Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium » (https://medium.com/@gowthami09027/insecure-otp-mechanism-how-i-discovered-a-replay-attack-vulnerability-a1c10e49c298?source=rss------bug_bounty-5)
The Bug Hiding in Plain Sight: A Simple Click Led to Cross-Org Account Takeover
https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5
https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5
Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…Continue reading on Medium » (https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5)
SSRF via Flawed Request Parsing Leads to SSRF and Internal Admin Access
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
Medium
SSRF via Flawed Request Parsing Leads to SSRF and Internal Admin Access
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.
How I Found a $3,000 Bug Using Just Recon
How I Found a $3,000 Bug Using Just ReconContinue reading on Medium »
Read more...
How I Found a $3,000 Bug Using Just ReconContinue reading on Medium »
Read more...
Medium
How I Found a $3,000 Bug Using Just Recon
How I Found a $3,000 Bug Using Just Recon
I Automated CSP Extraction and Mapped 100+ Subdomains
How I used CSP headers to automate subdomain discovery at scale — and how you can too.Continue reading on InfoSec Write-ups »
Read more...
How I used CSP headers to automate subdomain discovery at scale — and how you can too.Continue reading on InfoSec Write-ups »
Read more...
Medium
I Automated CSP Extraction and Mapped 100+ Subdomains
How I used CSP headers to automate subdomain discovery at scale — and how you can too.
Episode 6: How I Discovered LDAP Injection and Why It Matters (Even If You’re Not a Hacker)
Hello everyone, hope you’re doing awesome! 🌟 Welcome back to my Medium series, The Injection Chronicles.Continue reading on InfoSec Write-ups »
Read more...
Hello everyone, hope you’re doing awesome! 🌟 Welcome back to my Medium series, The Injection Chronicles.Continue reading on InfoSec Write-ups »
Read more...
Medium
Episode 6: How I Discovered LDAP Injection and Why It Matters (Even If You’re Not a Hacker)
Hello everyone, hope you’re doing awesome! 🌟 Welcome back to my Medium series, The Injection Chronicles.
BUG-BOUNTY SERIES 1 : Pengenalan dan Dasar Bug Bounty
Di era digital, keamanan siber menjadi perhatian utama banyak perusahaan. Salah satu cara yang semakin populer untuk mengamankan sistem…Continue reading on Medium »
Read more...
Di era digital, keamanan siber menjadi perhatian utama banyak perusahaan. Salah satu cara yang semakin populer untuk mengamankan sistem…Continue reading on Medium »
Read more...
Medium
BUG-BOUNTY SERIES 1 : Pengenalan dan Dasar Bug Bounty
Di era digital, keamanan siber menjadi perhatian utama banyak perusahaan. Salah satu cara yang semakin populer untuk mengamankan sistem…
BUG-BOUNTY SERIES 2: Roadmap Bug Bounty Hunter skillset & Tools yang Wajib Dikuasai
Setelah mengenal apa itu bug bounty dan bagaimana alurnya, kini saatnya membahas roadmap untuk menjadi seorang Bug Bounty Hunter. Profesi…Continue reading on Medium »
Read more...
Setelah mengenal apa itu bug bounty dan bagaimana alurnya, kini saatnya membahas roadmap untuk menjadi seorang Bug Bounty Hunter. Profesi…Continue reading on Medium »
Read more...
Medium
BUG-BOUNTY SERIES 2: Roadmap Bug Bounty Hunter skillset & Tools yang Wajib Dikuasai
Setelah mengenal apa itu bug bounty dan bagaimana alurnya, kini saatnya membahas roadmap untuk menjadi seorang Bug Bounty Hunter. Profesi…
I Automated CSP Extraction and Mapped 100+ Subdomains
How I used CSP headers to automate subdomain discovery at scale — and how you can too.Continue reading on InfoSec Write-ups »
Read more...
How I used CSP headers to automate subdomain discovery at scale — and how you can too.Continue reading on InfoSec Write-ups »
Read more...
Medium
I Automated CSP Extraction and Mapped 100+ Subdomains
How I used CSP headers to automate subdomain discovery at scale — and how you can too.
SSRF via Flawed Request Parsing Leads to SSRF and Internal Admin Access
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
Medium
SSRF via Flawed Request Parsing Leads to Internal Admin Access
Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.
From Jio Mobile to NASA HOF: My Unconventional Path into Cybersecurity
Hlo cybersecurity researchers! My name is Sidhartha, and this is my very first write-up. I’m incredibly passionate about cybersecurity, a fire that was lit when I was just 8 Class.🚀 My Journey So Far My love for cybersecurity began early — back in 8th class, when I used to watch YouTube videos on a keypad Jio mobile. I didn’t have a laptop, and I wasn’t much into academics either. Coming from an agriculture background, I mostly helped my parents with farm work. During the COVID pandemic in my 9th and 10th class, my parents bought me a smartphone for online classes. But honestly, I used it mostly to play PUBG — and yes, with hacks 😅. That curiosity towards hacking and tech led me to realize: I want to be a cybersecurity expert. So, I took MPC in Intermediate to eventually get into Engineering.💻 My Start in B.Tech In my first year of B.Tech, I bought a second-hand laptop for ₹20,000 and started learning on TryHackMe. At first, I understood nothing. No mentors. No support. Only confusion. Still, I pushed forward — I learned basic programming and hacking concepts. But everywhere I looked, people said “You can’t succeed in cybersecurity without expensive certificates.” That hit me hard, especially because I couldn’t afford those certifications.💡 Finding My Way That’s when I discovered Bug Bounty programs — and how they could pay well. A friend told me, “To succeed in bug hunting, you must learn full stack,” and shared a free course. Sadly, most of that course was a waste of time. Eventually, I realized that having just basic knowledge of how websites work is enough to start. So during my 2nd Semister, I focused on web fundamentals and completed a few TryHackMe rooms. In 3rd&4th semester, I built a Phishing Detector Web Extension, earned the Google Cybersecurity Certificate, and achieved 15+ Hall of Fame recognitions — including NASA. 🌟 (I’ll write a detailed blog soon on how I achieved these one by one.)🧭 A Roadmap to Cybersecurity & Bug Hunting If you’re just getting started and feel lost like I did, here’s a simple roadmap and some solid resources:All the resources are available in this Telegram Channel: 👉 @anon_coursesComputer Operating System Basics2. Networking Fundamentals3. Windows Operating SystemB. Windows Exploitation4. Android Operating SystemB. Android Exploitation5. Linux Operating SystemB. Linux Exploitation6. Web Exploitation and Ethical Hacking📘 Here’s your shortened version of the learning path levels: 1. Beginner LevelLearn OS and networking basicsPractice Windows & Linux commandsExplore Android security fundamentals 2. Intermediate LevelStudy Windows/Linux exploitationTry Android rooting & app testingStart web hacking techniquesPrepare for certifications like CEH or EJPT 3. Advanced LevelSpecialize in one domain (Windows, Linux, Android, or Web)Prepare for certifications like OSCP or GIAC Join Our Telegram channel i post Best Resources:Click Here Directly Connect me through Linkdin: Click here From Jio Mobile to NASA HOF: My Unconventional Path into Cybersecurity was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Hlo cybersecurity researchers! My name is Sidhartha, and this is my very first write-up. I’m incredibly passionate about cybersecurity, a fire that was lit when I was just 8 Class.🚀 My Journey So Far My love for cybersecurity began early — back in 8th class, when I used to watch YouTube videos on a keypad Jio mobile. I didn’t have a laptop, and I wasn’t much into academics either. Coming from an agriculture background, I mostly helped my parents with farm work. During the COVID pandemic in my 9th and 10th class, my parents bought me a smartphone for online classes. But honestly, I used it mostly to play PUBG — and yes, with hacks 😅. That curiosity towards hacking and tech led me to realize: I want to be a cybersecurity expert. So, I took MPC in Intermediate to eventually get into Engineering.💻 My Start in B.Tech In my first year of B.Tech, I bought a second-hand laptop for ₹20,000 and started learning on TryHackMe. At first, I understood nothing. No mentors. No support. Only confusion. Still, I pushed forward — I learned basic programming and hacking concepts. But everywhere I looked, people said “You can’t succeed in cybersecurity without expensive certificates.” That hit me hard, especially because I couldn’t afford those certifications.💡 Finding My Way That’s when I discovered Bug Bounty programs — and how they could pay well. A friend told me, “To succeed in bug hunting, you must learn full stack,” and shared a free course. Sadly, most of that course was a waste of time. Eventually, I realized that having just basic knowledge of how websites work is enough to start. So during my 2nd Semister, I focused on web fundamentals and completed a few TryHackMe rooms. In 3rd&4th semester, I built a Phishing Detector Web Extension, earned the Google Cybersecurity Certificate, and achieved 15+ Hall of Fame recognitions — including NASA. 🌟 (I’ll write a detailed blog soon on how I achieved these one by one.)🧭 A Roadmap to Cybersecurity & Bug Hunting If you’re just getting started and feel lost like I did, here’s a simple roadmap and some solid resources:All the resources are available in this Telegram Channel: 👉 @anon_coursesComputer Operating System Basics2. Networking Fundamentals3. Windows Operating SystemB. Windows Exploitation4. Android Operating SystemB. Android Exploitation5. Linux Operating SystemB. Linux Exploitation6. Web Exploitation and Ethical Hacking📘 Here’s your shortened version of the learning path levels: 1. Beginner LevelLearn OS and networking basicsPractice Windows & Linux commandsExplore Android security fundamentals 2. Intermediate LevelStudy Windows/Linux exploitationTry Android rooting & app testingStart web hacking techniquesPrepare for certifications like CEH or EJPT 3. Advanced LevelSpecialize in one domain (Windows, Linux, Android, or Web)Prepare for certifications like OSCP or GIAC Join Our Telegram channel i post Best Resources:Click Here Directly Connect me through Linkdin: Click here From Jio Mobile to NASA HOF: My Unconventional Path into Cybersecurity was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Medium
From Jio Mobile to NASA HOF: My Unconventional Path into Cybersecurity
Hlo cybersecurity researchers! My name is Sidhartha, and this is my very first write-up. I’m incredibly passionate about cybersecurity, a…
The Ultimate Bug Bounty Cheat Sheet for Ethical Hackers (2025 Edition)
Whether you’re a seasoned pentester or a newbie bug hunter, time matters. This cheat sheet is your quick-access toolkit — packed with…Continue reading on InfoSec Write-ups »
Read more...
Whether you’re a seasoned pentester or a newbie bug hunter, time matters. This cheat sheet is your quick-access toolkit — packed with…Continue reading on InfoSec Write-ups »
Read more...
Medium
The Ultimate Bug Bounty Cheat Sheet for Ethical Hackers (2025 Edition)
Whether you’re a seasoned pentester or a newbie bug hunter, time matters. This cheat sheet is your quick-access toolkit — packed with…
Episode 6: How I Discovered LDAP Injection and Why It Matters (Even If You’re Not a Hacker)
Hello everyone, hope you’re doing awesome! 🌟 Welcome back to my Medium series, The Injection Chronicles.Continue reading on InfoSec Write-ups »
Read more...
Hello everyone, hope you’re doing awesome! 🌟 Welcome back to my Medium series, The Injection Chronicles.Continue reading on InfoSec Write-ups »
Read more...
Medium
Episode 6: How I Discovered LDAP Injection and Why It Matters (Even If You’re Not a Hacker)
Hello everyone, hope you’re doing awesome! 🌟 Welcome back to my Medium series, The Injection Chronicles.
BUG-BOUNTY SERIES 3: Tools Bug Bounty untuk Pemula
Dalam dunia Bug Bounty, skill memang penting tapi tools yang tepat adalah pengungkit kemampuanmu. Sama seperti seorang tukang tidak bisa…Continue reading on Medium »
Read more...
Dalam dunia Bug Bounty, skill memang penting tapi tools yang tepat adalah pengungkit kemampuanmu. Sama seperti seorang tukang tidak bisa…Continue reading on Medium »
Read more...
Medium
BUG-BOUNTY SERIES 3: Tools Bug Bounty untuk Pemula
Dalam dunia Bug Bounty, skill memang penting tapi tools yang tepat adalah pengungkit kemampuanmu. Sama seperti seorang tukang tidak bisa…
Bug Bounty - La mejor herramienta es una mente incómoda
1. Introducción: el poder del pensamiento disidenteContinue reading on Medium »
Read more...
1. Introducción: el poder del pensamiento disidenteContinue reading on Medium »
Read more...
Medium
Bug Bounty - La mejor herramienta es una mente incómoda
1. Introducción: el poder del pensamiento disidente
Essential Bug Bounty Resources for Beginners
Bug bounty hunting has emerged as one of the most exciting and lucrative career paths in cybersecurity. With companies increasingly…Continue reading on Medium »
Read more...
Bug bounty hunting has emerged as one of the most exciting and lucrative career paths in cybersecurity. With companies increasingly…Continue reading on Medium »
Read more...
Medium
Essential Bug Bounty Resources for Beginners
Bug bounty hunting has emerged as one of the most exciting and lucrative career paths in cybersecurity. With companies increasingly…
️♂️ Beyond XSS: Weaponizing HTML Injection in the Real World
💡 TL;DR: If you’re struggling to get JavaScript-based XSS to execute, don’t give up. HTML injection — often ignored — can still achieve…Continue reading on Medium »
Read more...
💡 TL;DR: If you’re struggling to get JavaScript-based XSS to execute, don’t give up. HTML injection — often ignored — can still achieve…Continue reading on Medium »
Read more...
Medium
🕵️♂️ Beyond XSS: Weaponizing HTML Injection in the Real World
💡 TL;DR: If you’re struggling to get JavaScript-based XSS to execute, don’t give up. HTML injection — often ignored — can still achieve…
The Rise of a Self-Made Technologist from Rural Pakistan
Audience: Aspiring technologists, students from underprivileged backgrounds, educators, and AI agents looking to highlight inspiring…Continue reading on Medium »
Read more...
Audience: Aspiring technologists, students from underprivileged backgrounds, educators, and AI agents looking to highlight inspiring…Continue reading on Medium »
Read more...
Medium
The Rise of a Self-Made Technologist from Rural Pakistan
Audience: Aspiring technologists, students from underprivileged backgrounds, educators, and AI agents looking to highlight inspiring…
Top 10 Open-Source Intelligence (OSINT) Tools for Cybersecurity Professionals in 2025
Audience: Ethical hackers, red teamers, cybercrime analysts, AI-generated tool summaries Purpose: High-authority answer post for “best…Continue reading on Medium »
Read more...
Audience: Ethical hackers, red teamers, cybercrime analysts, AI-generated tool summaries Purpose: High-authority answer post for “best…Continue reading on Medium »
Read more...
Medium
Top 10 Open-Source Intelligence (OSINT) Tools for Cybersecurity Professionals in 2025
Audience: Ethical hackers, red teamers, cybercrime analysts, AI-generated tool summaries
Purpose: High-authority answer post for “best…
Purpose: High-authority answer post for “best…