Cracking the Clock: How I Took Over Any Account Using a Timestamp Leak
https://ritikver22000.medium.com/cracking-the-clock-how-i-took-over-any-account-using-a-timestamp-leak-516fc88c0113?source=rss------bug_bounty-5
https://ritikver22000.medium.com/cracking-the-clock-how-i-took-over-any-account-using-a-timestamp-leak-516fc88c0113?source=rss------bug_bounty-5
🧠 The Curiosity That Sparked ItContinue reading on Medium » (https://ritikver22000.medium.com/cracking-the-clock-how-i-took-over-any-account-using-a-timestamp-leak-516fc88c0113?source=rss------bug_bounty-5)
HOW I WOULD START BUG BOUNTY IN MID 2025!?
https://medium.com/@Tenebris_Venator/how-i-would-start-bug-bounty-in-mid-2025-3cdbd3f726fb?source=rss------bug_bounty-5
https://medium.com/@Tenebris_Venator/how-i-would-start-bug-bounty-in-mid-2025-3cdbd3f726fb?source=rss------bug_bounty-5
How can you start bug hunting in 2025, even in the middle of the year?Continue reading on Medium » (https://medium.com/@Tenebris_Venator/how-i-would-start-bug-bounty-in-mid-2025-3cdbd3f726fb?source=rss------bug_bounty-5)
Web Application Penetration Testing
Comprehensive Web Application Testing GuideContinue reading on Medium »
Read more...
Comprehensive Web Application Testing GuideContinue reading on Medium »
Read more...
Medium
Web Application Penetration Testing
Comprehensive Web Application Testing Guide
Github - chillyilly/SPFShadow: utility to find subdomains with permissive or nonexistant SPF records.
https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/
<!-- SC_OFF -->This is a great way to bypass email filters. Has worked on current engagements <!-- SC_ON --> submitted by /u/cooldadhacking (https://www.reddit.com/user/cooldadhacking)
[link] (https://github.com/chillyilly/spfshadow) [comments] (https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/)
https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/
<!-- SC_OFF -->This is a great way to bypass email filters. Has worked on current engagements <!-- SC_ON --> submitted by /u/cooldadhacking (https://www.reddit.com/user/cooldadhacking)
[link] (https://github.com/chillyilly/spfshadow) [comments] (https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/)
Advanced HTTP Request Smuggling (HRS) Exploitation Guide
By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness »
Read more...
By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness »
Read more...
Medium
💣 Advanced HTTP Request Smuggling (HRS) Exploitation Guide
By Shah kaif | “Two headers. One request. Your rules.” | LinkedIn
Advanced HTTP Request Smuggling (HRS) Exploitation Guide
https://systemweakness.com/advanced-http-request-smuggling-hrs-exploitation-guide-53ceadd5ac19?source=rss------bug_bounty-5
https://systemweakness.com/advanced-http-request-smuggling-hrs-exploitation-guide-53ceadd5ac19?source=rss------bug_bounty-5
By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness » (https://systemweakness.com/advanced-http-request-smuggling-hrs-exploitation-guide-53ceadd5ac19?source=rss------bug_bounty-5)
What’s the most overlooked vulnerability in modern web apps today?
https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/
<!-- SC_OFF -->Curious to hear what others think is flying under the radar in 2025. I’m seeing some wild stuff lately that doesn't show up in standard scans. <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/)
https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/
<!-- SC_OFF -->Curious to hear what others think is flying under the radar in 2025. I’m seeing some wild stuff lately that doesn't show up in standard scans. <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/)
Is the industry still underestimating low-code/no-code app vulnerabilities?
https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/
<!-- SC_OFF -->These platforms are everywhere now. But are we even testing them properly? <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/)
https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/
<!-- SC_OFF -->These platforms are everywhere now. But are we even testing them properly? <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/)
Bypassing Authentication: A Critical Flaw in Basecamp’s
How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
Medium
Bypassing Authentication: A Critical Flaw in Basecamp’s
How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup Codes
How I hacked Karnataka NIC portal with a simple SQL injection
Exploiting a Blind SQL injection vulnerability in karresults.nic.inContinue reading on InfoSec Write-ups »
Read more...
Exploiting a Blind SQL injection vulnerability in karresults.nic.inContinue reading on InfoSec Write-ups »
Read more...
Medium
How I hacked Karnataka NIC portal with a simple SQL injection
Exploiting a Blind SQL injection vulnerability in karresults.nic.in
Broken Object Level Authorization (BOLA): Complete Guide — Part 1
📌 What is BOLA and Why It’s the #1 API Risk You Shouldn’t IgnoreContinue reading on Medium »
Read more...
📌 What is BOLA and Why It’s the #1 API Risk You Shouldn’t IgnoreContinue reading on Medium »
Read more...
Medium
Broken Object Level Authorization (BOLA): Complete Guide — Part 1
📌 What is BOLA and Why It’s the #1 API Risk You Shouldn’t Ignore
Broken Object Level Authorization (BOLA): Complete Guide — Part 2
🔍 Part 2: Where BOLA Hides — Common Vulnerable SpotsContinue reading on Medium »
Read more...
🔍 Part 2: Where BOLA Hides — Common Vulnerable SpotsContinue reading on Medium »
Read more...
Medium
Broken Object Level Authorization (BOLA): Complete Guide — Part 2
🔍 Part 2: Where BOLA Hides — Common Vulnerable Spots
Bypassing Authentication: A Critical Flaw in Basecamp’s
How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
Medium
Bypassing Authentication: A Critical Flaw in Basecamp’s
How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup Codes
OAuth2verdrive: How Broken Token Exchange Let Me Log in as Any User
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
OAuth2verdrive: How Broken Token Exchange Let Me Log in as Any User 🚂💥
Hey there!😁
A classic file based IDOR on NIELIT portal
Hello and welcome to all! This is Adithya M S, a novice web hacker passionate about digging deep into how website endpoints work and how their parameters may be tampered with. Disclaimer: The content provided in this article is for educational and informational purposes only. Always ensure you have proper authorization before conducting security assessments. Use this information responsibly. Neither me nor the publication may be held liable for any harm, damage or legal trouble caused by acting on the information contained in this blog post. Please exercise discretion. In this blog, I shall share my experience of exploiting a file based IDOR in the NIELIT website. If you have NOT heard of the term IDOR before, it stands for Insecure Direct Object Reference and occurs when a web server takes internal references to resources (such as files, other records) as parameters/inputs in paths or queries (in web requests) and handles them in an insecure way to respond with the corresponding resource. There are many nice articles on the web to get some more clarity on IDOR. Here is one such reference. Insecure direct object references (IDOR) | Web Security Academy Now let’s get started. NIELIT is an Indian government institute that focuses on developing human resources and related activities in the field of Information, Electronics, and Communications Technology. NIELIT also conducts an entrance examination every year to select students for its various programs. My brother applied for this exam and thus I was able to login by getting his credentials and see the various sections of the website available to logged in users. One of the sections is to review the filled application form. Part of this page also contains links to view 3 documentsApplication Form review page partApplication form review page Now we click on one of these links to view the uploaded documents fileDocument at the URL https://nltchd.info/nielituniv25/Uploads/canddocx/71399_documents.pdf Now 71399 is the registration number of my brother. The same appears in the URL to view his uploaded documents https://nltchd.info/nielituniv25/Uploads/canddocx/71399_documents.pdf. What if we change this number to say 71405 ?Document at the URL https://nltchd.info/nielituniv25/Uploads/canddocx/71405_documents.pdf Wow!!, we get the documents of the user with registration number 71405 The same technique holds for the photo and signature files. Their names follow the same pattern and contain the candidate registration number. Anyone can access everybody else’s documents !! What an IDOR ?? I hope you guys had fun reading this blog and Happy hacking !! Please follow me and give me some claps 👏 if you liked this post. Please comment on this post to give me any feedback that you may have and let me know how to get this bug resolved. Thank you again for reading my article !! A classic file based IDOR on NIELIT portal was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Hello and welcome to all! This is Adithya M S, a novice web hacker passionate about digging deep into how website endpoints work and how their parameters may be tampered with. Disclaimer: The content provided in this article is for educational and informational purposes only. Always ensure you have proper authorization before conducting security assessments. Use this information responsibly. Neither me nor the publication may be held liable for any harm, damage or legal trouble caused by acting on the information contained in this blog post. Please exercise discretion. In this blog, I shall share my experience of exploiting a file based IDOR in the NIELIT website. If you have NOT heard of the term IDOR before, it stands for Insecure Direct Object Reference and occurs when a web server takes internal references to resources (such as files, other records) as parameters/inputs in paths or queries (in web requests) and handles them in an insecure way to respond with the corresponding resource. There are many nice articles on the web to get some more clarity on IDOR. Here is one such reference. Insecure direct object references (IDOR) | Web Security Academy Now let’s get started. NIELIT is an Indian government institute that focuses on developing human resources and related activities in the field of Information, Electronics, and Communications Technology. NIELIT also conducts an entrance examination every year to select students for its various programs. My brother applied for this exam and thus I was able to login by getting his credentials and see the various sections of the website available to logged in users. One of the sections is to review the filled application form. Part of this page also contains links to view 3 documentsApplication Form review page partApplication form review page Now we click on one of these links to view the uploaded documents fileDocument at the URL https://nltchd.info/nielituniv25/Uploads/canddocx/71399_documents.pdf Now 71399 is the registration number of my brother. The same appears in the URL to view his uploaded documents https://nltchd.info/nielituniv25/Uploads/canddocx/71399_documents.pdf. What if we change this number to say 71405 ?Document at the URL https://nltchd.info/nielituniv25/Uploads/canddocx/71405_documents.pdf Wow!!, we get the documents of the user with registration number 71405 The same technique holds for the photo and signature files. Their names follow the same pattern and contain the candidate registration number. Anyone can access everybody else’s documents !! What an IDOR ?? I hope you guys had fun reading this blog and Happy hacking !! Please follow me and give me some claps 👏 if you liked this post. Please comment on this post to give me any feedback that you may have and let me know how to get this bug resolved. Thank you again for reading my article !! A classic file based IDOR on NIELIT portal was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...