Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
Medium
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…
GraphQL Gatecrash: When an Introspection Query Opened the Whole Backend ️
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
GraphQL Gatecrash: When an Introspection Query Opened the Whole Backend 🎟️🔍
Free Link 🎈
$560 Bounty: How Twitter’s Android App Leaked User Location
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
Medium
$560 Bounty: How Twitter’s Android App Leaked User Location
A Silent Broadcast That Let Any App Spy on You Without Asking
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
Medium
Could XSS Be the Hidden Key to Account Takeover
What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…
Cache-Busting Bonanza: How I Bypassed Rate Limits Using HTTP Weirdness
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
Cache-Busting Bonanza: How I Bypassed Rate Limits Using HTTP Weirdness 🚀📥
Hey there!😁
Inspired by The Amateur, I built Enchat – a secure, encrypted terminal chat tool
https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/
<!-- SC_OFF -->After watching The Amateur, I started thinking more about truly private communication: direct, encrypted, and serverless. So I built Enchat. A lightweight terminal-to-terminal chat app that’s designed for privacy-first, ephemeral conversations. Enchat Github: https://github.com/sudodevdante/enchat Why it’s secure and private: • End-to-end encryption using Fernet (AES 128-bit under the hood) • No servers, no storage, no logs — ever • All messages vanish on exit • No user accounts, no metadata • Runs over Tor or proxychains for full anonymity • Works offline over LAN too (if needed) It’s like netcat but encrypted and made for situations where you don’t want anyone listening in.. not your ISP, not a server, not even a compromised machine in between. Would love to hear thoughts from the community especially if you care about minimal tooling, privacy, and control <!-- SC_ON --> submitted by /u/Weary_Sundae_2634 (https://www.reddit.com/user/Weary_Sundae_2634)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/)
https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/
<!-- SC_OFF -->After watching The Amateur, I started thinking more about truly private communication: direct, encrypted, and serverless. So I built Enchat. A lightweight terminal-to-terminal chat app that’s designed for privacy-first, ephemeral conversations. Enchat Github: https://github.com/sudodevdante/enchat Why it’s secure and private: • End-to-end encryption using Fernet (AES 128-bit under the hood) • No servers, no storage, no logs — ever • All messages vanish on exit • No user accounts, no metadata • Runs over Tor or proxychains for full anonymity • Works offline over LAN too (if needed) It’s like netcat but encrypted and made for situations where you don’t want anyone listening in.. not your ISP, not a server, not even a compromised machine in between. Would love to hear thoughts from the community especially if you care about minimal tooling, privacy, and control <!-- SC_ON --> submitted by /u/Weary_Sundae_2634 (https://www.reddit.com/user/Weary_Sundae_2634)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/)
Found Critical Vulnerability: Unauthorized Access to Customer Support Emails and Data via…
I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…Continue reading on Medium »
Read more...
I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…Continue reading on Medium »
Read more...
Medium
Found Critical Vulnerability: Unauthorized Access to Customer Support Emails and Data via…
I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…
️ 5 Essential Nmap Commands Every Beginner Bug Bounty Hunter Must Know
A complete beginner’s guide to using Nmap for ethical hacking and reconContinue reading on Medium »
Read more...
A complete beginner’s guide to using Nmap for ethical hacking and reconContinue reading on Medium »
Read more...
Medium
🛠️ 5 Essential Nmap Commands Every Beginner Bug Bounty Hunter Must Know
A complete beginner’s guide to using Nmap for ethical hacking and recon
Red Team Tactics and Their Detection Counterparts: A Purple Team Guide
https://medium.com/@paritoshblogs/red-team-tactics-and-their-detection-counterparts-a-purple-team-guide-a20c18ea4402?source=rss------bug_bounty-5
https://medium.com/@paritoshblogs/red-team-tactics-and-their-detection-counterparts-a-purple-team-guide-a20c18ea4402?source=rss------bug_bounty-5
If you’re into purple teaming, this article is for you. Let’s explore how red teams attack — and how blue teams can detect or stop them…Continue reading on Medium » (https://medium.com/@paritoshblogs/red-team-tactics-and-their-detection-counterparts-a-purple-team-guide-a20c18ea4402?source=rss------bug_bounty-5)
$560 Bounty: How Twitter’s Android App Leaked User Location
https://infosecwriteups.com/560-bounty-how-twitters-android-app-leaked-user-location-698a8f4d4b18?source=rss------bug_bounty-5
https://infosecwriteups.com/560-bounty-how-twitters-android-app-leaked-user-location-698a8f4d4b18?source=rss------bug_bounty-5
A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/560-bounty-how-twitters-android-app-leaked-user-location-698a8f4d4b18?source=rss------bug_bounty-5)
Upload2Own: How SQL Injection and File Upload Flaws Lead to Remote Code Execution
A story of persistence, subdomain hunting, and how one file upload gave me RCE on two sites.Continue reading on Medium »
Read more...
A story of persistence, subdomain hunting, and how one file upload gave me RCE on two sites.Continue reading on Medium »
Read more...
Medium
Upload2Own: How SQL Injection and File Upload Flaws Lead to Remote Code Execution
A story of persistence, subdomain hunting, and how one file upload gave me RCE on two sites.
From RXSS to ATO: Bypassing WAF with a Simple POST Trick
🛡️ Vulnerability Summary:Continue reading on Medium »
Read more...
🛡️ Vulnerability Summary:Continue reading on Medium »
Read more...
Medium
From RXSS to ATO: Bypassing WAF with a Simple POST Trick
🛡️ Vulnerability Summary:
Critical Google Security Flaw Exposes Millions of Users’ Phone Numbers Through Brute-Force Attack
This comprehensive analysis examines one of the most significant cybersecurity vulnerabilities discovered in 2025.Continue reading on Medium »
Read more...
This comprehensive analysis examines one of the most significant cybersecurity vulnerabilities discovered in 2025.Continue reading on Medium »
Read more...
Medium
Critical Google Security Flaw Exposes Millions of Users’ Phone Numbers Through Brute-Force Attack
This comprehensive analysis examines one of the most significant cybersecurity vulnerabilities discovered in 2025. For additional technical…
How I Made $4,260 Bypassing a Simple Username Bug
How a Single Space in a Username Field Unlocked a Samsung Bug BountyContinue reading on Medium »
Read more...
How a Single Space in a Username Field Unlocked a Samsung Bug BountyContinue reading on Medium »
Read more...
Medium
How I Made $4,260 Bypassing a Simple Username Bug
How a Single Space in a Username Field Unlocked a Samsung Bug Bounty
Debug Logs to Admin Panel Access
How I Accessed the Admin Panel in a Private Program on IntigritiContinue reading on LegionHunters »
Read more...
How I Accessed the Admin Panel in a Private Program on IntigritiContinue reading on LegionHunters »
Read more...
Medium
Debug Logs to Admin Panel Access
How I Accessed the Admin Panel in a Private Program on Intigriti
Bug Bounty for Beginners: The Real Talk Guide (No BS Edition)
A French DBA’s Guide to Actually Starting Bug Bounty Hunting Without Losing Your MindContinue reading on Medium »
Read more...
A French DBA’s Guide to Actually Starting Bug Bounty Hunting Without Losing Your MindContinue reading on Medium »
Read more...
Medium
Bug Bounty for Beginners: The Real Talk Guide (No BS Edition)
A French DBA’s Guide to Actually Starting Bug Bounty Hunting Without Losing Your Mind