Cracking JWTs: A Bug Bounty Hunting Guide [Part 6]
https://infosecwriteups.com/cracking-jwts-a-bug-bounty-hunting-guide-part-6-1d48459744f6?source=rss------bug_bounty-5
https://infosecwriteups.com/cracking-jwts-a-bug-bounty-hunting-guide-part-6-1d48459744f6?source=rss------bug_bounty-5
JWT Authentication Bypass via Algorithm ConfusionContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/cracking-jwts-a-bug-bounty-hunting-guide-part-6-1d48459744f6?source=rss------bug_bounty-5)
Bypass Cerrificate Pinning for thick Client applicatio n
https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/
<!-- SC_OFF -->Anyone here had experience with thick client application pentesting and could actually bypass cerrificate pinning ? I am using proxifier and Burp and the application fails whener I try to forward and intercept requests. I can see traffic happening using wireshark. Any suggestions ? <!-- SC_ON --> submitted by /u/ceasar911 (https://www.reddit.com/user/ceasar911)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/)
https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/
<!-- SC_OFF -->Anyone here had experience with thick client application pentesting and could actually bypass cerrificate pinning ? I am using proxifier and Burp and the application fails whener I try to forward and intercept requests. I can see traffic happening using wireshark. Any suggestions ? <!-- SC_ON --> submitted by /u/ceasar911 (https://www.reddit.com/user/ceasar911)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/)
GraphQL Role Escalation and Data Exposure
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
Medium
GraphQL Role Escalation and Data Exposure
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلم
GraphQL Role Escalation and Data Exposure
https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5
https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium » (https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5)
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH »
Read more...
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH »
Read more...
Medium
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern Authentication
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack
https://medium.com/h7w/oauth-misuse-how-broken-flows-and-open-redirects-lead-to-account-hijack-9f280680aab5?source=rss------bug_bounty-5
https://medium.com/h7w/oauth-misuse-how-broken-flows-and-open-redirects-lead-to-account-hijack-9f280680aab5?source=rss------bug_bounty-5
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH » (https://medium.com/h7w/oauth-misuse-how-broken-flows-and-open-redirects-lead-to-account-hijack-9f280680aab5?source=rss------bug_bounty-5)
I want a reality check !
https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/
<!-- SC_OFF -->So i'm very new to pensting, i see all those people on youtube claiming you can get a six figure job straight after finishing a 3 month cert, frankly i think this is BS, so i want to know what it actually takes to get a pentesting job, i'm still in uni with 4 years to graduation, i preferably want to use this time to get a pentesting after i get my degree, if it's not realistic then how to accelerate the process and get it as fast as possible. Please be brutally objective with me as i want to hear the unfiltered opinion of professionals, i'm willing to do whatever it takes to make this goal a reality so please help me. <!-- SC_ON --> submitted by /u/Valens_007 (https://www.reddit.com/user/Valens_007)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/)
https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/
<!-- SC_OFF -->So i'm very new to pensting, i see all those people on youtube claiming you can get a six figure job straight after finishing a 3 month cert, frankly i think this is BS, so i want to know what it actually takes to get a pentesting job, i'm still in uni with 4 years to graduation, i preferably want to use this time to get a pentesting after i get my degree, if it's not realistic then how to accelerate the process and get it as fast as possible. Please be brutally objective with me as i want to hear the unfiltered opinion of professionals, i'm willing to do whatever it takes to make this goal a reality so please help me. <!-- SC_ON --> submitted by /u/Valens_007 (https://www.reddit.com/user/Valens_007)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/)
$250 Bounty: How I Tricked the Nextcloud Android App Into Uploading Its Own Sensitive Files
A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root AccessContinue reading on OSINT Team »
Read more...
A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root AccessContinue reading on OSINT Team »
Read more...
Medium
$250 Bounty: How I Tricked the Nextcloud Android App Into Uploading Its Own Sensitive Files
A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root Access
Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF
A Hands-on practical guide to earning rewards.Continue reading on OSINT Team »
Read more...
A Hands-on practical guide to earning rewards.Continue reading on OSINT Team »
Read more...
Medium
Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF
A Hands-on practical guide to earning rewards.
$250 Bounty: How I Tricked the Nextcloud Android App Into Uploading Its Own Sensitive Files
https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5
https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5
A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root AccessContinue reading on OSINT Team » (https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5)
Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF
https://osintteam.blog/grafana-cve-2025-4123-open-redirect-xss-ssrf-8fa24bb26d5d?source=rss------bug_bounty-5
https://osintteam.blog/grafana-cve-2025-4123-open-redirect-xss-ssrf-8fa24bb26d5d?source=rss------bug_bounty-5
A Hands-on practical guide to earning rewards.Continue reading on OSINT Team » (https://osintteam.blog/grafana-cve-2025-4123-open-redirect-xss-ssrf-8fa24bb26d5d?source=rss------bug_bounty-5)