Confessions of a Burp Suite Beginner
I didn’t think my first meltdown in cybersecurity would come from a tool named burp, but here we are.Continue reading on Medium »
Read more...
I didn’t think my first meltdown in cybersecurity would come from a tool named burp, but here we are.Continue reading on Medium »
Read more...
Medium
Confessions of a Burp Suite Beginner
I didn’t think my first meltdown in cybersecurity would come from a tool named burp, but here we are. You know that feeling when you open a…
New to Bug Bounties? These Are the PoC to Earn Your First $$$!
https://medium.com/@wanqais007/new-to-bug-bounties-these-are-the-poc-to-earn-your-first-cf48af82b2f2?source=rss------bug_bounty-5
https://medium.com/@wanqais007/new-to-bug-bounties-these-are-the-poc-to-earn-your-first-cf48af82b2f2?source=rss------bug_bounty-5
Hey folks! 😎Continue reading on Medium » (https://medium.com/@wanqais007/new-to-bug-bounties-these-are-the-poc-to-earn-your-first-cf48af82b2f2?source=rss------bug_bounty-5)
Confessions of a Burp Suite Beginner
https://medium.com/@cosmicbyt3/confessions-of-a-burp-suite-beginner-03aae8944284?source=rss------bug_bounty-5
I didn’t think my first meltdown in cybersecurity would come from a tool named burp, but here we are.Continue reading on Medium » (https://medium.com/@cosmicbyt3/confessions-of-a-burp-suite-beginner-03aae8944284?source=rss------bug_bounty-5)
https://medium.com/@cosmicbyt3/confessions-of-a-burp-suite-beginner-03aae8944284?source=rss------bug_bounty-5
I didn’t think my first meltdown in cybersecurity would come from a tool named burp, but here we are.Continue reading on Medium » (https://medium.com/@cosmicbyt3/confessions-of-a-burp-suite-beginner-03aae8944284?source=rss------bug_bounty-5)
POC — CVE-2025–2539 File Away <= 3.9.9.0.1
https://medium.com/@verylazytech/poc-cve-2025-2539-file-away-3-9-9-0-1-ee5c84e42a92?source=rss------bug_bounty-5
https://medium.com/@verylazytech/poc-cve-2025-2539-file-away-3-9-9-0-1-ee5c84e42a92?source=rss------bug_bounty-5
✨ Free linkContinue reading on Medium » (https://medium.com/@verylazytech/poc-cve-2025-2539-file-away-3-9-9-0-1-ee5c84e42a92?source=rss------bug_bounty-5)
Which Programming or Scripting Skill Was a Game-Changer in Your Pentesting Journey?
https://www.reddit.com/r/Pentesting/comments/1kxcaf9/which_programming_or_scripting_skill_was_a/
https://www.reddit.com/r/Pentesting/comments/1kxcaf9/which_programming_or_scripting_skill_was_a/
<!-- SC_OFF -->I hope you’re doing well. I’m writing an article on the essential programming and scripting foundations every pentester should master in 2025, and I’d love to learn from your real-world experiences: • Which languages or libraries have you found most valuable for automation or exploit development? • What beginner-to-intermediate projects gave you the biggest confidence boost when working with code? • Are there any resources—courses, tutorials, GitHub repos—that truly transformed your workflow? • What common pitfalls would you warn newcomers to avoid when they start coding for security tasks? I appreciate any insights, examples, or recommendations you can share. Thank you so much for your help! <!-- SC_ON --> submitted by /u/Anezaneo (https://www.reddit.com/user/Anezaneo)
[link] (https://infosecwriteups.com/part-3-how-to-become-a-pentester-in-2025-programming-scripting-foundations-for-pentester-c57334e7a8fe) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxcaf9/which_programming_or_scripting_skill_was_a/)
[link] (https://infosecwriteups.com/part-3-how-to-become-a-pentester-in-2025-programming-scripting-foundations-for-pentester-c57334e7a8fe) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxcaf9/which_programming_or_scripting_skill_was_a/)
<!-- SC_OFF -->hey everyone. I'm running into a ModuleNotFoundError when trying to use a tool that relies on requests and urllib3. Here's the error I'm getting: I've already tried: Installing an older version of urllib3 (even v1.26.x) Reinstalling requests, urllib3, and six Setting up a fresh virtual environment The issue seems to stem from urllib3 relying on six, but that module path doesn’t exist anymore in recent versions. Still getting the same error. https://preview.redd.it/fxi4k7t73i3f1.png?width=1215&format=png&auto=webp&s=85e382cb55c588fb373b7da4b54f2c94b368de20 <!-- SC_ON --> submitted by /u/ZucchiniAgitated21 (https://www.reddit.com/user/ZucchiniAgitated21)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxdq5t/osintgram_tool/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxdq5t/osintgram_tool/)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxdq5t/osintgram_tool/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxdq5t/osintgram_tool/)
Regex for searching creds
https://www.reddit.com/r/Pentesting/comments/1kxei99/regex_for_searching_creds/
<!-- SC_OFF -->what regular expressions do you use when searching for passwords on domain shares? <!-- SC_ON --> submitted by /u/grime_vietnam (https://www.reddit.com/user/grime_vietnam)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxei99/regex_for_searching_creds/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxei99/regex_for_searching_creds/)
https://www.reddit.com/r/Pentesting/comments/1kxei99/regex_for_searching_creds/
<!-- SC_OFF -->what regular expressions do you use when searching for passwords on domain shares? <!-- SC_ON --> submitted by /u/grime_vietnam (https://www.reddit.com/user/grime_vietnam)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxei99/regex_for_searching_creds/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxei99/regex_for_searching_creds/)
I made a thing!
https://www.reddit.com/r/Pentesting/comments/1kxgaes/i_made_a_thing/
<!-- SC_OFF -->Good morning all you awesome pentesters! I just wanted to show you all a tool i developed for physical pentesting. It's a small usb device that lets you inject keyboard key strokes from your phone or from afar via a C2 web server. https://www.kickstarter.com/projects/pidgn/pidgn?ref=user_menu <!-- SC_ON --> submitted by /u/Clean-Drop9629 (https://www.reddit.com/user/Clean-Drop9629)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxgaes/i_made_a_thing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxgaes/i_made_a_thing/)
https://www.reddit.com/r/Pentesting/comments/1kxgaes/i_made_a_thing/
<!-- SC_OFF -->Good morning all you awesome pentesters! I just wanted to show you all a tool i developed for physical pentesting. It's a small usb device that lets you inject keyboard key strokes from your phone or from afar via a C2 web server. https://www.kickstarter.com/projects/pidgn/pidgn?ref=user_menu <!-- SC_ON --> submitted by /u/Clean-Drop9629 (https://www.reddit.com/user/Clean-Drop9629)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxgaes/i_made_a_thing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxgaes/i_made_a_thing/)
How a Simple Payment Exploit Could Take Down a Prop Firm — And No One Cared
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them). This…Continue reading on Medium »
Read more...
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them). This…Continue reading on Medium »
Read more...
Medium
How a Simple Payment Exploit Could Take Down a Prop Firm — And No One Cared
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them). This…
How I discovered Reflected XSS in GoldAcademy.
First of all, as usual, we need to make some infogatheringContinue reading on Medium »
Read more...
First of all, as usual, we need to make some infogatheringContinue reading on Medium »
Read more...
Medium
How I discovered Reflected XSS in GoldAcademy.
First of all, as usual, we need to make some infogathering
Spidering in Security
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium »
Read more...
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium »
Read more...
Medium
Spidering in Security
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…
How Web Cache Poisoning via Unkeyed Query Strings Can Lead to Reflected XSS
Write-up Web Cache Poisoning via an Unkeyed Query String.Continue reading on OSINT Team »
Read more...
Write-up Web Cache Poisoning via an Unkeyed Query String.Continue reading on OSINT Team »
Read more...
Medium
How Web Cache Poisoning via Unkeyed Query Strings Can Lead to Reflected XSS
[Write-up] Web Cache Poisoning via an Unkeyed Query String.
Uncovering Hidden Signup Pages for Bug Bounty Hunting
While we hunting a bug in a web pentesting,we can able to see only login button.Continue reading on Medium »
Read more...
While we hunting a bug in a web pentesting,we can able to see only login button.Continue reading on Medium »
Read more...
Medium
Uncovering Hidden Signup Pages for Bug Bounty Hunting
While we hunting a bug in a web pentesting,we can able to see only login button.