De reconocimiento pasivo a investigativo: transformando mi fase de reconocimiento en Bug Bounty
“No es la abundancia de datos lo que te descubre vulnerabilidades, sino la profundidad de tu investigación.”Continue reading on Medium »
Read more...
“No es la abundancia de datos lo que te descubre vulnerabilidades, sino la profundidad de tu investigación.”Continue reading on Medium »
Read more...
Medium
De reconocimiento pasivo a investigativo: transformando mi fase de reconocimiento en Bug Bounty
“No es la abundancia de datos lo que te descubre vulnerabilidades, sino la profundidad de tu investigación.”
$2,000 |critical Samsung Bug Bounty: Bypassing Plan Restrictions via Business Logic Flaw
https://medium.com/@aminefarah802/2-000-critical-samsung-bug-bounty-bypassing-plan-restrictions-via-business-logic-flaw-e18eace8a6cf?source=rss------bug_bounty-5
https://medium.com/@aminefarah802/2-000-critical-samsung-bug-bounty-bypassing-plan-restrictions-via-business-logic-flaw-e18eace8a6cf?source=rss------bug_bounty-5
During testing of Samsung VXT, I discovered a plan escalation vulnerability allowing S Plan users to access Pro Plan features by…Continue reading on Medium » (https://medium.com/@aminefarah802/2-000-critical-samsung-bug-bounty-bypassing-plan-restrictions-via-business-logic-flaw-e18eace8a6cf?source=rss------bug_bounty-5)
Prompt Injection to Bounty: Part 2 — Chaining with SSRF, BOLA & RCE
In Part 1, we explored what Prompt Injection is, how it works, and how real-world systems are already being exploited. But this rabbit…Continue reading on Medium »
Read more...
In Part 1, we explored what Prompt Injection is, how it works, and how real-world systems are already being exploited. But this rabbit…Continue reading on Medium »
Read more...
Medium
Prompt Injection to Bounty: Part 2 — Chaining with SSRF, BOLA & RCE
In Part 1, we explored what Prompt Injection is, how it works, and how real-world systems are already being exploited. But this rabbit…
Prompt-Driven Vulnerability Chains: How to Build Multi-Step Exploits from Low-Severity Bugs with AI
Security testing has evolved far beyond single-click exploits. Today, real-world compromise often requires the ability to chain multiple…Continue reading on Medium »
Read more...
Security testing has evolved far beyond single-click exploits. Today, real-world compromise often requires the ability to chain multiple…Continue reading on Medium »
Read more...
Medium
Prompt-Driven Vulnerability Chains: How to Build Multi-Step Exploits from Low-Severity Bugs with AI
Security testing has evolved far beyond single-click exploits. Today, real-world compromise often requires the ability to chain multiple…
Elastic Heart: How a Misconfigured Kibana Dashboard Sang Like a Canary
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🐤 Elastic Heart: How a Misconfigured Kibana Dashboard Sang Like a Canary 📊🎶
Hey there!😁
Insufficient Workflow Validation: A Logic Flaw Case Study
Discover how insecure logic in online purchase workflows can lead to major security breaches and revenue loss.Continue reading on OSINT Team »
Read more...
Discover how insecure logic in online purchase workflows can lead to major security breaches and revenue loss.Continue reading on OSINT Team »
Read more...
Medium
Insufficient Workflow Validation: A Logic Flaw Case Study
Discover how insecure logic in online purchase workflows can lead to major security breaches and revenue loss.
“$ Unearthing Digital Ghosts: How Deleted GitHub Files Can Make Your Bug Bounty Fortune”
The Illusion of “Delete”Continue reading on Medium »
Read more...
The Illusion of “Delete”Continue reading on Medium »
Read more...
Medium
“$ Unearthing Digital Ghosts: How Deleted GitHub Files Can Make Your Bug Bounty Fortune”
The Illusion of “Delete”
Meta Bug Bounty: Unauthorized Access and Control Over Private Image IDs on meta ai
🧠 IntroductionContinue reading on Medium »
Read more...
🧠 IntroductionContinue reading on Medium »
Read more...
Medium
Meta Bug Bounty: Unauthorized Access and Control Over Private Image IDs on meta ai
🧠 Introduction
From Zero to Super Admin: A Bug Story from My Internship
👩🏻💻“13 Days. No Login. No Hope. Then… Admin Unlocked.”Continue reading on Medium »
Read more...
👩🏻💻“13 Days. No Login. No Hope. Then… Admin Unlocked.”Continue reading on Medium »
Read more...
Medium
🔐From Zero to Super Admin: A Bug Story from My Internship🎯
👩🏻💻“13 Days. No Login. No Hope. Then… Admin Unlocked.”
My first shot with Bugbounty Radar and I hit a vuln — bounty coming soon?
Hello guys,Continue reading on Medium »
Read more...
Hello guys,Continue reading on Medium »
Read more...
Medium
My first shot with Bugbounty Radar and I hit a vuln — bounty coming soon?
Hello guys,
Hack The Box Journey — Day 2: Learning by Doing (Not Just Watching)
Date: July 18, 2025 Focus: Web Exploitation Basics Tools Used: Kali Linux, curl, Firefox Developer Tools Platform: Hack The Box — Starting…Continue reading on Medium »
Read more...
Date: July 18, 2025 Focus: Web Exploitation Basics Tools Used: Kali Linux, curl, Firefox Developer Tools Platform: Hack The Box — Starting…Continue reading on Medium »
Read more...
Medium
Hack The Box Journey — Day 2: Learning by Doing (Not Just Watching)
Date: July 18, 2025
Focus: Web Exploitation Basics Tools Used: Kali Linux, curl, Firefox Developer Tools
Platform: Hack The Box — Starting…
Focus: Web Exploitation Basics Tools Used: Kali Linux, curl, Firefox Developer Tools
Platform: Hack The Box — Starting…
Password Change Doesn’t Expire Sessions — A Hidden Risk in Session Management
Author: Gourav Kumar (Gourav(spidergk)) Platform: hub.example.com Bug Type: Insufficient Session Expiration Status: Closed as Duplicate…Continue reading on Medium »
Read more...
Author: Gourav Kumar (Gourav(spidergk)) Platform: hub.example.com Bug Type: Insufficient Session Expiration Status: Closed as Duplicate…Continue reading on Medium »
Read more...
Medium
Password Change Doesn’t Expire Sessions — A Hidden Risk in Session Management
Author: Gourav Kumar (Gourav(spidergk)) Platform: hub.example.com Bug Type: Insufficient Session Expiration Status: Closed as Duplicate…
From Recon to Root: The Ultimate Bug Bounty Recon Playbook (2025 Edition)
Bug bounty isn’t just about knowing what to attack — it’s about knowing where and how to look. In this ultimate recon playbook, we’ll walk…Continue reading on Medium »
Read more...
Bug bounty isn’t just about knowing what to attack — it’s about knowing where and how to look. In this ultimate recon playbook, we’ll walk…Continue reading on Medium »
Read more...
Medium
From Recon to Root: The Ultimate Bug Bounty Recon Playbook (2025 Edition)
Bug bounty isn’t just about knowing what to attack — it’s about knowing where and how to look. In this ultimate recon playbook, we’ll walk…
Google Dorks for Bug Bounty Hunting: 25 Powerful Dorks to Find Exposed PDFs, NDAs, and Signatures
Bug bounty hunting isn’t just about scanning for common vulnerabilities — it’s about knowing where sensitive data might be hiding. One of…Continue reading on Medium »
Read more...
Bug bounty hunting isn’t just about scanning for common vulnerabilities — it’s about knowing where sensitive data might be hiding. One of…Continue reading on Medium »
Read more...
Medium
Google Dorks for Bug Bounty Hunting: 25 Powerful Dorks to Find Exposed PDFs, NDAs, and Signatures
Bug bounty hunting isn’t just about scanning for common vulnerabilities — it’s about knowing where sensitive data might be hiding. One of…
I Broke Rate Limits to Hijack Accounts — Without Getting Blocked
During a bug bounty hunt, a single flaw was discovered that allowed me to reset any user’s password, without a single click from the…Continue reading on Medium »
Read more...
During a bug bounty hunt, a single flaw was discovered that allowed me to reset any user’s password, without a single click from the…Continue reading on Medium »
Read more...
Medium
I Broke Rate Limits to Hijack Accounts — Without Getting Blocked
During a bug bounty hunt, a single flaw was discovered that allowed me to reset any user’s password, without a single click from the…
Cracking Ray-Ban Stories: How a Firmware Tweak Exposed Privacy Risks
The Hook: A 30-Second Limit Begging to Be BrokenContinue reading on Medium »
Read more...
The Hook: A 30-Second Limit Begging to Be BrokenContinue reading on Medium »
Read more...
Medium
Cracking Ray-Ban Stories: How a Firmware Tweak Exposed Privacy Risks
The Hook: A 30-Second Limit Begging to Be Broken
Same Bug, Different Places: 3 Logic Flaws I Found on Main Domain
بِسْمِ اللَّـهِ الرَّحْمَٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَىٰ الْمَبْعُوثِ رَحْمَةً لِلْعَالَمِينَ ﷺContinue reading on Medium »
Read more...
بِسْمِ اللَّـهِ الرَّحْمَٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَىٰ الْمَبْعُوثِ رَحْمَةً لِلْعَالَمِينَ ﷺContinue reading on Medium »
Read more...
Medium
Same Bug, Different Places: 3 Logic Flaws I Found on Main Domain💥
بِسْمِ اللَّـهِ الرَّحْمَٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَىٰ الْمَبْعُوثِ رَحْمَةً لِلْعَالَمِينَ ﷺ
Citrix Bleed 2: Critical RCE Flaw in 2025
Intro: A New Citrix NightmareContinue reading on Medium »
Read more...
Intro: A New Citrix NightmareContinue reading on Medium »
Read more...
Medium
Citrix Bleed 2: Critical RCE Flaw in 2025
Intro: A New Citrix Nightmare
Where to learn stuff and is it worth though?
https://www.reddit.com/r/Pentesting/comments/1m2z9vl/where_to_learn_stuff_and_is_it_worth_though/
<!-- SC_OFF -->I've started to slightly dive in cybersecurity 2 weeks ago. After researching what i like more i've decided to move towards pentesting specialization. Started on HTB network fundamentals, after moved on Linux fundamentals + OverTheWire bandit levels. I'm feeling bit concerned about did i choose good resources for studying and how long my journey gonna take. I'm aware that in the IT sphere everyday you work - everyday you learn. And i'm not scared about that, i just lost some part of motivation and don't really sure will i be able to find a job as a pentester after couple of years of constantly studying due to rapidly AI evolution. Maybe someone know great free education resources? <!-- SC_ON --> submitted by /u/askalenok (https://www.reddit.com/user/askalenok)
[link] (https://www.reddit.com/r/Pentesting/comments/1m2z9vl/where_to_learn_stuff_and_is_it_worth_though/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2z9vl/where_to_learn_stuff_and_is_it_worth_though/)
https://www.reddit.com/r/Pentesting/comments/1m2z9vl/where_to_learn_stuff_and_is_it_worth_though/
<!-- SC_OFF -->I've started to slightly dive in cybersecurity 2 weeks ago. After researching what i like more i've decided to move towards pentesting specialization. Started on HTB network fundamentals, after moved on Linux fundamentals + OverTheWire bandit levels. I'm feeling bit concerned about did i choose good resources for studying and how long my journey gonna take. I'm aware that in the IT sphere everyday you work - everyday you learn. And i'm not scared about that, i just lost some part of motivation and don't really sure will i be able to find a job as a pentester after couple of years of constantly studying due to rapidly AI evolution. Maybe someone know great free education resources? <!-- SC_ON --> submitted by /u/askalenok (https://www.reddit.com/user/askalenok)
[link] (https://www.reddit.com/r/Pentesting/comments/1m2z9vl/where_to_learn_stuff_and_is_it_worth_though/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2z9vl/where_to_learn_stuff_and_is_it_worth_though/)