XSS Unleashed: Exploiting & Defending Cross-Site Scripting in the Wild
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Medium
🚨 XSS Unleashed: Exploiting & Defending Cross-Site Scripting in the Wild 💻💥
Cross-Site Scripting (XSS) is still one of the most exploited and underestimated web vulnerabilities out there. Whether you’re a pentester or a dev, mastering how it works and how to shut it down is…
From Hunger to Hacker: How a Zomato Order Earned Me ₹25K”
https://medium.com/@leavemessagetopraveen/from-hunger-to-hacker-how-a-zomato-order-earned-me-25k-706b879c2bce?source=rss------bug_bounty-5
https://medium.com/@leavemessagetopraveen/from-hunger-to-hacker-how-a-zomato-order-earned-me-25k-706b879c2bce?source=rss------bug_bounty-5
Zomato Bugbounty Continue reading on Medium » (https://medium.com/@leavemessagetopraveen/from-hunger-to-hacker-how-a-zomato-order-earned-me-25k-706b879c2bce?source=rss------bug_bounty-5)
Hacking APIs: Exploiting Shadow APIs and Forgotten Endpoints
Most companies focus on protecting their main APIs. But attackers know that the real gold often hides in places security teams forget: old…Continue reading on Medium »
Read more...
Most companies focus on protecting their main APIs. But attackers know that the real gold often hides in places security teams forget: old…Continue reading on Medium »
Read more...
Medium
Hacking APIs: Exploiting Shadow APIs and Forgotten Endpoints
Most companies focus on protecting their main APIs. But attackers know that the real gold often hides in places security teams forget: old…
Cracking JWTs: A Bug Bounty Hunting Guide [Part 6]
JWT Authentication Bypass via Algorithm ConfusionContinue reading on InfoSec Write-ups »
Read more...
JWT Authentication Bypass via Algorithm ConfusionContinue reading on InfoSec Write-ups »
Read more...
Medium
Cracking JWTs: A Bug Bounty Hunting Guide [Part 6]
JWT Authentication Bypass via Algorithm Confusion
Hacking APIs: Exploiting Shadow APIs and Forgotten Endpoints
https://iaraoz.medium.com/hacking-apis-exploiting-shadow-apis-and-forgotten-endpoints-9930c78e7c2d?source=rss------bug_bounty-5
https://iaraoz.medium.com/hacking-apis-exploiting-shadow-apis-and-forgotten-endpoints-9930c78e7c2d?source=rss------bug_bounty-5
Most companies focus on protecting their main APIs. But attackers know that the real gold often hides in places security teams forget: old…Continue reading on Medium » (https://iaraoz.medium.com/hacking-apis-exploiting-shadow-apis-and-forgotten-endpoints-9930c78e7c2d?source=rss------bug_bounty-5)
Cracking JWTs: A Bug Bounty Hunting Guide [Part 6]
https://infosecwriteups.com/cracking-jwts-a-bug-bounty-hunting-guide-part-6-1d48459744f6?source=rss------bug_bounty-5
https://infosecwriteups.com/cracking-jwts-a-bug-bounty-hunting-guide-part-6-1d48459744f6?source=rss------bug_bounty-5
JWT Authentication Bypass via Algorithm ConfusionContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/cracking-jwts-a-bug-bounty-hunting-guide-part-6-1d48459744f6?source=rss------bug_bounty-5)
Bypass Cerrificate Pinning for thick Client applicatio n
https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/
<!-- SC_OFF -->Anyone here had experience with thick client application pentesting and could actually bypass cerrificate pinning ? I am using proxifier and Burp and the application fails whener I try to forward and intercept requests. I can see traffic happening using wireshark. Any suggestions ? <!-- SC_ON --> submitted by /u/ceasar911 (https://www.reddit.com/user/ceasar911)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/)
https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/
<!-- SC_OFF -->Anyone here had experience with thick client application pentesting and could actually bypass cerrificate pinning ? I am using proxifier and Burp and the application fails whener I try to forward and intercept requests. I can see traffic happening using wireshark. Any suggestions ? <!-- SC_ON --> submitted by /u/ceasar911 (https://www.reddit.com/user/ceasar911)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/)
GraphQL Role Escalation and Data Exposure
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
Medium
GraphQL Role Escalation and Data Exposure
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلم
GraphQL Role Escalation and Data Exposure
https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5
https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium » (https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5)
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH »
Read more...
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH »
Read more...
Medium
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern Authentication
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack
https://medium.com/h7w/oauth-misuse-how-broken-flows-and-open-redirects-lead-to-account-hijack-9f280680aab5?source=rss------bug_bounty-5
https://medium.com/h7w/oauth-misuse-how-broken-flows-and-open-redirects-lead-to-account-hijack-9f280680aab5?source=rss------bug_bounty-5