Upcoming Interview for Vulnerability & Pen Testing Co-op
https://www.reddit.com/r/Pentesting/comments/1k66u72/upcoming_interview_for_vulnerability_pen_testing/
<!-- SC_OFF -->I just got scheduled for an interview in two days. Any ways to help prepare for the interview. It is a co-op position for Vulnerability & Pen Testing. Possible Interview Questions will help alot. Thank you <!-- SC_ON --> submitted by /u/F-Raheem (https://www.reddit.com/user/F-Raheem)
[link] (https://www.reddit.com/r/Pentesting/comments/1k66u72/upcoming_interview_for_vulnerability_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k66u72/upcoming_interview_for_vulnerability_pen_testing/)
https://www.reddit.com/r/Pentesting/comments/1k66u72/upcoming_interview_for_vulnerability_pen_testing/
<!-- SC_OFF -->I just got scheduled for an interview in two days. Any ways to help prepare for the interview. It is a co-op position for Vulnerability & Pen Testing. Possible Interview Questions will help alot. Thank you <!-- SC_ON --> submitted by /u/F-Raheem (https://www.reddit.com/user/F-Raheem)
[link] (https://www.reddit.com/r/Pentesting/comments/1k66u72/upcoming_interview_for_vulnerability_pen_testing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k66u72/upcoming_interview_for_vulnerability_pen_testing/)
Man in trouble again
https://www.reddit.com/r/Pentesting/comments/1k6e9bm/man_in_trouble_again/
<!-- SC_OFF -->does spoofing mac id even work now day when trying to gain access just general question like trusted device?? <!-- SC_ON --> submitted by /u/Sweaty_Kiwi5077 (https://www.reddit.com/user/Sweaty_Kiwi5077)
[link] (https://www.reddit.com/r/Pentesting/comments/1k6e9bm/man_in_trouble_again/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k6e9bm/man_in_trouble_again/)
https://www.reddit.com/r/Pentesting/comments/1k6e9bm/man_in_trouble_again/
<!-- SC_OFF -->does spoofing mac id even work now day when trying to gain access just general question like trusted device?? <!-- SC_ON --> submitted by /u/Sweaty_Kiwi5077 (https://www.reddit.com/user/Sweaty_Kiwi5077)
[link] (https://www.reddit.com/r/Pentesting/comments/1k6e9bm/man_in_trouble_again/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k6e9bm/man_in_trouble_again/)
Can’t find anything really impactful and feel stressed about my skills
https://www.reddit.com/r/Pentesting/comments/1k6jp4f/cant_find_anything_really_impactful_and_feel/
<!-- SC_OFF -->Hi pentesters. I recently landed my first job as a pentester at a consulting firm, which is a dream come true after two years of self-study and earning my OSCP, I also did most of the cpts and cbbh role paths on htb academy. However, I’m feeling really overwhelmed. My colleagues are incredibly skilled, with 3 and 10 years of experience, and they’re amazing at programming, often creating their own tools and write their own exploits. I, on the other hand, have zero programming background and jumped straight into offensive security. When I read their reports, they always seem to find impactful vulnerabilities, but I struggle to keep up during 4-5 day engagement projects. I’m worried about not meeting expectations and getting fired. I tried so hard to get into this field and really don’t want to lose my job. I know it’s impossible to catch up with these guys in a short period of time but any advice on how to improve quickly or manage my stress would be greatly appreciated. Thanks in advance! <!-- SC_ON --> submitted by /u/Downtown-Mango-3861 (https://www.reddit.com/user/Downtown-Mango-3861)
[link] (https://www.reddit.com/r/Pentesting/comments/1k6jp4f/cant_find_anything_really_impactful_and_feel/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k6jp4f/cant_find_anything_really_impactful_and_feel/)
https://www.reddit.com/r/Pentesting/comments/1k6jp4f/cant_find_anything_really_impactful_and_feel/
<!-- SC_OFF -->Hi pentesters. I recently landed my first job as a pentester at a consulting firm, which is a dream come true after two years of self-study and earning my OSCP, I also did most of the cpts and cbbh role paths on htb academy. However, I’m feeling really overwhelmed. My colleagues are incredibly skilled, with 3 and 10 years of experience, and they’re amazing at programming, often creating their own tools and write their own exploits. I, on the other hand, have zero programming background and jumped straight into offensive security. When I read their reports, they always seem to find impactful vulnerabilities, but I struggle to keep up during 4-5 day engagement projects. I’m worried about not meeting expectations and getting fired. I tried so hard to get into this field and really don’t want to lose my job. I know it’s impossible to catch up with these guys in a short period of time but any advice on how to improve quickly or manage my stress would be greatly appreciated. Thanks in advance! <!-- SC_ON --> submitted by /u/Downtown-Mango-3861 (https://www.reddit.com/user/Downtown-Mango-3861)
[link] (https://www.reddit.com/r/Pentesting/comments/1k6jp4f/cant_find_anything_really_impactful_and_feel/) [comments] (https://www.reddit.com/r/Pentesting/comments/1k6jp4f/cant_find_anything_really_impactful_and_feel/)
What kind of phishing copy would be more suitable nowadays?
https://www.reddit.com/r/redteamsec/comments/1k6k042/what_kind_of_phishing_copy_would_be_more_suitable/
<!-- SC_OFF -->Under the condition where there are experienced operations personnel and strict EDR detection, how should phishing be conducted? What kind of phishing copy would be more suitable nowadays? I think sending resumes and compressed files is probably the most direct and efficient method so far, but when sending via IM software, such as WhatsApp, once delivered, the operations personnel will see “Oh, there’s an exe under the WhatsApp path, pretending to be a resume.” So how should this issue be addressed? We’re not hackers; we are a red team targeting a specific individual. How can we make phishing more cool and effective? I think this is a very good topic. <!-- SC_ON --> submitted by /u/No_Atmosphere1271 (https://www.reddit.com/user/No_Atmosphere1271)
[link] (https://wuu.wikipedia.org/wiki/%E9%92%93%E9%B1%BC%E5%BC%8F%E6%94%BB%E5%87%BB) [comments] (https://www.reddit.com/r/redteamsec/comments/1k6k042/what_kind_of_phishing_copy_would_be_more_suitable/)
https://www.reddit.com/r/redteamsec/comments/1k6k042/what_kind_of_phishing_copy_would_be_more_suitable/
<!-- SC_OFF -->Under the condition where there are experienced operations personnel and strict EDR detection, how should phishing be conducted? What kind of phishing copy would be more suitable nowadays? I think sending resumes and compressed files is probably the most direct and efficient method so far, but when sending via IM software, such as WhatsApp, once delivered, the operations personnel will see “Oh, there’s an exe under the WhatsApp path, pretending to be a resume.” So how should this issue be addressed? We’re not hackers; we are a red team targeting a specific individual. How can we make phishing more cool and effective? I think this is a very good topic. <!-- SC_ON --> submitted by /u/No_Atmosphere1271 (https://www.reddit.com/user/No_Atmosphere1271)
[link] (https://wuu.wikipedia.org/wiki/%E9%92%93%E9%B1%BC%E5%BC%8F%E6%94%BB%E5%87%BB) [comments] (https://www.reddit.com/r/redteamsec/comments/1k6k042/what_kind_of_phishing_copy_would_be_more_suitable/)
❌ Top 10 Mistakes Beginners Make in Bug Bounty — Avoid These!
Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Medium
❌ Top 10 Mistakes Beginners Make in Bug Bounty — Avoid These!
Free Article Link
Burp, Bounce, and Break: How Web Cache Poisoning Let Me Control the App
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
Burp, Bounce, and Break: How Web Cache Poisoning Let Me Control the App 🎈🌐
Hey there!😁
How to Create a Botnet Using One Tool: A Proof of Concept for Educational Purposes Aspiring…
Learn how attackers build and control botnets — safely and ethically — using a lightweight POC tool designed for cybersecurity education.Continue reading on InfoSec Write-ups »
Read more...
Learn how attackers build and control botnets — safely and ethically — using a lightweight POC tool designed for cybersecurity education.Continue reading on InfoSec Write-ups »
Read more...
Medium
How to Create a Botnet Using One Tool: A Proof of Concept for Educational Purposes Aspiring Security Researchers
Learn how attackers build and control botnets — safely and ethically — using a lightweight POC tool designed for cybersecurity education.
Email Verification Bypass during Account Creation | Insecure Design
Hello! While hunting on a public program, I discovered a simple flaw that made it possible to create an account without verifying its email address. The website contained an embedded app that required users to verify a phone number. After entering the code, the application required submitting personal information before verifying an email. An unusual request was made to http://redacted.us-east-1.aws.squid.cloud/query/batchQueries. It fetched user profile information from a local instance of Firebase even though registration was still in progress. Strange. I took a closer look and noticed the email verification token was included as profile data.Structure of verificationToken Sending a GET request to https://www.redacted.com/auth/verify?lid=redact ed&token=eyJlbWFpbCI6InJ2YW53YXJ0QHdlYXJlaGFja2Vyb25lLmNvbSIsImV4cCI6MTc0NTM4MjQ1NDQxOSwic2FsdCI6Im1lcTRsNWtxMWMifQ== finalized account creation. I found this endpoint after previously creating an account. This vulnerability is an example of security through obscurity. Using it would would make it possible to register with any unused email address and potentially impersonate other users or staff.Remediation Prohibit users from accessing profile data until registration is complete. If that is not possible, consider moving verification tokens to a table in Firebase with restricted access. Email Verification Bypass during Account Creation | Insecure Design was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Hello! While hunting on a public program, I discovered a simple flaw that made it possible to create an account without verifying its email address. The website contained an embedded app that required users to verify a phone number. After entering the code, the application required submitting personal information before verifying an email. An unusual request was made to http://redacted.us-east-1.aws.squid.cloud/query/batchQueries. It fetched user profile information from a local instance of Firebase even though registration was still in progress. Strange. I took a closer look and noticed the email verification token was included as profile data.Structure of verificationToken Sending a GET request to https://www.redacted.com/auth/verify?lid=redact ed&token=eyJlbWFpbCI6InJ2YW53YXJ0QHdlYXJlaGFja2Vyb25lLmNvbSIsImV4cCI6MTc0NTM4MjQ1NDQxOSwic2FsdCI6Im1lcTRsNWtxMWMifQ== finalized account creation. I found this endpoint after previously creating an account. This vulnerability is an example of security through obscurity. Using it would would make it possible to register with any unused email address and potentially impersonate other users or staff.Remediation Prohibit users from accessing profile data until registration is complete. If that is not possible, consider moving verification tokens to a table in Firebase with restricted access. Email Verification Bypass during Account Creation | Insecure Design was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Nothing changed… except for one detail. And that was enough to hack
Sometimes, hacking doesn’t require any exploit… just good observation.Continue reading on InfoSec Write-ups »
Read more...
Sometimes, hacking doesn’t require any exploit… just good observation.Continue reading on InfoSec Write-ups »
Read more...
Medium
Nothing changed… except for one detail. And that was enough to hack
Sometimes, hacking doesn’t require any exploit… just good observation.
How I discovered a hidden user thanks to server responses ?
My first real step into web hacking and it wasn’t what i thought it would be.Continue reading on InfoSec Write-ups »
Read more...
My first real step into web hacking and it wasn’t what i thought it would be.Continue reading on InfoSec Write-ups »
Read more...
Medium
🔍 How I discovered a hidden user thanks to server responses ?
My first real step into web hacking and it wasn’t what i thought it would be.
I Used AI to Write a Payload… And It Worked (Sort of)
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Medium
I Used AI to Write a Payload… And It Worked (Sort of) 🤖💥
🎯Free Article Link
Bug Bounty: failure experience records
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium »
Read more...
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium »
Read more...
Medium
Bug Bounty: failure experience records
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.
I Used AI to Write a Payload… And It Worked (Sort of)
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
🎯Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Medium
I Used AI to Write a Payload… And It Worked (Sort of) 🤖💥
🎯Free Article Link
Arjun: The Ultimate Parameter Discovery Tool For Bug Hunters
Uncovering Hidden Secrets in Web Apps with ArjunContinue reading on Medium »
Read more...
Uncovering Hidden Secrets in Web Apps with ArjunContinue reading on Medium »
Read more...
Medium
Arjun: The Ultimate Parameter Discovery Tool For Bug Hunters
Uncovering Hidden Secrets in Web Apps with Arjun
Hijacking Trust: The Parallels Between Use-After-Free and Insecure Deserialization
https://medium.com/@MasoudAbdaal/hijacking-trust-the-parallels-between-use-after-free-and-insecure-deserialization-a12c587a2987?source=rss------bug_bounty-5
https://medium.com/@MasoudAbdaal/hijacking-trust-the-parallels-between-use-after-free-and-insecure-deserialization-a12c587a2987?source=rss------bug_bounty-5
I Used AI to Write a Payload… And It Worked (Sort of)
https://infosecwriteups.com/i-used-ai-to-write-a-payload-and-it-worked-sort-of-55b6860d8be9?source=rss------bug_bounty-5
https://infosecwriteups.com/i-used-ai-to-write-a-payload-and-it-worked-sort-of-55b6860d8be9?source=rss------bug_bounty-5
🎯Free Article LinkContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/i-used-ai-to-write-a-payload-and-it-worked-sort-of-55b6860d8be9?source=rss------bug_bounty-5)
Bug Bounty: failure experience records
https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium » (https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5)
https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5
Bug bounty requires luck in addition to skills, because the final result is only yes or no, there is no middle option.Continue reading on Medium » (https://medium.com/@smilemil/bug-bounty-failure-experience-records-62e928efd54a?source=rss------bug_bounty-5)