NimDump: Stealthy LSASS Dumping Using Only NTAPIs in Nim
https://www.reddit.com/r/redteamsec/comments/1kf4lle/nimdump_stealthy_lsass_dumping_using_only_ntapis/
submitted by /u/Rare_Bicycle_5705 (https://www.reddit.com/user/Rare_Bicycle_5705)
[link] (https://github.com/ricardojoserf/NativeDump/tree/nim-flavour) [comments] (https://www.reddit.com/r/redteamsec/comments/1kf4lle/nimdump_stealthy_lsass_dumping_using_only_ntapis/)
https://www.reddit.com/r/redteamsec/comments/1kf4lle/nimdump_stealthy_lsass_dumping_using_only_ntapis/
submitted by /u/Rare_Bicycle_5705 (https://www.reddit.com/user/Rare_Bicycle_5705)
[link] (https://github.com/ricardojoserf/NativeDump/tree/nim-flavour) [comments] (https://www.reddit.com/r/redteamsec/comments/1kf4lle/nimdump_stealthy_lsass_dumping_using_only_ntapis/)
Introducing SubHunterX – My Open-Source Recon Automation Tool for Bug Bounty Hunters
https://www.reddit.com/r/redteamsec/comments/1kf5y5y/introducing_subhunterx_my_opensource_recon/
<!-- SC_OFF -->I created SubHunterX to automate and streamline the recon process in bug bounty hunting. It brings together tools like Subfinder, Amass, HTTPx, FFuf, Katana, and GF into one unified workflow to boost speed, coverage, and efficiency. Key Features: Subdomain enumeration (active + passive) DNS resolution and IP mapping Live host detection, crawling, fuzzing Vulnerability pattern matching using GF This is just the beginning. I'm actively working on improving it, and I need your support. If you're into recon, automation, or bug bounty hunting — please contribute, share feedback, report issues, or open a pull request. Let's make SubHunterX more powerful, reliable, and usable for the whole security community. Check it out: https://github.com/who0xac/SubHunterX <!-- SC_ON --> submitted by /u/0xFFac (https://www.reddit.com/user/0xFFac)
[link] (https://github.com/who0xac/SubHunterX) [comments] (https://www.reddit.com/r/redteamsec/comments/1kf5y5y/introducing_subhunterx_my_opensource_recon/)
https://www.reddit.com/r/redteamsec/comments/1kf5y5y/introducing_subhunterx_my_opensource_recon/
<!-- SC_OFF -->I created SubHunterX to automate and streamline the recon process in bug bounty hunting. It brings together tools like Subfinder, Amass, HTTPx, FFuf, Katana, and GF into one unified workflow to boost speed, coverage, and efficiency. Key Features: Subdomain enumeration (active + passive) DNS resolution and IP mapping Live host detection, crawling, fuzzing Vulnerability pattern matching using GF This is just the beginning. I'm actively working on improving it, and I need your support. If you're into recon, automation, or bug bounty hunting — please contribute, share feedback, report issues, or open a pull request. Let's make SubHunterX more powerful, reliable, and usable for the whole security community. Check it out: https://github.com/who0xac/SubHunterX <!-- SC_ON --> submitted by /u/0xFFac (https://www.reddit.com/user/0xFFac)
[link] (https://github.com/who0xac/SubHunterX) [comments] (https://www.reddit.com/r/redteamsec/comments/1kf5y5y/introducing_subhunterx_my_opensource_recon/)
Subdomain Takeover: My $450 Win & How You Can Do It Too
Free Article Link: Click for free!Continue reading on Medium »
Read more...
Free Article Link: Click for free!Continue reading on Medium »
Read more...
Medium
Subdomain Takeover: My $450 Win & How You Can Do It Too
Free Article Link: Click for free!
une XSS simple sur la page de login CVE-2024–48410
Bonjour à tous,Continue reading on Medium »
Read more...
Bonjour à tous,Continue reading on Medium »
Read more...
Medium
une XSS simple sur la page de login CVE-2024–48410
Bonjour à tous,
Cross-Site Request Forgery (CSRF) Made Easy: A Beginner’s Perspective
Cross-Site Request Forgery (CSRF) is a web security vulnerability that tricks users into performing unwanted actions on a web application…Continue reading on Medium »
Read more...
Cross-Site Request Forgery (CSRF) is a web security vulnerability that tricks users into performing unwanted actions on a web application…Continue reading on Medium »
Read more...
Medium
Cross-Site Request Forgery (CSRF) Made Easy: A Beginner’s Perspective
Cross-Site Request Forgery (CSRF) is a web security vulnerability that tricks users into performing unwanted actions on a web application…
Subdomain Takeover: My $450 Win & How You Can Do It Too
https://ehteshamulhaq198.medium.com/subdomain-takeover-my-450-win-how-you-can-do-it-too-3337ca0513b6?source=rss------bug_bounty-5
https://ehteshamulhaq198.medium.com/subdomain-takeover-my-450-win-how-you-can-do-it-too-3337ca0513b6?source=rss------bug_bounty-5
Free Article Link: Click for free!Continue reading on Medium » (https://ehteshamulhaq198.medium.com/subdomain-takeover-my-450-win-how-you-can-do-it-too-3337ca0513b6?source=rss------bug_bounty-5)
une XSS simple sur la page de login CVE-2024–48410
https://medium.com/@Itachi0xf/une-xss-simple-sur-la-page-de-login-cve-2024-48410-65435f4a0f84?source=rss------bug_bounty-5
https://medium.com/@Itachi0xf/une-xss-simple-sur-la-page-de-login-cve-2024-48410-65435f4a0f84?source=rss------bug_bounty-5
Bonjour à tous,Continue reading on Medium » (https://medium.com/@Itachi0xf/une-xss-simple-sur-la-page-de-login-cve-2024-48410-65435f4a0f84?source=rss------bug_bounty-5)
Cross-Site Request Forgery (CSRF) Made Easy: A Beginner’s Perspective
https://medium.com/@natarajanck2/cross-site-request-forgery-csrf-made-easy-a-beginners-perspective-037b4ba6d62a?source=rss------bug_bounty-5
Cross-Site Request Forgery (CSRF) is a web security vulnerability that tricks users into performing unwanted actions on a web application…Continue reading on Medium » (https://medium.com/@natarajanck2/cross-site-request-forgery-csrf-made-easy-a-beginners-perspective-037b4ba6d62a?source=rss------bug_bounty-5)
https://medium.com/@natarajanck2/cross-site-request-forgery-csrf-made-easy-a-beginners-perspective-037b4ba6d62a?source=rss------bug_bounty-5
Cross-Site Request Forgery (CSRF) is a web security vulnerability that tricks users into performing unwanted actions on a web application…Continue reading on Medium » (https://medium.com/@natarajanck2/cross-site-request-forgery-csrf-made-easy-a-beginners-perspective-037b4ba6d62a?source=rss------bug_bounty-5)
Here we go , 2 bugs in the same program
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…Continue reading on Medium »
Read more...
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…Continue reading on Medium »
Read more...
Medium
Here we go 🚨, 2 bugs in the same program
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…
The Ultimate Guide to API Security Testing — Cheat sheet 2025 Edition
I was searching for such resource to work as cheat sheet series and guide me through different attack scenarios for API attacks, didn’t…Continue reading on Medium »
Read more...
I was searching for such resource to work as cheat sheet series and guide me through different attack scenarios for API attacks, didn’t…Continue reading on Medium »
Read more...
Medium
The Ultimate Guide to API Security Testing — Cheat sheet 2025 — Part1
I was searching for such resource to work as cheat sheet series and guide me through different attack scenarios for API attacks, didn’t…
Hacker’s Recon Guide: Tools & Tricks to Map Any Target
In the realm of cybersecurity, reconnaissance is the foundational phase that sets the stage for any ethical hacking or penetration testing…Continue reading on OSINT Team »
Read more...
In the realm of cybersecurity, reconnaissance is the foundational phase that sets the stage for any ethical hacking or penetration testing…Continue reading on OSINT Team »
Read more...
Medium
🧠 Hacker’s Recon Guide: Tools & Tricks to Map Any Target
In the realm of cybersecurity, reconnaissance is the foundational phase that sets the stage for any ethical hacking or penetration testing…
$500 Bounty for Reflected XSS on HackerOne
How a Security Researcher Earned $500 by Discovering Reflected XSS on HackerOneContinue reading on OSINT Team »
Read more...
How a Security Researcher Earned $500 by Discovering Reflected XSS on HackerOneContinue reading on OSINT Team »
Read more...
Medium
$500 Bounty for Reflected XSS on HackerOne
How a Security Researcher Earned $500 by Discovering Reflected XSS on HackerOne
What are we on? A survey on substance use among cybersecurity professionals.
https://www.reddit.com/r/redteamsec/comments/1kflpfn/what_are_we_on_a_survey_on_substance_use_among/
submitted by /u/mind_f3ck (https://www.reddit.com/user/mind_f3ck)
[link] (https://forms.gle/GdfVJDPnZHVz1jY67) [comments] (https://www.reddit.com/r/redteamsec/comments/1kflpfn/what_are_we_on_a_survey_on_substance_use_among/)
https://www.reddit.com/r/redteamsec/comments/1kflpfn/what_are_we_on_a_survey_on_substance_use_among/
submitted by /u/mind_f3ck (https://www.reddit.com/user/mind_f3ck)
[link] (https://forms.gle/GdfVJDPnZHVz1jY67) [comments] (https://www.reddit.com/r/redteamsec/comments/1kflpfn/what_are_we_on_a_survey_on_substance_use_among/)
The Ultimate Guide to API Security Testing — Cheat sheet 2025 Edition
https://t4144t.medium.com/the-ultimate-guide-to-api-security-testing-cheat-sheet-2025-edition-b64fd3d158dd?source=rss------bug_bounty-5
https://t4144t.medium.com/the-ultimate-guide-to-api-security-testing-cheat-sheet-2025-edition-b64fd3d158dd?source=rss------bug_bounty-5