From HTML Injection to Admin Info Leak — My First Bug Bounty Payout
https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever tag and some luckContinue reading on Medium » (https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5)
https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5
How a simple HTML injection led me to leak admin info and earn my first bug bounty all with one clever tag and some luckContinue reading on Medium » (https://medium.com/@shabutaher0/from-html-injection-to-admin-info-leak-my-first-bug-bounty-payout-751a16b41518?source=rss------bug_bounty-5)
Breaking SMTP: Real-World Enumeration Using Nmap, Telnet & Metasploit
https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5
By Nazia MobeenContinue reading on Medium » (https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5)
https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5
By Nazia MobeenContinue reading on Medium » (https://medium.com/@naziamalik24822/breaking-smtp-real-world-enumeration-using-nmap-telnet-metasploit-1574633f4f52?source=rss------bug_bounty-5)
Breaking SMTP: Real-World Enumeration Using Nmap, Telnet & Metasploit
By Nazia MobeenContinue reading on Medium »
Read more...
By Nazia MobeenContinue reading on Medium »
Read more...
Medium
🧠 Breaking SMTP: Real-World Enumeration Using Nmap, Telnet & Metasploit
By Nazia Mobeen
Introduction
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…Continue reading on Medium »
Read more...
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…Continue reading on Medium »
Read more...
Medium
⏱️ Bypassing Limits with Style: Exploiting a Race Condition in the Wild 🚀🧠
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…
This was one of my earlier discoveries as a hacker under the name ValidByAccident — a case that showed me how concurrency issues can slip…Continue reading on Medium » (https://medium.com/@chorfimajd22/introduction-dd73e4ae2897?source=rss------bug_bounty-5)
Bug Bounty Journey — Valid Report Part 8
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…Continue reading on Medium »
Read more...
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…Continue reading on Medium »
Read more...
Medium
Bug Bounty Journey — Valid Report Part 8
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…
Bug Bounty Journey — Valid Report Part 8
https://medium.com/@0xF3r4t/bug-bounty-journey-valid-report-part-8-0edfa67082b2?source=rss------bug_bounty-5
https://medium.com/@0xF3r4t/bug-bounty-journey-valid-report-part-8-0edfa67082b2?source=rss------bug_bounty-5
In this journey, I will share my experience with a valid report I submitted. This will be a series until I discover new vulnerabilities…Continue reading on Medium » (https://medium.com/@0xF3r4t/bug-bounty-journey-valid-report-part-8-0edfa67082b2?source=rss------bug_bounty-5)
Diseño Inseguro: Guía de Hacking, Bug Bounty y Prevención
Descubre cómo las fallas en la lógica de negocio crean bugs que pagan alto en Bug Bounty. ¡La creatividad es clave!Continue reading on Medium »
Read more...
Descubre cómo las fallas en la lógica de negocio crean bugs que pagan alto en Bug Bounty. ¡La creatividad es clave!Continue reading on Medium »
Read more...
Medium
Insecure Design (OWASP A04): Guía de Hacking, Bug Bounty y Prevención
Descubre cómo las fallas en la lógica de negocio crean bugs que pagan alto en Bug Bounty. ¡La creatividad es clave!
$240 Bounty: Denial of Service Vulnerability in Python
How a Simple HTTP Request Can Cripple Your Python ApplicationContinue reading on T3CH »
Read more...
How a Simple HTTP Request Can Cripple Your Python ApplicationContinue reading on T3CH »
Read more...
Medium
$240 Bounty: Denial of Service Vulnerability in Python
How a Simple HTTP Request Can Cripple Your Python Application
SSRF via PDF Export in Analytics Dashboard
How a Common Reporting Feature Can Expose Internal InfrastructureContinue reading on T3CH »
Read more...
How a Common Reporting Feature Can Expose Internal InfrastructureContinue reading on T3CH »
Read more...
Medium
SSRF via PDF Export in Analytics Dashboard
How a Common Reporting Feature Can Expose Internal Infrastructure
Leveraging Real-time work queue API for shellcode execution
https://www.reddit.com/r/redteamsec/comments/1m23j9c/leveraging_realtime_work_queue_api_for_shellcode/
submitted by /u/flamedpt (https://www.reddit.com/user/flamedpt)
[link] (https://ghostline.neocities.org/RtwqExecution/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m23j9c/leveraging_realtime_work_queue_api_for_shellcode/)
https://www.reddit.com/r/redteamsec/comments/1m23j9c/leveraging_realtime_work_queue_api_for_shellcode/
submitted by /u/flamedpt (https://www.reddit.com/user/flamedpt)
[link] (https://ghostline.neocities.org/RtwqExecution/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m23j9c/leveraging_realtime_work_queue_api_for_shellcode/)
Coding in Red Teaming
https://www.reddit.com/r/redteamsec/comments/1m2okir/coding_in_red_teaming/
<!-- SC_OFF -->Hey, I'm new here in this subreddit, and new at the concept of cybersec/pentest/red teaming. I'm pursuing a degree in computer engineering now, but I don't know exactly which carrer path to follow. After some research, i stumbled acrosso some cybersec info, found abound red teaming and it caught my eyes, because i love the dynamism this carrer (possibly) can offer, always having to come up with new ways to infiltrate, malwares, etc. What is the recommended path to take to know if this is really what I want? How can I get good at it? Another doubt is if it involves a lot of coding. I love coding, but not so much building apps/web views, just the act of code, mainly in C/C++, does this carrer path has a lot of moments that i can code tools/scripts? Thank you! <!-- SC_ON --> submitted by /u/zokura_c (https://www.reddit.com/user/zokura_c)
[link] (http://www.example.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m2okir/coding_in_red_teaming/)
https://www.reddit.com/r/redteamsec/comments/1m2okir/coding_in_red_teaming/
<!-- SC_OFF -->Hey, I'm new here in this subreddit, and new at the concept of cybersec/pentest/red teaming. I'm pursuing a degree in computer engineering now, but I don't know exactly which carrer path to follow. After some research, i stumbled acrosso some cybersec info, found abound red teaming and it caught my eyes, because i love the dynamism this carrer (possibly) can offer, always having to come up with new ways to infiltrate, malwares, etc. What is the recommended path to take to know if this is really what I want? How can I get good at it? Another doubt is if it involves a lot of coding. I love coding, but not so much building apps/web views, just the act of code, mainly in C/C++, does this carrer path has a lot of moments that i can code tools/scripts? Thank you! <!-- SC_ON --> submitted by /u/zokura_c (https://www.reddit.com/user/zokura_c)
[link] (http://www.example.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m2okir/coding_in_red_teaming/)
Mastering the Hunt: The Ultimate Guide to Modern Bug Bounty Hunting
From Recon to Report — A Beginner-to-Advanced Journey for Finding Real-World Security VulnerabilitiesContinue reading on OSINT Team »
Read more...
From Recon to Report — A Beginner-to-Advanced Journey for Finding Real-World Security VulnerabilitiesContinue reading on OSINT Team »
Read more...
Medium
Mastering the Hunt: The Ultimate Guide to Modern Bug Bounty Hunting
From Recon to Report — A Beginner-to-Advanced Journey for Finding Real-World Security Vulnerabilities
Diseño Inseguro: Guía de Hacking, Bug Bounty y Prevención
https://medium.com/@jpablo13/dise%C3%B1o-inseguro-gu%C3%ADa-de-hacking-bug-bounty-y-prevenci%C3%B3n-b8a50b23fb71?source=rss------bug_bounty-5
https://medium.com/@jpablo13/dise%C3%B1o-inseguro-gu%C3%ADa-de-hacking-bug-bounty-y-prevenci%C3%B3n-b8a50b23fb71?source=rss------bug_bounty-5
Descubre cómo las fallas en la lógica de negocio crean bugs que pagan alto en Bug Bounty. ¡La creatividad es clave!Continue reading on Medium » (https://medium.com/@jpablo13/dise%C3%B1o-inseguro-gu%C3%ADa-de-hacking-bug-bounty-y-prevenci%C3%B3n-b8a50b23fb71?source=rss------bug_bounty-5)
$240 Bounty: Denial of Service Vulnerability in Python
https://medium.com/h7w/240-bounty-denial-of-service-vulnerability-in-python-f42b24cfa066?source=rss------bug_bounty-5
https://medium.com/h7w/240-bounty-denial-of-service-vulnerability-in-python-f42b24cfa066?source=rss------bug_bounty-5