OS command injection, simple case [ES] [PortSwigger]
https://h0lm3s.medium.com/os-command-injection-simple-case-es-portswigger-601126eea44a?source=rss------bug_bounty-5
https://h0lm3s.medium.com/os-command-injection-simple-case-es-portswigger-601126eea44a?source=rss------bug_bounty-5
Imagina que pudieras dar instrucciones secretas al sistema operativo y obtener el resultado sin ningún tipo de filtro, utilizando un canal…Continue reading on Medium » (https://h0lm3s.medium.com/os-command-injection-simple-case-es-portswigger-601126eea44a?source=rss------bug_bounty-5)
Anyone have experience with bypassing sentinelone edr?
https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/
<!-- SC_OFF -->Im Stucked in one red team engagement. Need some guidance from experts here. <!-- SC_ON --> submitted by /u/Designer-Ad6955 (https://www.reddit.com/user/Designer-Ad6955)
[link] (https://google.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/)
https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/
<!-- SC_OFF -->Im Stucked in one red team engagement. Need some guidance from experts here. <!-- SC_ON --> submitted by /u/Designer-Ad6955 (https://www.reddit.com/user/Designer-Ad6955)
[link] (https://google.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/)
SharePoint ToolShell: The Most sophisticated Enterprise hack of 2025
By Mostefa Jakboub | Threat Hunter & Security ResearcherContinue reading on Medium »
Read more...
By Mostefa Jakboub | Threat Hunter & Security ResearcherContinue reading on Medium »
Read more...
Medium
SharePoint ToolShell: The Most sophisticated Enterprise hack of 2025
By Mostefa Jakboub | Threat Hunter & Security Researcher
Insecure OTP Mechanism: How I Discovered a Replay Attack Vulnerability
Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium »
Read more...
Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium »
Read more...
Medium
Insecure OTP Mechanism: How I Discovered a Replay Attack Vulnerability
Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…
Admin Emails & Passwords Exposed via HTTP Method Change
https://www.reddit.com/r/Pentesting/comments/1m9h51p/admin_emails_passwords_exposed_via_http_method/
https://www.reddit.com/r/Pentesting/comments/1m9h51p/admin_emails_passwords_exposed_via_http_method/
<!-- SC_OFF -->Just published a new write-up where I walk through how a small HTTP method misconfiguration led to admin credentials being exposed. It's a simple but impactful example of why misconfigurations matter. 📖 Read it here: https://is4curity.medium.com/admin-emails-passwords-exposed-via-http-method-change-da23186f37d3 Let me know what you think and feel free to share similar cases! <!-- SC_ON --> submitted by /u/General_Speaker9653 (https://www.reddit.com/user/General_Speaker9653)
[link] (https://i.redd.it/puj4vxkmi4ff1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/1m9h51p/admin_emails_passwords_exposed_via_http_method/)
[link] (https://i.redd.it/puj4vxkmi4ff1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/1m9h51p/admin_emails_passwords_exposed_via_http_method/)
The Bug Hiding in Plain Sight: A Simple Click Led to Cross-Org Account Takeover
Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…Continue reading on Medium »
Read more...
Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…Continue reading on Medium »
Read more...
Medium
The Bug Hiding in Plain Sight: A Simple Click Led to Cross-Org Account Takeover
Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…
SharePoint ToolShell: The Most sophisticated Enterprise hack of 2025
https://medium.com/@jakboubmostefa/sharepoint-toolshell-the-most-sophisticated-enterprise-breach-of-2025-7acb4bf71222?source=rss------bug_bounty-5
https://medium.com/@jakboubmostefa/sharepoint-toolshell-the-most-sophisticated-enterprise-breach-of-2025-7acb4bf71222?source=rss------bug_bounty-5
By Mostefa Jakboub | Threat Hunter & Security ResearcherContinue reading on Medium » (https://medium.com/@jakboubmostefa/sharepoint-toolshell-the-most-sophisticated-enterprise-breach-of-2025-7acb4bf71222?source=rss------bug_bounty-5)
Insecure OTP Mechanism: How I Discovered a Replay Attack Vulnerability
https://medium.com/@gowthami09027/insecure-otp-mechanism-how-i-discovered-a-replay-attack-vulnerability-a1c10e49c298?source=rss------bug_bounty-5
https://medium.com/@gowthami09027/insecure-otp-mechanism-how-i-discovered-a-replay-attack-vulnerability-a1c10e49c298?source=rss------bug_bounty-5
Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium » (https://medium.com/@gowthami09027/insecure-otp-mechanism-how-i-discovered-a-replay-attack-vulnerability-a1c10e49c298?source=rss------bug_bounty-5)
The Bug Hiding in Plain Sight: A Simple Click Led to Cross-Org Account Takeover
https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5
https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5
Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…Continue reading on Medium » (https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5)
SSRF via Flawed Request Parsing Leads to SSRF and Internal Admin Access
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
Medium
SSRF via Flawed Request Parsing Leads to SSRF and Internal Admin Access
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.
How I Found a $3,000 Bug Using Just Recon
How I Found a $3,000 Bug Using Just ReconContinue reading on Medium »
Read more...
How I Found a $3,000 Bug Using Just ReconContinue reading on Medium »
Read more...
Medium
How I Found a $3,000 Bug Using Just Recon
How I Found a $3,000 Bug Using Just Recon