How I Earned my Second Bounty of €2000 by Discovering an Authorization Bypass Vulnerability in a…
https://medium.com/@sohelparashar/how-i-earned-my-second-bounty-of-2000-by-discovering-an-authorization-bypass-vulnerability-in-a-8b20570004d8?source=rss------bug_bounty-5
https://medium.com/@sohelparashar/how-i-earned-my-second-bounty-of-2000-by-discovering-an-authorization-bypass-vulnerability-in-a-8b20570004d8?source=rss------bug_bounty-5
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…Continue reading on Medium » (https://medium.com/@sohelparashar/how-i-earned-my-second-bounty-of-2000-by-discovering-an-authorization-bypass-vulnerability-in-a-8b20570004d8?source=rss------bug_bounty-5)
$2,400 in 60 Minutes: Hacking a Management Backend by Tweaking a Single Response Packet
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.Continue reading on Medium »
Read more...
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.Continue reading on Medium »
Read more...
Medium
$2,400 in 60 Minutes: Hacking a Management Backend by Tweaking a Single Response Packet
It’s been a while since I last updated. I recently encountered an interesting vulnerability, so I thought I’d share it with you all.
How I Earned my Second Bounty of €2000 by Discovering an Authorization Bypass Vulnerability in a…
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…Continue reading on Medium »
Read more...
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…Continue reading on Medium »
Read more...
Medium
💰How I Earned my Second Bounty of €2000 by Discovering an Authorization Bypass Vulnerability in a Document Management Platform
In this blog, I’ll walk you through my second successful bug bounty, a critical Authorization Bypass File Read vulnerability I discovered…
$3,500 Bounty: Stored XSS in GitLab’s RDoc Wiki via Malicious Image Links
https://medium.com/h7w/3-500-bounty-stored-xss-in-gitlabs-rdoc-wiki-via-malicious-image-links-c394d4730d2a?source=rss------bug_bounty-5
https://medium.com/h7w/3-500-bounty-stored-xss-in-gitlabs-rdoc-wiki-via-malicious-image-links-c394d4730d2a?source=rss------bug_bounty-5
How Improper Sanitization in RDoc Pages Let Attackers Inject Persistent XSS Payloads on GitLab.comContinue reading on T3CH » (https://medium.com/h7w/3-500-bounty-stored-xss-in-gitlabs-rdoc-wiki-via-malicious-image-links-c394d4730d2a?source=rss------bug_bounty-5)
How Hackers Discover Hidden Admin Panels and Secret Files ️♂️
https://osintteam.blog/how-hackers-discover-hidden-admin-panels-and-secret-files-%EF%B8%8F-%EF%B8%8F-c2b12ab0b841?source=rss------bug_bounty-5
https://osintteam.blog/how-hackers-discover-hidden-admin-panels-and-secret-files-%EF%B8%8F-%EF%B8%8F-c2b12ab0b841?source=rss------bug_bounty-5
IntroductionContinue reading on OSINT Team » (https://osintteam.blog/how-hackers-discover-hidden-admin-panels-and-secret-files-%EF%B8%8F-%EF%B8%8F-c2b12ab0b841?source=rss------bug_bounty-5)
$3,500 Bounty: Stored XSS in GitLab’s RDoc Wiki via Malicious Image Links
How Improper Sanitization in RDoc Pages Let Attackers Inject Persistent XSS Payloads on GitLab.comContinue reading on T3CH »
Read more...
How Improper Sanitization in RDoc Pages Let Attackers Inject Persistent XSS Payloads on GitLab.comContinue reading on T3CH »
Read more...
Medium
$3,500 Bounty: Stored XSS in GitLab’s RDoc Wiki via Malicious Image Links
How Improper Sanitization in RDoc Pages Let Attackers Inject Persistent XSS Payloads on GitLab.com
How Hackers Discover Hidden Admin Panels and Secret Files ️♂️
IntroductionContinue reading on OSINT Team »
Read more...
IntroductionContinue reading on OSINT Team »
Read more...
Medium
How Hackers Discover Hidden Admin Panels and Secret Files 🕵️♂️🔍
Introduction
Any Cybersecurity Companies to Avoid When Shopping for Pentesting?
https://www.reddit.com/r/Pentesting/comments/1krk867/any_cybersecurity_companies_to_avoid_when/
<!-- SC_OFF -->I’m hunting for a decent pentesting company for a work project, and I’m getting so fed up with the process. I keep finding these firms that go on and on about being the “number one pentesting company” all over their website and blog posts. But when you look closer, it’s just their own hype. No real proof, no independent reviews, just them saying they’re the best. Also, sometimes, it is just links too in their own webpage that point to other people saying they are the best but when you look at the article, it was just put there by them. It’s annoying and makes me wonder if they’re even legit. I'm doing searches for various pentest companies and many at the top aren't good or when I dig into them, they have a ridiculous amount of lawsuits against them (just look it up yourself, wtf?!) Has anyone else run into companies like this? Ones that claim they’re the best but it’s all based on their own marketing? Then when I searched them deeper, they had a bunch of lawsuits against them. How do you figure out who’s actually good and who’s just full of it? It would be nice to find a pentesting provider that doesn't cost an arm/leg, but these self-proclaimed “number one” types are making me doubt everyone. Any companies you’d avoid or red flags to watch for? Also, any tips on how to vet these firms would be awesome. Thanks for any help. I just want to find someone solid without all the marketing nonsense. Just to clarify, I’m mostly annoyed by companies that keep saying they’re the best without any real evidence which makes me not trust them more. Any tricks to check if a pentesting firm is actually trustworthy? <!-- SC_ON --> submitted by /u/Affectionate-Tie5816 (https://www.reddit.com/user/Affectionate-Tie5816)
[link] (https://www.reddit.com/r/Pentesting/comments/1krk867/any_cybersecurity_companies_to_avoid_when/) [comments] (https://www.reddit.com/r/Pentesting/comments/1krk867/any_cybersecurity_companies_to_avoid_when/)
https://www.reddit.com/r/Pentesting/comments/1krk867/any_cybersecurity_companies_to_avoid_when/
<!-- SC_OFF -->I’m hunting for a decent pentesting company for a work project, and I’m getting so fed up with the process. I keep finding these firms that go on and on about being the “number one pentesting company” all over their website and blog posts. But when you look closer, it’s just their own hype. No real proof, no independent reviews, just them saying they’re the best. Also, sometimes, it is just links too in their own webpage that point to other people saying they are the best but when you look at the article, it was just put there by them. It’s annoying and makes me wonder if they’re even legit. I'm doing searches for various pentest companies and many at the top aren't good or when I dig into them, they have a ridiculous amount of lawsuits against them (just look it up yourself, wtf?!) Has anyone else run into companies like this? Ones that claim they’re the best but it’s all based on their own marketing? Then when I searched them deeper, they had a bunch of lawsuits against them. How do you figure out who’s actually good and who’s just full of it? It would be nice to find a pentesting provider that doesn't cost an arm/leg, but these self-proclaimed “number one” types are making me doubt everyone. Any companies you’d avoid or red flags to watch for? Also, any tips on how to vet these firms would be awesome. Thanks for any help. I just want to find someone solid without all the marketing nonsense. Just to clarify, I’m mostly annoyed by companies that keep saying they’re the best without any real evidence which makes me not trust them more. Any tricks to check if a pentesting firm is actually trustworthy? <!-- SC_ON --> submitted by /u/Affectionate-Tie5816 (https://www.reddit.com/user/Affectionate-Tie5816)
[link] (https://www.reddit.com/r/Pentesting/comments/1krk867/any_cybersecurity_companies_to_avoid_when/) [comments] (https://www.reddit.com/r/Pentesting/comments/1krk867/any_cybersecurity_companies_to_avoid_when/)
$500 Bounty: DOM-Based XSS in HackerOne’s Careers Page
How a Simple URL Parameter and a JS Library Opened a Door to XSS in IE/EdgeContinue reading on OSINT Team »
Read more...
How a Simple URL Parameter and a JS Library Opened a Door to XSS in IE/EdgeContinue reading on OSINT Team »
Read more...
Medium
$500 Bounty: DOM-Based XSS in HackerOne’s Careers Page
How a Simple URL Parameter and a JS Library Opened a Door to XSS in IE/Edge
$500 Bounty: DOM-Based XSS in HackerOne’s Careers Page
https://osintteam.blog/500-bounty-dom-based-xss-in-hackerones-careers-page-019f78c5e213?source=rss------bug_bounty-5
https://osintteam.blog/500-bounty-dom-based-xss-in-hackerones-careers-page-019f78c5e213?source=rss------bug_bounty-5
How a Simple URL Parameter and a JS Library Opened a Door to XSS in IE/EdgeContinue reading on OSINT Team » (https://osintteam.blog/500-bounty-dom-based-xss-in-hackerones-careers-page-019f78c5e213?source=rss------bug_bounty-5)
They Missed This One Tiny Parameter — I Made $500 Instantly
✨Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
✨Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
Medium
🧠 They Missed This One Tiny Parameter — I Made $500 Instantly
✨Free Article Link
$2,500 Bounty: DOM-Based XSS via postMessage on Upserve’s Login Page
How a Loose Origin Check Opened the Door to Credential Theft on a Production Login PageContinue reading on InfoSec Write-ups »
Read more...
How a Loose Origin Check Opened the Door to Credential Theft on a Production Login PageContinue reading on InfoSec Write-ups »
Read more...
Medium
$2,500 Bounty: DOM-Based XSS via postMessage on Upserve’s Login Page
How a Loose Origin Check Opened the Door to Credential Theft on a Production Login Page
Demystifying Cookies: The Complete Guide for Bug Bounty Hunters
Everything you need to know about cookies to expand your attack surface and find real bugs.Continue reading on InfoSec Write-ups »
Read more...
Everything you need to know about cookies to expand your attack surface and find real bugs.Continue reading on InfoSec Write-ups »
Read more...