How Hackers Exploit CORS Misconfigurations
🔐 How Hackers Exploit CORS MisconfigurationsContinue reading on InfoSec Write-ups »
Read more...
🔐 How Hackers Exploit CORS MisconfigurationsContinue reading on InfoSec Write-ups »
Read more...
Medium
How Hackers Exploit CORS Misconfigurations
🔐 How Hackers Exploit CORS Misconfigurations
$2000 Bounty: Stored XSS in GitLab
Exploiting a stored XSS in GitLab’s repository viewer for $2000Continue reading on InfoSec Write-ups »
Read more...
Exploiting a stored XSS in GitLab’s repository viewer for $2000Continue reading on InfoSec Write-ups »
Read more...
Medium
$2000 Bounty: Stored XSS in GitLab
Exploiting a stored XSS in GitLab’s repository viewer for $2000
Query Confusion: How HTTP Parameter Pollution Made the App Spill Secrets
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
Query Confusion: How HTTP Parameter Pollution Made the App Spill Secrets 🧼📤
Hey there!😁
Mastering Runtime Hooking with Frida — Real-World Challenges (Part 3)
Hey folks, welcome back! This is Chetan Kashyap, and I’m excited to bring you Part 3 of my ongoing series on runtime hooking using Frida…Continue reading on Medium »
Read more...
Hey folks, welcome back! This is Chetan Kashyap, and I’m excited to bring you Part 3 of my ongoing series on runtime hooking using Frida…Continue reading on Medium »
Read more...
Medium
Mastering Runtime Hooking with Frida — Real-World Challenges (Part 3)
Hey folks, welcome back! This is Chetan Kashyap, and I’m excited to bring you Part 3 of my ongoing series on runtime hooking using Frida…
Undeleted Secrets: Uncovering an IDOR Vulnerability in “Recently Deleted” Items
During a security assessment of a web application, I identified a critical Insecure Direct Object Reference (IDOR) vulnerability within…Continue reading on Medium »
Read more...
During a security assessment of a web application, I identified a critical Insecure Direct Object Reference (IDOR) vulnerability within…Continue reading on Medium »
Read more...
Medium
Undeleted Secrets: Uncovering an IDOR Vulnerability in “Recently Deleted” Items
During a security assessment of a web application, I identified a critical Insecure Direct Object Reference (IDOR) vulnerability within the…
OAuth Integration Hijack via Predictable state Parameter
Hey there! I’m Kariem Gamal, a bug hunter and penetration test. Today, I’d like to share my recent discovery of an OAuth misconfiguration…Continue reading on Medium »
Read more...
Hey there! I’m Kariem Gamal, a bug hunter and penetration test. Today, I’d like to share my recent discovery of an OAuth misconfiguration…Continue reading on Medium »
Read more...
Medium
OAuth Integration Hijack via Predictable state Parameter
Hey there! I’m Kariem Gamal, a bug hunter and penetration test. Today, I’d like to share my recent discovery of an OAuth misconfiguration…
How Hackers Exploit CORS Misconfigurations
https://infosecwriteups.com/how-hackers-exploit-cors-misconfigurations-35a6c5d7e0c8?source=rss------bug_bounty-5
https://infosecwriteups.com/how-hackers-exploit-cors-misconfigurations-35a6c5d7e0c8?source=rss------bug_bounty-5
🔐 How Hackers Exploit CORS MisconfigurationsContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-hackers-exploit-cors-misconfigurations-35a6c5d7e0c8?source=rss------bug_bounty-5)
Looking for an open-source Agent that can use nmap/metasploit MCP servers
https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/
<!-- SC_OFF -->Do you know any ethical hacker agent project open-source that leverages nmap and metasplout MCP servers in order to have a fully functioning ethical hacker? <!-- SC_ON --> submitted by /u/filopedraz (https://www.reddit.com/user/filopedraz)
[link] (https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/)
https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/
<!-- SC_OFF -->Do you know any ethical hacker agent project open-source that leverages nmap and metasplout MCP servers in order to have a fully functioning ethical hacker? <!-- SC_ON --> submitted by /u/filopedraz (https://www.reddit.com/user/filopedraz)
[link] (https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/)
How I Found Critical Flaws in a Medical SOAP API
My €400 Bug Bounty StoryContinue reading on ILLUMINATION »
Read more...
My €400 Bug Bounty StoryContinue reading on ILLUMINATION »
Read more...
Medium
How I Found Critical Flaws in a Medical SOAP API
My €400 Bug Bounty Story
A list of checklists for bug hunters and penetration testers
Learn new things in your bug bounty and penetration testing journey using these resourcesContinue reading on Medium »
Read more...
Learn new things in your bug bounty and penetration testing journey using these resourcesContinue reading on Medium »
Read more...
Medium
A list of checklists for bug hunters and penetration testers
Learn new things in your bug bounty and penetration testing journey using these resources
Email Enumeration melalui Endpoint POST /api/passwordReset/?h=
Email enumeration merupakan celah keamanan yang memungkinkan pihak luar mengetahui apakah sebuah alamat email terdaftar pada sistem, hanya…Continue reading on Medium »
Read more...
Email enumeration merupakan celah keamanan yang memungkinkan pihak luar mengetahui apakah sebuah alamat email terdaftar pada sistem, hanya…Continue reading on Medium »
Read more...
Medium
📧 Email Enumeration melalui Endpoint POST /api/passwordReset/?h=
Email enumeration merupakan celah keamanan yang memungkinkan pihak luar mengetahui apakah sebuah alamat email terdaftar pada sistem, hanya…
A Must-Have Tool for Bug Hunters: Find Open Redirect Vulnerabilities on Linux
Automate open redirection detection, save hours of manual testing, and level up your bug bounty recon game.Continue reading on InfoSec Write-ups »
Read more...
Automate open redirection detection, save hours of manual testing, and level up your bug bounty recon game.Continue reading on InfoSec Write-ups »
Read more...
Medium
A Must-Have Tool for Bug Hunters: Find Open Redirect Vulnerabilities on Linux
Automate open redirection detection, save hours of manual testing, and level up your bug bounty recon game.
Accidental Hacker: How I Found a Critical Data Leak Bug with Just a Few Clicks
The Accidental DiscoveryContinue reading on Medium »
Read more...
The Accidental DiscoveryContinue reading on Medium »
Read more...
Medium
Accidental Hacker: How I Found a Critical Data Leak Bug with Just a Few Clicks
The Accidental Discovery
I Found Bugs in 50+ Paid Bug Bounty Programs
Hey everyone! I’m Mehrab Opi, a security researcher on platforms like Bugcrowd. Today, I’m sharing my experience and methodology for…Continue reading on Medium »
Read more...
Hey everyone! I’m Mehrab Opi, a security researcher on platforms like Bugcrowd. Today, I’m sharing my experience and methodology for…Continue reading on Medium »
Read more...
Medium
I Found Bugs in 50+ Paid Bug Bounty Programs
Hey everyone! I’m Mehrab Opi, a security researcher on platforms like Bugcrowd. Today, I’m sharing my experience and methodology for…
The Hidden Dangers of Misconfigured Cloud Storage
Today, many businesses turn to cloud storage solutions to improve data management and streamline operations. However, when these services…Continue reading on MeetCyber »
Read more...
Today, many businesses turn to cloud storage solutions to improve data management and streamline operations. However, when these services…Continue reading on MeetCyber »
Read more...
Medium
The Hidden Dangers of Misconfigured Cloud Storage
Today, many businesses turn to cloud storage solutions to improve data management and streamline operations. However, when these services…
How I Built a One-Click Vulnerability Report Generator with Python
Writing detailed, professional vulnerability reports has always been a time-consuming part of penetration testing and security audits. As…Continue reading on Medium »
Read more...
Writing detailed, professional vulnerability reports has always been a time-consuming part of penetration testing and security audits. As…Continue reading on Medium »
Read more...
Medium
How I Built a One-Click Vulnerability Report Generator with Python
Writing detailed, professional vulnerability reports has always been a time-consuming part of penetration testing and security audits. As…
IDOR Allows Unauthorized Access to Other Users’ Personal Data
In this writeup I’ll demonstrate how I got an IDOR with user’s UUIDContinue reading on Medium »
Read more...
In this writeup I’ll demonstrate how I got an IDOR with user’s UUIDContinue reading on Medium »
Read more...
Medium
IDOR Allows Unauthorized Access to Other Users Personal Data
In this writeup I’ll demonstrate how I got an IDOR with user’s UUID