👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium » (https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5)
Misinterpreted: What Penetration Test Reports Actually Mean
https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/
https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/
<!-- SC_OFF -->Hey everyone, our blog post this month post discusses pentest reports and how the various audiences that consume them sometimes misinterpret what they mean. We cover why findings in a report are not a sign of failure, why "clean" reports aren't always good news, and why it may not be necessary to fix every single identified vulnerability. The post concludes with a few takeaways about how the information in a pentest report helps inform the reader about the report subject's security posture. <!-- SC_ON --> submitted by /u/IncludeSec (https://www.reddit.com/user/IncludeSec)
[link] (https://blog.includesecurity.com/2025/05/misinterpreted-what-penetration-test-reports-actually-mean/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/)
[link] (https://blog.includesecurity.com/2025/05/misinterpreted-what-penetration-test-reports-actually-mean/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/)
Android Pentesting Setup Up Burpsuite Intercept
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium »
Read more...
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium »
Read more...
Medium
Android Pentesting Setup Up Burpsuite Intercept
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device. By following…
Android Pentesting Setup Up Burpsuite Intercept
https://medium.com/@muhammadhuzaifa02134182093/android-pentesting-setup-up-burpsuite-intercept-53b37ea9762c?source=rss------bug_bounty-5
https://medium.com/@muhammadhuzaifa02134182093/android-pentesting-setup-up-burpsuite-intercept-53b37ea9762c?source=rss------bug_bounty-5
This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium » (https://medium.com/@muhammadhuzaifa02134182093/android-pentesting-setup-up-burpsuite-intercept-53b37ea9762c?source=rss------bug_bounty-5)
Certifications Advice
https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/
<!-- SC_OFF -->Hi! Maybe can I have an advice? As an Amazon Driver I have a benefit for some programs, and I just checkd they have this programs with ed2go, and the have Secuirtiy+, Network+, A+, and another one TECH+, I thin this last one is a new from Comptia.Also I have interest in the AWS Cloud Practitioner, all of them include the boot camp style study and the vouchers.I have an amount of 5250 to spend, but I am not sure how to use it. Is A+ worth it to got?? I was going to take it because it can help ,landing that first job in IT Support. Network+ I think is a must, and of course the gold standard Security+TECH+ I think may not be necessary. AWS Cloud Practitioner may be a good one to have to. So, the comptia ones can be taken as bundles in ed2go, but my real question is about taking the A+ or your opinion is that it may not be necessary, and just go to Sec and Net, with AWS. I know I can have all this free in YouTube and all that, but I really like to study in a structured way, and also they include the vouchers so may be a good option. About me? I am pivoting from Public Administration, i am Ecuadorian and i have an Associates in Cybersecurity, and i am trying to land my first TECH job Thanks for your help! <!-- SC_ON --> submitted by /u/Fickle-Throat4940 (https://www.reddit.com/user/Fickle-Throat4940)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/)
https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/
<!-- SC_OFF -->Hi! Maybe can I have an advice? As an Amazon Driver I have a benefit for some programs, and I just checkd they have this programs with ed2go, and the have Secuirtiy+, Network+, A+, and another one TECH+, I thin this last one is a new from Comptia.Also I have interest in the AWS Cloud Practitioner, all of them include the boot camp style study and the vouchers.I have an amount of 5250 to spend, but I am not sure how to use it. Is A+ worth it to got?? I was going to take it because it can help ,landing that first job in IT Support. Network+ I think is a must, and of course the gold standard Security+TECH+ I think may not be necessary. AWS Cloud Practitioner may be a good one to have to. So, the comptia ones can be taken as bundles in ed2go, but my real question is about taking the A+ or your opinion is that it may not be necessary, and just go to Sec and Net, with AWS. I know I can have all this free in YouTube and all that, but I really like to study in a structured way, and also they include the vouchers so may be a good option. About me? I am pivoting from Public Administration, i am Ecuadorian and i have an Associates in Cybersecurity, and i am trying to land my first TECH job Thanks for your help! <!-- SC_ON --> submitted by /u/Fickle-Throat4940 (https://www.reddit.com/user/Fickle-Throat4940)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxvfao/certifications_advice/)
️ Sensitive Data Exposure via WP-JSON in WordPress
https://medium.com/@noorsaper64/%EF%B8%8F-sensitive-data-exposure-via-wp-json-in-wordpress-d1dee7318d3b?source=rss------bug_bounty-5
https://medium.com/@noorsaper64/%EF%B8%8F-sensitive-data-exposure-via-wp-json-in-wordpress-d1dee7318d3b?source=rss------bug_bounty-5
$1,000 Bounty: Created Support Tickets on Behalf of Any HackerOne User via Email
Abusing Email-Based Ticketing to Impersonate Users and Bypass Identity Controls — Earned $1,000Continue reading on OSINT Team »
Read more...
Abusing Email-Based Ticketing to Impersonate Users and Bypass Identity Controls — Earned $1,000Continue reading on OSINT Team »
Read more...
Medium
$1,000 Bounty: Created Support Tickets on Behalf of Any HackerOne User via Email
Abusing Email-Based Ticketing to Impersonate Users and Bypass Identity Controls — Earned $1,000
$1,000 Bounty: Created Support Tickets on Behalf of Any HackerOne User via Email
https://osintteam.blog/1-000-bounty-created-support-tickets-on-behalf-of-any-hackerone-user-via-email-d8b6f90f0757?source=rss------bug_bounty-5
https://osintteam.blog/1-000-bounty-created-support-tickets-on-behalf-of-any-hackerone-user-via-email-d8b6f90f0757?source=rss------bug_bounty-5
Abusing Email-Based Ticketing to Impersonate Users and Bypass Identity Controls — Earned $1,000Continue reading on OSINT Team » (https://osintteam.blog/1-000-bounty-created-support-tickets-on-behalf-of-any-hackerone-user-via-email-d8b6f90f0757?source=rss------bug_bounty-5)
EG-CERT CTF25 Flog: Nowadays Arch Issues
At EG-CTF25 this year, we focused on creating real-world, practical challenges for players. Our goal wasn’t just to challenge them, but to…Continue reading on Medium »
Read more...
At EG-CTF25 this year, we focused on creating real-world, practical challenges for players. Our goal wasn’t just to challenge them, but to…Continue reading on Medium »
Read more...
Medium
EG-CERT CTF25 Flog: Nowadays Arch Issues
At EG-CTF25 this year, we focused on creating real-world, practical challenges for players. Our goal wasn’t just to challenge them, but to…
CVE-2025–4687 ( Pre-Account takeover through invite on Teletonika RMS website )
Teletonika RMS website which is used to manage remote devices was found to be vulnerable to Pre-account takeover using invite. The…Continue reading on Medium »
Read more...
Teletonika RMS website which is used to manage remote devices was found to be vulnerable to Pre-account takeover using invite. The…Continue reading on Medium »
Read more...
Medium
CVE-2025–4687 ( Pre-Account takeover through invite on Teletonika RMS website )
Teletonika RMS website which is used to manage remote devices was found to be vulnerable to Pre-account takeover using invite. The…
Uncovering Amazon S3 Bucket Vulnerabilities: A Comprehensive Guide for Ethical Hackers
How to Identify, Exploit, and Secure S3 Bucket MisconfigurationsContinue reading on InfoSec Write-ups »
Read more...
How to Identify, Exploit, and Secure S3 Bucket MisconfigurationsContinue reading on InfoSec Write-ups »
Read more...
Medium
Uncovering Amazon S3 Bucket Vulnerabilities: A Comprehensive Guide for Ethical Hackers 🔐💻
How to Identify, Exploit, and Secure S3 Bucket Misconfigurations
Added classic registry based persistence to OnionC2
https://www.reddit.com/r/redteamsec/comments/1kxuqac/added_classic_registry_based_persistence_to/
<!-- SC_OFF -->One of many persistence mechanisms to come. Simple to setup, all you need to do is slightly modify config.rs to your liking. Stay tuned as in the near future I will add advanced mechanisms of persistence. <!-- SC_ON --> submitted by /u/ZarkonesOfficial (https://www.reddit.com/user/ZarkonesOfficial)
[link] (https://github.com/zarkones/OnionC2) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxuqac/added_classic_registry_based_persistence_to/)
https://www.reddit.com/r/redteamsec/comments/1kxuqac/added_classic_registry_based_persistence_to/
<!-- SC_OFF -->One of many persistence mechanisms to come. Simple to setup, all you need to do is slightly modify config.rs to your liking. Stay tuned as in the near future I will add advanced mechanisms of persistence. <!-- SC_ON --> submitted by /u/ZarkonesOfficial (https://www.reddit.com/user/ZarkonesOfficial)
[link] (https://github.com/zarkones/OnionC2) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxuqac/added_classic_registry_based_persistence_to/)