How I discovered Reflected XSS in GoldAcademy.
First of all, as usual, we need to make some infogatheringContinue reading on Medium »
Read more...
First of all, as usual, we need to make some infogatheringContinue reading on Medium »
Read more...
Medium
How I discovered Reflected XSS in GoldAcademy.
First of all, as usual, we need to make some infogathering
Spidering in Security
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium »
Read more...
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium »
Read more...
Medium
Spidering in Security
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…
How Web Cache Poisoning via Unkeyed Query Strings Can Lead to Reflected XSS
Write-up Web Cache Poisoning via an Unkeyed Query String.Continue reading on OSINT Team »
Read more...
Write-up Web Cache Poisoning via an Unkeyed Query String.Continue reading on OSINT Team »
Read more...
Medium
How Web Cache Poisoning via Unkeyed Query Strings Can Lead to Reflected XSS
[Write-up] Web Cache Poisoning via an Unkeyed Query String.
Uncovering Hidden Signup Pages for Bug Bounty Hunting
While we hunting a bug in a web pentesting,we can able to see only login button.Continue reading on Medium »
Read more...
While we hunting a bug in a web pentesting,we can able to see only login button.Continue reading on Medium »
Read more...
Medium
Uncovering Hidden Signup Pages for Bug Bounty Hunting
While we hunting a bug in a web pentesting,we can able to see only login button.
Game of Active Directory: Penetration Testing an Active Directory Environment (Video)
https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/
<!-- SC_OFF -->https://www.youtube.com/watch?v=J4l-BMG9gTQ Our SVP of Cybersecurity, Jesse Roberts, put together a short breakdown of Active Directory pentesting. Sharing here in case it’s helpful! <!-- SC_ON --> submitted by /u/CompassITCompliance (https://www.reddit.com/user/CompassITCompliance)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/)
https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/
<!-- SC_OFF -->https://www.youtube.com/watch?v=J4l-BMG9gTQ Our SVP of Cybersecurity, Jesse Roberts, put together a short breakdown of Active Directory pentesting. Sharing here in case it’s helpful! <!-- SC_ON --> submitted by /u/CompassITCompliance (https://www.reddit.com/user/CompassITCompliance)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxib0s/game_of_active_directory_penetration_testing_an/)
Ethical Hacking Assignment - getting root from an IP/Site
https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/
<!-- SC_OFF -->Hi, I am a 4th semester of computer sciences right now and I'm working on my final project, which is getting root access of a site/ip using kali linux, we've attempted to use gobuster and metasploit, however, both methods are considered brute forcing and it simply isn't effective based on our deadline which is in a few days. The system we're trying to take root over uses linux so eternalbblue wouldn't work as well. Any tips on what method we should use. The goal here is to use kali to get the root access of server3.pentest.id (http://server3.pentest.id/) (this is a fake site that my lecturer gave us}. Also we found the vulnerable ports that are open already, there are 2 to be exact. So i guess we need to utilize those open ports. <!-- SC_ON --> submitted by /u/Seraphims-Monody (https://www.reddit.com/user/Seraphims-Monody)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/)
https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/
<!-- SC_OFF -->Hi, I am a 4th semester of computer sciences right now and I'm working on my final project, which is getting root access of a site/ip using kali linux, we've attempted to use gobuster and metasploit, however, both methods are considered brute forcing and it simply isn't effective based on our deadline which is in a few days. The system we're trying to take root over uses linux so eternalbblue wouldn't work as well. Any tips on what method we should use. The goal here is to use kali to get the root access of server3.pentest.id (http://server3.pentest.id/) (this is a fake site that my lecturer gave us}. Also we found the vulnerable ports that are open already, there are 2 to be exact. So i guess we need to utilize those open ports. <!-- SC_ON --> submitted by /u/Seraphims-Monody (https://www.reddit.com/user/Seraphims-Monody)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/)
Cracking JWTs: A Bug Bounty Hunting Guide [Part 1]
JWT Authentication Bypass via Unverified and Flawed Signature VerificationContinue reading on InfoSec Write-ups »
Read more...
JWT Authentication Bypass via Unverified and Flawed Signature VerificationContinue reading on InfoSec Write-ups »
Read more...
Medium
Cracking JWTs: A Bug Bounty Hunting Guide [Part 1]
JWT Authentication Bypass via Unverified and Flawed Signature Verification
How I Bypassed a Famous Regional Newspaper’s Subscription Plan By Http Response Manipulation
My article is open to everyone; non-member readers can click this link to read the full text.Continue reading on OSINT Team »
Read more...
My article is open to everyone; non-member readers can click this link to read the full text.Continue reading on OSINT Team »
Read more...
Medium
How I Bypassed a Famous Regional Newspaper’s Subscription Plan By Http Response Manipulation
My article is open to everyone; non-member readers can click this link to read the full text.
Windows Defender E5 auto remediation problem
https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/
<!-- SC_OFF -->During a pentest, the windows test account was found by Defender and later disabled. It seems it also added the account to 2 windows user policy settings - "Deny access to this computer from the network" and "Deny logon through Remote Desktop Services" on each item that was accessed. I don't see any group policy that has this setting added and the local policy has it but is greyed out and I am unable to remove it. Any ideas? Just need to remove it so we can continue testing or if real-world, get the user back to normal access again. <!-- SC_ON --> submitted by /u/Successful_Way_3663 (https://www.reddit.com/user/Successful_Way_3663)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/)
https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/
<!-- SC_OFF -->During a pentest, the windows test account was found by Defender and later disabled. It seems it also added the account to 2 windows user policy settings - "Deny access to this computer from the network" and "Deny logon through Remote Desktop Services" on each item that was accessed. I don't see any group policy that has this setting added and the local policy has it but is greyed out and I am unable to remove it. Any ideas? Just need to remove it so we can continue testing or if real-world, get the user back to normal access again. <!-- SC_ON --> submitted by /u/Successful_Way_3663 (https://www.reddit.com/user/Successful_Way_3663)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/)
Mastering PHP Wrappers: Concepts, Use Cases, and Security Risks
By ZoningxtrContinue reading on Medium »
Read more...
By ZoningxtrContinue reading on Medium »
Read more...
Medium
🧵 Mastering PHP Wrappers: Concepts, Use Cases, and Security Risks
By Zoningxtr
How a Simple Payment Exploit Could Take Down a Prop Firm — And No One Cared
https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5
https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them).
This…Continue reading on Medium » (https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5)
This…Continue reading on Medium » (https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5)
How I discovered Reflected XSS in GoldAcademy.
https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5
First of all, as usual, we need to make some infogatheringContinue reading on Medium » (https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5)
https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5
First of all, as usual, we need to make some infogatheringContinue reading on Medium » (https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5)
Spidering in Security
https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium » (https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5)
https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium » (https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5)
Is it possible to be a red teamer with superior degree?
https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/
<!-- SC_OFF -->Im finishing a higher degree of web applications development, but ive noticed that I like too much the cibersecurity area. So I did some research, and red teamer seems to fit the best with what im interested in. But the thing is, do i have real spectations to find a job there without a university degree? I could do my best to get the needed certifications (if my budget allows it), but would it be enough? And if it actually is, could i make it to the top? Im just genuinely asking from ignorance, so i will appreciate constructive answers. <!-- SC_ON --> submitted by /u/Informal-Command-714 (https://www.reddit.com/user/Informal-Command-714)
[link] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/)
https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/
<!-- SC_OFF -->Im finishing a higher degree of web applications development, but ive noticed that I like too much the cibersecurity area. So I did some research, and red teamer seems to fit the best with what im interested in. But the thing is, do i have real spectations to find a job there without a university degree? I could do my best to get the needed certifications (if my budget allows it), but would it be enough? And if it actually is, could i make it to the top? Im just genuinely asking from ignorance, so i will appreciate constructive answers. <!-- SC_ON --> submitted by /u/Informal-Command-714 (https://www.reddit.com/user/Informal-Command-714)
[link] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/)
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium »
Read more...
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium »
Read more...
Medium
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec
https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5
https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium » (https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5)
Misinterpreted: What Penetration Test Reports Actually Mean
https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/
https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/