Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF
A Hands-on practical guide to earning rewards.Continue reading on OSINT Team »
Read more...
A Hands-on practical guide to earning rewards.Continue reading on OSINT Team »
Read more...
Medium
Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF
A Hands-on practical guide to earning rewards.
$250 Bounty: How I Tricked the Nextcloud Android App Into Uploading Its Own Sensitive Files
https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5
https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5
A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root AccessContinue reading on OSINT Team » (https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5)
Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF
https://osintteam.blog/grafana-cve-2025-4123-open-redirect-xss-ssrf-8fa24bb26d5d?source=rss------bug_bounty-5
https://osintteam.blog/grafana-cve-2025-4123-open-redirect-xss-ssrf-8fa24bb26d5d?source=rss------bug_bounty-5
A Hands-on practical guide to earning rewards.Continue reading on OSINT Team » (https://osintteam.blog/grafana-cve-2025-4123-open-redirect-xss-ssrf-8fa24bb26d5d?source=rss------bug_bounty-5)
Red Team Tactics and Their Detection Counterparts: A Purple Team Guide
If you’re into purple teaming, this article is for you. Let’s explore how red teams attack — and how blue teams can detect or stop them…Continue reading on Medium »
Read more...
If you’re into purple teaming, this article is for you. Let’s explore how red teams attack — and how blue teams can detect or stop them…Continue reading on Medium »
Read more...
Medium
Red Team Tactics and Their Detection Counterparts: A Purple Team Guide
If you’re into purple teaming, this article is for you. Let’s explore how red teams attack — and how blue teams can detect or stop them…
$560 Bounty: How Twitter’s Android App Leaked User Location
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
Medium
$560 Bounty: How Twitter’s Android App Leaked User Location
A Silent Broadcast That Let Any App Spy on You Without Asking
HTML Injection in Traveler Profiles
Free Article Link: Click for free!Continue reading on InfoSec Write-ups »
Read more...
Free Article Link: Click for free!Continue reading on InfoSec Write-ups »
Read more...
Medium
HTML Injection in Traveler Profiles
Free Article Link: Click for free!
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
Medium
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…
GraphQL Gatecrash: When an Introspection Query Opened the Whole Backend ️
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
GraphQL Gatecrash: When an Introspection Query Opened the Whole Backend 🎟️🔍
Free Link 🎈
$560 Bounty: How Twitter’s Android App Leaked User Location
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
Medium
$560 Bounty: How Twitter’s Android App Leaked User Location
A Silent Broadcast That Let Any App Spy on You Without Asking
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
Medium
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…
Cache-Busting Bonanza: How I Bypassed Rate Limits Using HTTP Weirdness
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
Cache-Busting Bonanza: How I Bypassed Rate Limits Using HTTP Weirdness 🚀📥
Hey there!😁
Inspired by The Amateur, I built Enchat – a secure, encrypted terminal chat tool
https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/
<!-- SC_OFF -->After watching The Amateur, I started thinking more about truly private communication: direct, encrypted, and serverless. So I built Enchat. A lightweight terminal-to-terminal chat app that’s designed for privacy-first, ephemeral conversations. Enchat Github: https://github.com/sudodevdante/enchat Why it’s secure and private: • End-to-end encryption using Fernet (AES 128-bit under the hood) • No servers, no storage, no logs — ever • All messages vanish on exit • No user accounts, no metadata • Runs over Tor or proxychains for full anonymity • Works offline over LAN too (if needed) It’s like netcat but encrypted and made for situations where you don’t want anyone listening in.. not your ISP, not a server, not even a compromised machine in between. Would love to hear thoughts from the community especially if you care about minimal tooling, privacy, and control <!-- SC_ON --> submitted by /u/Weary_Sundae_2634 (https://www.reddit.com/user/Weary_Sundae_2634)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/)
https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/
<!-- SC_OFF -->After watching The Amateur, I started thinking more about truly private communication: direct, encrypted, and serverless. So I built Enchat. A lightweight terminal-to-terminal chat app that’s designed for privacy-first, ephemeral conversations. Enchat Github: https://github.com/sudodevdante/enchat Why it’s secure and private: • End-to-end encryption using Fernet (AES 128-bit under the hood) • No servers, no storage, no logs — ever • All messages vanish on exit • No user accounts, no metadata • Runs over Tor or proxychains for full anonymity • Works offline over LAN too (if needed) It’s like netcat but encrypted and made for situations where you don’t want anyone listening in.. not your ISP, not a server, not even a compromised machine in between. Would love to hear thoughts from the community especially if you care about minimal tooling, privacy, and control <!-- SC_ON --> submitted by /u/Weary_Sundae_2634 (https://www.reddit.com/user/Weary_Sundae_2634)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/)
Found Critical Vulnerability: Unauthorized Access to Customer Support Emails and Data via…
I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…Continue reading on Medium »
Read more...
I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…Continue reading on Medium »
Read more...
Medium
Found Critical Vulnerability: Unauthorized Access to Customer Support Emails and Data via…
I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…
️ 5 Essential Nmap Commands Every Beginner Bug Bounty Hunter Must Know
A complete beginner’s guide to using Nmap for ethical hacking and reconContinue reading on Medium »
Read more...
A complete beginner’s guide to using Nmap for ethical hacking and reconContinue reading on Medium »
Read more...
Medium
🛠️ 5 Essential Nmap Commands Every Beginner Bug Bounty Hunter Must Know
A complete beginner’s guide to using Nmap for ethical hacking and recon
Red Team Tactics and Their Detection Counterparts: A Purple Team Guide
https://medium.com/@paritoshblogs/red-team-tactics-and-their-detection-counterparts-a-purple-team-guide-a20c18ea4402?source=rss------bug_bounty-5
https://medium.com/@paritoshblogs/red-team-tactics-and-their-detection-counterparts-a-purple-team-guide-a20c18ea4402?source=rss------bug_bounty-5