce-how-i-turned-a-file-read-into-shell-access-073ec2e5501e?source=rss------bug_bounty-5
https://medium.com/@sujeetkamblesrk/from-lfi-to-rce-how-i-turned-a-file-read-into-shell-access-073ec2e5501e?source=rss------bug_bounty-5
Hello everyone! Welcome to my very first blog post. Today, I’m thrilled to share a recent breakthrough where I transformed a Local File…Continue reading on Medium » (https://medium.com/@sujeetkamblesrk/from-lfi-to-rce-how-i-turned-a-file-read-into-shell-access-073ec2e5501e?source=rss------bug_bounty-5)
Bug Bounty Tips: Exploiting .git File Disclosure for Fun & Profit
https://frostyxsec.medium.com/bug-bounty-tips-exploiting-git-file-disclosure-for-fun-profit-5a85e82e580c?source=rss------bug_bounty-5
https://frostyxsec.medium.com/bug-bounty-tips-exploiting-git-file-disclosure-for-fun-profit-5a85e82e580c?source=rss------bug_bounty-5
When performing a penetration test, one of the most overlooked but critical misconfigurations is .git file disclosure.Continue reading on Medium » (https://frostyxsec.medium.com/bug-bounty-tips-exploiting-git-file-disclosure-for-fun-profit-5a85e82e580c?source=rss------bug_bounty-5)
Bug Bounty Tips: Exploiting .git File Disclosure for Fun & Profit
When performing a penetration test, one of the most overlooked but critical misconfigurations is .git file disclosure.Continue reading on Medium »
Read more...
When performing a penetration test, one of the most overlooked but critical misconfigurations is .git file disclosure.Continue reading on Medium »
Read more...
Medium
🔍 Bug Bounty Tips: Exploiting .git File Disclosure for Fun & Profit
When performing a penetration test, one of the most overlooked but critical misconfigurations is .git file disclosure.
DorkMine — Unleash the Power of Google Dorking Like Never Before!
Open-source dork engine for bug bounty hunters and security researchers.Continue reading on Medium »
Read more...
Open-source dork engine for bug bounty hunters and security researchers.Continue reading on Medium »
Read more...
Medium
DorkMine — Unleash the Power of Google Dorking Like Never Before!
Open-source dork engine for bug bounty hunters and security researchers.
Bug Bounty Automation: Save Time with These Smart Hacking Scripts — @verylazytech
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Bug Bounty Automation: Save Time with These Smart Hacking Scripts — @verylazytech
Introduction
The Ultimate Roadmap to Becoming a Bug Bounty Hunter
Zero to Hero in Bug BountyContinue reading on Medium »
Read more...
Zero to Hero in Bug BountyContinue reading on Medium »
Read more...
Medium
The Ultimate Roadmap to Becoming a Bug Bounty Hunter
Zero to Hero in Bug Bounty
Hello everyone I need help in my cybersecurity lab I ll fail my final project 😭
https://www.reddit.com/r/Pentesting/comments/1jnomxa/hello_everyone_i_need_help_in_my_cybersecurity/
<!-- SC_OFF -->Hello guys it s been really good time since I have issues with my cyber security lab first once I try to apply changes on intrusion detection in opnsense it freezes immediately and I got timeouts and once I try to connect to sftp server I don t know how to download custom nmap rules and xml file please help me out 😭 <!-- SC_ON --> submitted by /u/Historical-Ring8382 (https://www.reddit.com/user/Historical-Ring8382)
[link] (https://www.reddit.com/r/Pentesting/comments/1jnomxa/hello_everyone_i_need_help_in_my_cybersecurity/) [comments] (https://www.reddit.com/r/Pentesting/comments/1jnomxa/hello_everyone_i_need_help_in_my_cybersecurity/)
https://www.reddit.com/r/Pentesting/comments/1jnomxa/hello_everyone_i_need_help_in_my_cybersecurity/
<!-- SC_OFF -->Hello guys it s been really good time since I have issues with my cyber security lab first once I try to apply changes on intrusion detection in opnsense it freezes immediately and I got timeouts and once I try to connect to sftp server I don t know how to download custom nmap rules and xml file please help me out 😭 <!-- SC_ON --> submitted by /u/Historical-Ring8382 (https://www.reddit.com/user/Historical-Ring8382)
[link] (https://www.reddit.com/r/Pentesting/comments/1jnomxa/hello_everyone_i_need_help_in_my_cybersecurity/) [comments] (https://www.reddit.com/r/Pentesting/comments/1jnomxa/hello_everyone_i_need_help_in_my_cybersecurity/)
Next steps for a cybersecurity engineer
https://www.reddit.com/r/Pentesting/comments/1jnrxzv/next_steps_for_a_cybersecurity_engineer/
<!-- SC_OFF -->I’m currently a security engineer who wants to pivot into offense. My boss wants me to and offensive work is super fun. I’ve done some light testing in my last role and have about 5 years experience in IT (2 of which are in security). I have the sec+, sscp, cysa+, SAL1, and pentest+ Is the OSCP worth it? Or should I just focus on tryhackme, htb, and CTFs? Is eJPT or PJPT/PNPT worth it for me or should I jump straight into OSCP? I know a bit about internal network pentesting, but hardly anything about web stuff or appsec. <!-- SC_ON --> submitted by /u/at0micpub (https://www.reddit.com/user/at0micpub)
[link] (https://www.reddit.com/r/Pentesting/comments/1jnrxzv/next_steps_for_a_cybersecurity_engineer/) [comments] (https://www.reddit.com/r/Pentesting/comments/1jnrxzv/next_steps_for_a_cybersecurity_engineer/)
https://www.reddit.com/r/Pentesting/comments/1jnrxzv/next_steps_for_a_cybersecurity_engineer/
<!-- SC_OFF -->I’m currently a security engineer who wants to pivot into offense. My boss wants me to and offensive work is super fun. I’ve done some light testing in my last role and have about 5 years experience in IT (2 of which are in security). I have the sec+, sscp, cysa+, SAL1, and pentest+ Is the OSCP worth it? Or should I just focus on tryhackme, htb, and CTFs? Is eJPT or PJPT/PNPT worth it for me or should I jump straight into OSCP? I know a bit about internal network pentesting, but hardly anything about web stuff or appsec. <!-- SC_ON --> submitted by /u/at0micpub (https://www.reddit.com/user/at0micpub)
[link] (https://www.reddit.com/r/Pentesting/comments/1jnrxzv/next_steps_for_a_cybersecurity_engineer/) [comments] (https://www.reddit.com/r/Pentesting/comments/1jnrxzv/next_steps_for_a_cybersecurity_engineer/)
Pentesting pulse secure
https://www.reddit.com/r/Pentesting/comments/1jnyead/pentesting_pulse_secure/
<!-- SC_OFF -->Hi guys, expect for known cves what would you check in an engagement against pulse secure connect? <!-- SC_ON --> submitted by /u/Any_Leadership_8920 (https://www.reddit.com/user/Any_Leadership_8920)
[link] (https://www.reddit.com/r/Pentesting/comments/1jnyead/pentesting_pulse_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1jnyead/pentesting_pulse_secure/)
https://www.reddit.com/r/Pentesting/comments/1jnyead/pentesting_pulse_secure/
<!-- SC_OFF -->Hi guys, expect for known cves what would you check in an engagement against pulse secure connect? <!-- SC_ON --> submitted by /u/Any_Leadership_8920 (https://www.reddit.com/user/Any_Leadership_8920)
[link] (https://www.reddit.com/r/Pentesting/comments/1jnyead/pentesting_pulse_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1jnyead/pentesting_pulse_secure/)
How I Hacked My School Website (And Reported It!)
Yo, what’s up? ChrolloD here. So, this is a quick write-up on how I hacked my school’s website one random afternoon. Turns out, they had a…Continue reading on Medium »
Read more...
Yo, what’s up? ChrolloD here. So, this is a quick write-up on how I hacked my school’s website one random afternoon. Turns out, they had a…Continue reading on Medium »
Read more...
Medium
How I Hacked My School Website (And Reported It!)
Yo, what’s up? ChrolloD here. So, this is a quick write-up on how I hacked my school’s website one random afternoon. Turns out, they had a…
I Went on the Dark Web and Instantly Regretted It
I Went on the Dark Web and Instantly Regretted It 😨🌑Continue reading on Medium »
Read more...
I Went on the Dark Web and Instantly Regretted It 😨🌑Continue reading on Medium »
Read more...
Medium
I Went on the Dark Web and Instantly Regretted It 😨🌑
I Went on the Dark Web and Instantly Regretted It 😨🌑
DorkMine — Unleash the Power of Google Dorking Like Never Before!
https://gktomic.medium.com/dorkmine-unleash-the-power-of-google-dorking-like-never-before-0eca2f05e111?source=rss------bug_bounty-5
https://gktomic.medium.com/dorkmine-unleash-the-power-of-google-dorking-like-never-before-0eca2f05e111?source=rss------bug_bounty-5
Open-source dork engine for bug bounty hunters and security researchers.Continue reading on Medium » (https://gktomic.medium.com/dorkmine-unleash-the-power-of-google-dorking-like-never-before-0eca2f05e111?source=rss------bug_bounty-5)
Bug Bounty Automation: Save Time with These Smart Hacking Scripts — @verylazytech
https://medium.com/@verylazytech/bug-bounty-automation-save-time-with-these-smart-hacking-scripts-verylazytech-5b42f6602636?source=rss------bug_bounty-5
https://medium.com/@verylazytech/bug-bounty-automation-save-time-with-these-smart-hacking-scripts-verylazytech-5b42f6602636?source=rss------bug_bounty-5