My First Bounty: How I Found an Information Disclosure Bug on HackerOne
Writes upContinue reading on Medium »
Read more...
Writes upContinue reading on Medium »
Read more...
Medium
🎉 My First Bounty: How I Found an Information Disclosure Bug on HackerOne
Writes up
Path Traversal — A tour to the web server’s assets
Path traversal, also known as Directory traversal, is a vulnerability that can reveal sensitive information stored on the web server.Continue reading on Medium »
Read more...
Path traversal, also known as Directory traversal, is a vulnerability that can reveal sensitive information stored on the web server.Continue reading on Medium »
Read more...
Medium
Path Traversal — A tour to the web server’s assets
Path traversal, also known as Directory traversal, is a vulnerability that can reveal sensitive information stored on the web server.
Open Redirect Vulnerability — The Silent Gateway to Phishing and OAuth Hijacks
By Shah kaif | | “Open redirects don’t break your app — they break your user’s trust.” | LinkedInContinue reading on Medium »
Read more...
By Shah kaif | | “Open redirects don’t break your app — they break your user’s trust.” | LinkedInContinue reading on Medium »
Read more...
Medium
Open Redirect Vulnerability — The Silent Gateway to Phishing and OAuth Hijacks
By Shah kaif | | “Open redirects don’t break your app — they break your user’s trust.” | LinkedIn
Why You Should NOT Choose Cybersecurity as a Career
Cybersecurity is not for everyone.Continue reading on Medium »
Read more...
Cybersecurity is not for everyone.Continue reading on Medium »
Read more...
Medium
Why You Should NOT Choose Cybersecurity as a Career
Cybersecurity is not for everyone.
How I Use the DeFi Watchdog Unified Security API to Secure Smart Contracts (Part 1)
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
How I Use the DeFi Watchdog Unified Security API to Secure Smart Contracts (Part 1)
Introduction
Prompt Injection to Bounty: How LLMs Can Turn Into Entry Points
https://medium.com/@narendarlb123/prompt-injection-to-bounty-how-llms-can-turn-into-entry-points-bbf7bb6c8b05?source=rss------bug_bounty-5
In the era of AI-driven applications, large language models (LLMs) have revolutionized everything — from customer support to code…Continue reading on Medium » (https://medium.com/@narendarlb123/prompt-injection-to-bounty-how-llms-can-turn-into-entry-points-bbf7bb6c8b05?source=rss------bug_bounty-5)
https://medium.com/@narendarlb123/prompt-injection-to-bounty-how-llms-can-turn-into-entry-points-bbf7bb6c8b05?source=rss------bug_bounty-5
In the era of AI-driven applications, large language models (LLMs) have revolutionized everything — from customer support to code…Continue reading on Medium » (https://medium.com/@narendarlb123/prompt-injection-to-bounty-how-llms-can-turn-into-entry-points-bbf7bb6c8b05?source=rss------bug_bounty-5)
My Latest Bug: Reflected XSS on GlobalProtect VPN Portal (CVE-2025–0133)
Hello everyone,Continue reading on Medium »
Read more...
Hello everyone,Continue reading on Medium »
Read more...
Medium
My Latest Bug: Reflected XSS on GlobalProtect VPN Portal (CVE-2025–0133)💥
Hello everyone,
From HTML Injection to Admin Info Leak — My First Bug Bounty Payout
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever <img> tag and some luckContinue reading on Medium »
Read more...
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever <img> tag and some luckContinue reading on Medium »
Read more...
Medium
From HTML Injection to Admin Info Leak — My First Bug Bounty Payout
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever <img> tag and some luck
Open to freelancing
https://www.reddit.com/r/Pentesting/comments/1m26jcl/open_to_freelancing/
<!-- SC_OFF -->After working 8yrs in VAPT (ulnerability assessment and penetration testing) looking forward to start my freelancing carreer, and open to collabs as well, i am OSCP certified You can reach me for the following assessments Web application security assessmemt Mobile application security assessment Thick client penetration testing API penetration testing Internal and external network audits <!-- SC_ON --> submitted by /u/PsychologyLow2558 (https://www.reddit.com/user/PsychologyLow2558)
[link] (https://www.reddit.com/r/Pentesting/comments/1m26jcl/open_to_freelancing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m26jcl/open_to_freelancing/)
https://www.reddit.com/r/Pentesting/comments/1m26jcl/open_to_freelancing/
<!-- SC_OFF -->After working 8yrs in VAPT (ulnerability assessment and penetration testing) looking forward to start my freelancing carreer, and open to collabs as well, i am OSCP certified You can reach me for the following assessments Web application security assessmemt Mobile application security assessment Thick client penetration testing API penetration testing Internal and external network audits <!-- SC_ON --> submitted by /u/PsychologyLow2558 (https://www.reddit.com/user/PsychologyLow2558)
[link] (https://www.reddit.com/r/Pentesting/comments/1m26jcl/open_to_freelancing/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m26jcl/open_to_freelancing/)
submitted by /u/IntrigueMe_1337 (https://www.reddit.com/user/IntrigueMe_1337)
[link] (https://youtu.be/h6w4SX7ZJMQ?si=WvHkkd4y0am-z8po) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2awuf/enjoy/)
[link] (https://youtu.be/h6w4SX7ZJMQ?si=WvHkkd4y0am-z8po) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2awuf/enjoy/)
Completed Pentesting in Cybersecurity from DataSpace, cleared eJPT, Google Cybersecurity Cert, solved 100+ CTFs, and built red & blue team projects (GitHub/Medium). Still jobless as a fresher. Does eJPT & Google cert hold value in India? Seeking guidance/opportunity.
https://www.reddit.com/r/Pentesting/comments/1m2blop/completed_pentesting_in_cybersecurity_from/
submitted by /u/No-Flatworm-5445 (https://www.reddit.com/user/No-Flatworm-5445)
[link] (https://www.reddit.com/r/Pentesting/comments/1m2blop/completed_pentesting_in_cybersecurity_from/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2blop/completed_pentesting_in_cybersecurity_from/)
https://www.reddit.com/r/Pentesting/comments/1m2blop/completed_pentesting_in_cybersecurity_from/
submitted by /u/No-Flatworm-5445 (https://www.reddit.com/user/No-Flatworm-5445)
[link] (https://www.reddit.com/r/Pentesting/comments/1m2blop/completed_pentesting_in_cybersecurity_from/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2blop/completed_pentesting_in_cybersecurity_from/)
My Latest Bug: Reflected XSS on GlobalProtect VPN Portal (CVE-2025–0133)
https://medium.com/@firdansp/my-latest-bug-reflected-xss-on-globalprotect-vpn-portal-cve-2025-0133-ba1649943250?source=rss------bug_bounty-5
https://medium.com/@firdansp/my-latest-bug-reflected-xss-on-globalprotect-vpn-portal-cve-2025-0133-ba1649943250?source=rss------bug_bounty-5
Hello everyone,Continue reading on Medium » (https://medium.com/@firdansp/my-latest-bug-reflected-xss-on-globalprotect-vpn-portal-cve-2025-0133-ba1649943250?source=rss------bug_bounty-5)
From HTML Injection to Admin Info Leak — My First Bug Bounty Payout
https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever tag and some luckContinue reading on Medium » (https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5)
https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever tag and some luckContinue reading on Medium » (https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5)
Breaking SMTP: Real-World Enumeration Using Nmap, Telnet & Metasploit
https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5
By Nazia MobeenContinue reading on Medium » (https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5)
https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5
By Nazia MobeenContinue reading on Medium » (https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5)
Breaking SMTP: Real-World Enumeration Using Nmap, Telnet & Metasploit
By Nazia MobeenContinue reading on Medium »
Read more...
By Nazia MobeenContinue reading on Medium »
Read more...
Medium
🧠 Breaking SMTP: Real-World Enumeration Using Nmap, Telnet & Metasploit
By Nazia Mobeen
Introduction
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…Continue reading on Medium »
Read more...
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…Continue reading on Medium »
Read more...
Medium
⏱️ Bypassing Limits with Style: Exploiting a Race Condition in the Wild 🚀🧠
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…