Understanding Server Side Request Forgery (SSRF) with a Simple Real-Life Example
Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…Continue reading on Medium »
Read more...
Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…Continue reading on Medium »
Read more...
Medium
Understanding Server Side Request Forgery (SSRF) with a Simple Real-Life Example
Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…
Hunting for Web Cache Deception Vulnerabilities with a Custom Bash Script
https://medium.com/@m4r5h4ll2969/hunting-for-web-cache-deception-vulnerabilities-with-a-custom-bash-script-a52d2f8fd722?source=rss------bug_bounty-5
Author: @m0x_mw4_dContinue reading on Medium » (https://medium.com/@m4r5h4ll2969/hunting-for-web-cache-deception-vulnerabilities-with-a-custom-bash-script-a52d2f8fd722?source=rss------bug_bounty-5)
https://medium.com/@m4r5h4ll2969/hunting-for-web-cache-deception-vulnerabilities-with-a-custom-bash-script-a52d2f8fd722?source=rss------bug_bounty-5
Author: @m0x_mw4_dContinue reading on Medium » (https://medium.com/@m4r5h4ll2969/hunting-for-web-cache-deception-vulnerabilities-with-a-custom-bash-script-a52d2f8fd722?source=rss------bug_bounty-5)
Understanding Server Side Request Forgery (SSRF) with a Simple Real-Life Example
https://medium.com/@natarajanck2/understanding-server-side-request-forgery-ssrf-with-a-simple-real-life-example-a14650bd5317?source=rss------bug_bounty-5
Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…Continue reading on Medium » (https://medium.com/@natarajanck2/understanding-server-side-request-forgery-ssrf-with-a-simple-real-life-example-a14650bd5317?source=rss------bug_bounty-5)
https://medium.com/@natarajanck2/understanding-server-side-request-forgery-ssrf-with-a-simple-real-life-example-a14650bd5317?source=rss------bug_bounty-5
Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…Continue reading on Medium » (https://medium.com/@natarajanck2/understanding-server-side-request-forgery-ssrf-with-a-simple-real-life-example-a14650bd5317?source=rss------bug_bounty-5)
Zerolend: Technical Analysis of the Risks and Failures Undermining Its DeFi Protocol
Zerolend aims to be a decentralized lending protocol, offering speed and flexibility for borrowing or lending crypto assets. However, a…Continue reading on Medium »
Read more...
Zerolend aims to be a decentralized lending protocol, offering speed and flexibility for borrowing or lending crypto assets. However, a…Continue reading on Medium »
Read more...
Medium
🪐 Jupiter and the Challenge of Incentivized Governance with ASR and Airdrops.
While Sanctum kicks off its first reward allocation, Jupiter is about to close an important vote on its own Active Stake Reallocation (ASR)…
How I Bypassed My University’s OTP System and Got Admin-Level Access (Ethical Hack)
“Curiosity is the most powerful exploit.”Continue reading on Medium »
Read more...
“Curiosity is the most powerful exploit.”Continue reading on Medium »
Read more...
Medium
How I Bypassed My University’s OTP System and Got Admin-Level Access (Ethical Hack)
“Curiosity is the most powerful exploit.”
$5,000 | Authorization Bypass via Parameter Parsing Mismatch (Django — Flask)
SummaryContinue reading on Medium »
Read more...
SummaryContinue reading on Medium »
Read more...
Medium
$5,000 | Authorization Bypass via Parameter Parsing Mismatch (Django — Flask)
Summary
Bug Bounty
“Step-by-step notes from my bug bounty journey — tools, techniques, and tips.”Continue reading on Medium »
Read more...
“Step-by-step notes from my bug bounty journey — tools, techniques, and tips.”Continue reading on Medium »
Read more...
Medium
Bug Bounty
“Step-by-step notes from my bug bounty journey — tools, techniques, and tips.”
Should I Move On? Looking for Insights from Cybersecurity Professionals
https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/
<!-- SC_OFF -->Hi everyone, I’m currently working in the cybersecurity domain with around 2 years of experience. However, I feel that my current skill level is not quite up to par with industry standards. The company I work for has very few projects, and unfortunately, it’s been difficult for me to grow or upskill due to the lack of real-world exposure. I’ve been considering starting a job search to move to a company where I can work on actual projects and be around more experienced professionals to accelerate my learning. For those of you working as pentesters or in similar roles — do you think it's a good idea to shift companies at this stage? Would moving to a more dynamic environment help me grow faster? Any advice or suggestions would be really appreciated! Thanks in advance! <!-- SC_ON --> submitted by /u/NenuDhevudini (https://www.reddit.com/user/NenuDhevudini)
[link] (https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/) [comments] (https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/)
https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/
<!-- SC_OFF -->Hi everyone, I’m currently working in the cybersecurity domain with around 2 years of experience. However, I feel that my current skill level is not quite up to par with industry standards. The company I work for has very few projects, and unfortunately, it’s been difficult for me to grow or upskill due to the lack of real-world exposure. I’ve been considering starting a job search to move to a company where I can work on actual projects and be around more experienced professionals to accelerate my learning. For those of you working as pentesters or in similar roles — do you think it's a good idea to shift companies at this stage? Would moving to a more dynamic environment help me grow faster? Any advice or suggestions would be really appreciated! Thanks in advance! <!-- SC_ON --> submitted by /u/NenuDhevudini (https://www.reddit.com/user/NenuDhevudini)
[link] (https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/) [comments] (https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/)
$5,000 | Authorization Bypass via Parameter Parsing Mismatch (Django — Flask)
https://medium.com/@pranshux0x/5-000-authorization-bypass-via-parameter-parsing-mismatch-django-flask-6f0f748db6be?source=rss------bug_bounty-5
SummaryContinue reading on Medium » (https://medium.com/@pranshux0x/5-000-authorization-bypass-via-parameter-parsing-mismatch-django-flask-6f0f748db6be?source=rss------bug_bounty-5)
https://medium.com/@pranshux0x/5-000-authorization-bypass-via-parameter-parsing-mismatch-django-flask-6f0f748db6be?source=rss------bug_bounty-5
SummaryContinue reading on Medium » (https://medium.com/@pranshux0x/5-000-authorization-bypass-via-parameter-parsing-mismatch-django-flask-6f0f748db6be?source=rss------bug_bounty-5)
“Step-by-step notes from my bug bounty journey — tools, techniques, and tips.”Continue reading on Medium » (https://medium.com/@navtesh_sharma/bug-bounty-30cba1c7a2b0?source=rss------bug_bounty-5)
Reflected Chaos: How One XSS Vector Spawned Three CVEs
A routine bug bounty checks. A familiar endpoint. But one odd behavior caught my eye — a parameter that echoed back a payload with just a…Continue reading on Medium »
Read more...
A routine bug bounty checks. A familiar endpoint. But one odd behavior caught my eye — a parameter that echoed back a payload with just a…Continue reading on Medium »
Read more...
Medium
Reflected Chaos: How One XSS Vector Spawned Three CVEs
A routine bug bounty checks. A familiar endpoint. But one odd behavior caught my eye — a parameter that echoed back a payload with just a…
Reflected Chaos: How One XSS Vector Spawned Three CVEs
https://medium.com/@bonghaxor_34691/reflected-chaos-how-one-xss-vector-spawned-three-cves-f20e2df3275f?source=rss------bug_bounty-5
https://medium.com/@bonghaxor_34691/reflected-chaos-how-one-xss-vector-spawned-three-cves-f20e2df3275f?source=rss------bug_bounty-5
A routine bug bounty checks. A familiar endpoint. But one odd behavior caught my eye — a parameter that echoed back a payload with just a…Continue reading on Medium » (https://medium.com/@bonghaxor_34691/reflected-chaos-how-one-xss-vector-spawned-three-cves-f20e2df3275f?source=rss------bug_bounty-5)
This is how I got 16 CVEs in 2 months
2024 was a year for me. I used to play a lot of CTF with my team called “Hantu Siber” (https://ctftime.org/team/203878/). We also won some…Continue reading on Medium »
Read more...
2024 was a year for me. I used to play a lot of CTF with my team called “Hantu Siber” (https://ctftime.org/team/203878/). We also won some…Continue reading on Medium »
Read more...
ctftime.org
CTFtime.org / Hantu Siber
CTFtime team profile,Hantu Siber
New alternative to Bloodhound: Neo4LDAP, LDAP + graph visualization over Neo4j
https://www.reddit.com/r/redteamsec/comments/1ks1e00/new_alternative_to_bloodhound_neo4ldap_ldap_graph/
<!-- SC_OFF -->I recently came across this tool and tried it out to analyse some large AD environments. It worked surprisingly well, as it allows you to dynamically hide nodes and subgraphs to reduce noise. It also allows LDAP queries to retrieve Neo4j data which is more intuitive than cypher. <!-- SC_ON --> submitted by /u/Aggressive_Show_5256 (https://www.reddit.com/user/Aggressive_Show_5256)
[link] (https://github.com/Krypteria/Neo4LDAP) [comments] (https://www.reddit.com/r/redteamsec/comments/1ks1e00/new_alternative_to_bloodhound_neo4ldap_ldap_graph/)
https://www.reddit.com/r/redteamsec/comments/1ks1e00/new_alternative_to_bloodhound_neo4ldap_ldap_graph/
<!-- SC_OFF -->I recently came across this tool and tried it out to analyse some large AD environments. It worked surprisingly well, as it allows you to dynamically hide nodes and subgraphs to reduce noise. It also allows LDAP queries to retrieve Neo4j data which is more intuitive than cypher. <!-- SC_ON --> submitted by /u/Aggressive_Show_5256 (https://www.reddit.com/user/Aggressive_Show_5256)
[link] (https://github.com/Krypteria/Neo4LDAP) [comments] (https://www.reddit.com/r/redteamsec/comments/1ks1e00/new_alternative_to_bloodhound_neo4ldap_ldap_graph/)
This is how I got 16 CVEs in 2 months
https://medium.com/@rayhanhanaputra/this-is-how-i-got-16-cves-in-2-months-491be07793b0?source=rss------bug_bounty-5
https://medium.com/@rayhanhanaputra/this-is-how-i-got-16-cves-in-2-months-491be07793b0?source=rss------bug_bounty-5
2024 was a year for me. I used to play a lot of CTF with my team called “Hantu Siber” (https://ctftime.org/team/203878/). We also won some…Continue reading on Medium » (https://medium.com/@rayhanhanaputra/this-is-how-i-got-16-cves-in-2-months-491be07793b0?source=rss------bug_bounty-5)