How a Simple Payment Exploit Could Take Down a Prop Firm — And No One Cared
https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5
https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them).
This…Continue reading on Medium » (https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5)
This…Continue reading on Medium » (https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5)
How I discovered Reflected XSS in GoldAcademy.
https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5
First of all, as usual, we need to make some infogatheringContinue reading on Medium » (https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5)
https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5
First of all, as usual, we need to make some infogatheringContinue reading on Medium » (https://medium.com/@secourses8/how-i-discovered-reflected-xss-in-goldacademy-257b69a14be8?source=rss------bug_bounty-5)
Spidering in Security
https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium » (https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5)
https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5
Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium » (https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5)
Is it possible to be a red teamer with superior degree?
https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/
<!-- SC_OFF -->Im finishing a higher degree of web applications development, but ive noticed that I like too much the cibersecurity area. So I did some research, and red teamer seems to fit the best with what im interested in. But the thing is, do i have real spectations to find a job there without a university degree? I could do my best to get the needed certifications (if my budget allows it), but would it be enough? And if it actually is, could i make it to the top? Im just genuinely asking from ignorance, so i will appreciate constructive answers. <!-- SC_ON --> submitted by /u/Informal-Command-714 (https://www.reddit.com/user/Informal-Command-714)
[link] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/)
https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/
<!-- SC_OFF -->Im finishing a higher degree of web applications development, but ive noticed that I like too much the cibersecurity area. So I did some research, and red teamer seems to fit the best with what im interested in. But the thing is, do i have real spectations to find a job there without a university degree? I could do my best to get the needed certifications (if my budget allows it), but would it be enough? And if it actually is, could i make it to the top? Im just genuinely asking from ignorance, so i will appreciate constructive answers. <!-- SC_ON --> submitted by /u/Informal-Command-714 (https://www.reddit.com/user/Informal-Command-714)
[link] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/)
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium »
Read more...
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium »
Read more...
Medium
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec
https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5
https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium » (https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5)
Misinterpreted: What Penetration Test Reports Actually Mean
https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/
https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/
<!-- SC_OFF -->Hey everyone, our blog post this month post discusses pentest reports and how the various audiences that consume them sometimes misinterpret what they mean. We cover why findings in a report are not a sign of failure, why "clean" reports aren't always good news, and why it may not be necessary to fix every single identified vulnerability. The post concludes with a few takeaways about how the information in a pentest report helps inform the reader about the report subject's security posture. <!-- SC_ON --> submitted by /u/IncludeSec (https://www.reddit.com/user/IncludeSec)
[link] (https://blog.includesecurity.com/2025/05/misinterpreted-what-penetration-test-reports-actually-mean/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/)
[link] (https://blog.includesecurity.com/2025/05/misinterpreted-what-penetration-test-reports-actually-mean/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/)
Android Pentesting Setup Up Burpsuite Intercept
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium »
Read more...
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium »
Read more...
Medium
Android Pentesting Setup Up Burpsuite Intercept
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device. By following…
Android Pentesting Setup Up Burpsuite Intercept
https://medium.com/@muhammadhuzaifa02134182093/android-pentesting-setup-up-burpsuite-intercept-53b37ea9762c?source=rss------bug_bounty-5
https://medium.com/@muhammadhuzaifa02134182093/android-pentesting-setup-up-burpsuite-intercept-53b37ea9762c?source=rss------bug_bounty-5
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium » (https://medium.com/@muhammadhuzaifa02134182093/android-pentesting-setup-up-burpsuite-intercept-53b37ea9762c?source=rss------bug_bounty-5)
Certifications Advice
https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/
<!-- SC_OFF -->Hi! Maybe can I have an advice? As an Amazon Driver I have a benefit for some programs, and I just checkd they have this programs with ed2go, and the have Secuirtiy+, Network+, A+, and another one TECH+, I thin this last one is a new from Comptia.Also I have interest in the AWS Cloud Practitioner, all of them include the boot camp style study and the vouchers.I have an amount of 5250 to spend, but I am not sure how to use it. Is A+ worth it to got?? I was going to take it because it can help ,landing that first job in IT Support. Network+ I think is a must, and of course the gold standard Security+TECH+ I think may not be necessary. AWS Cloud Practitioner may be a good one to have to. So, the comptia ones can be taken as bundles in ed2go, but my real question is about taking the A+ or your opinion is that it may not be necessary, and just go to Sec and Net, with AWS. I know I can have all this free in YouTube and all that, but I really like to study in a structured way, and also they include the vouchers so may be a good option. About me? I am pivoting from Public Administration, i am Ecuadorian and i have an Associates in Cybersecurity, and i am trying to land my first TECH job Thanks for your help! <!-- SC_ON --> submitted by /u/Fickle-Throat4940 (https://www.reddit.com/user/Fickle-Throat4940)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/)
https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/
<!-- SC_OFF -->Hi! Maybe can I have an advice? As an Amazon Driver I have a benefit for some programs, and I just checkd they have this programs with ed2go, and the have Secuirtiy+, Network+, A+, and another one TECH+, I thin this last one is a new from Comptia.Also I have interest in the AWS Cloud Practitioner, all of them include the boot camp style study and the vouchers.I have an amount of 5250 to spend, but I am not sure how to use it. Is A+ worth it to got?? I was going to take it because it can help ,landing that first job in IT Support. Network+ I think is a must, and of course the gold standard Security+TECH+ I think may not be necessary. AWS Cloud Practitioner may be a good one to have to. So, the comptia ones can be taken as bundles in ed2go, but my real question is about taking the A+ or your opinion is that it may not be necessary, and just go to Sec and Net, with AWS. I know I can have all this free in YouTube and all that, but I really like to study in a structured way, and also they include the vouchers so may be a good option. About me? I am pivoting from Public Administration, i am Ecuadorian and i have an Associates in Cybersecurity, and i am trying to land my first TECH job Thanks for your help! <!-- SC_ON --> submitted by /u/Fickle-Throat4940 (https://www.reddit.com/user/Fickle-Throat4940)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/)
️ Sensitive Data Exposure via WP-JSON in WordPress
https://medium.com/@noorsaper64/%EF%B8%8F-sensitive-data-exposure-via-wp-json-in-wordpress-d1dee7318d3b?source=rss------bug_bounty-5
https://medium.com/@noorsaper64/%EF%B8%8F-sensitive-data-exposure-via-wp-json-in-wordpress-d1dee7318d3b?source=rss------bug_bounty-5