When an Android App Whispers Secrets: How I Found Plaintext Credentials in Logcat
“The real magic in security doesn’t always lie in breaking into systems. Sometimes, it’s in seeing what was never meant to be seen.” —…Continue reading on Medium »
Read more...
“The real magic in security doesn’t always lie in breaking into systems. Sometimes, it’s in seeing what was never meant to be seen.” —…Continue reading on Medium »
Read more...
Medium
🔓 When an Android App Whispers Secrets: How I Found Plaintext Credentials in Logcat
“The real magic in security doesn’t always lie in breaking into systems. Sometimes, it’s in seeing what was never meant to be seen.” —…
Beyond Human Eyes: How AI Uncovers Critical Security Vulnerabilities.
https://medium.com/@yahya.abouhashim/beyond-human-eyes-how-ai-uncovers-critical-security-vulnerabilities-cd7266bc05e5?source=rss------bug_bounty-5
https://medium.com/@yahya.abouhashim/beyond-human-eyes-how-ai-uncovers-critical-security-vulnerabilities-cd7266bc05e5?source=rss------bug_bounty-5
The Secret Behind “Big Sleep” and “Xbow”: AI’s Foray into Vulnerability DiscoveryContinue reading on Medium » (https://medium.com/@yahya.abouhashim/beyond-human-eyes-how-ai-uncovers-critical-security-vulnerabilities-cd7266bc05e5?source=rss------bug_bounty-5)
How Attackers Steal Data Using CORS Misconfigurations — Step-by-Step Breakdown!
https://medium.com/@zoningxtr/how-attackers-steal-data-using-cors-misconfigurations-step-by-step-breakdown-b483b5f10cc5?source=rss------bug_bounty-5
https://medium.com/@zoningxtr/how-attackers-steal-data-using-cors-misconfigurations-step-by-step-breakdown-b483b5f10cc5?source=rss------bug_bounty-5
By ZoningxtrContinue reading on Medium » (https://medium.com/@zoningxtr/how-attackers-steal-data-using-cors-misconfigurations-step-by-step-breakdown-b483b5f10cc5?source=rss------bug_bounty-5)
🛡️ Understanding HTTP Parameter Pollution (HPP)Continue reading on Medium » (https://mrsi13nt.medium.com/http-parameter-pollution-0af3dcd1f96c?source=rss------bug_bounty-5)
When an Android App Whispers Secrets: How I Found Plaintext Credentials in Logcat
https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5
“The real magic in security doesn’t always lie in breaking into systems.
Sometimes, it’s in seeing what was never meant to be seen.”
—…Continue reading on Medium » (https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5)
https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5
“The real magic in security doesn’t always lie in breaking into systems.
Sometimes, it’s in seeing what was never meant to be seen.”
—…Continue reading on Medium » (https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5)
My Simple Method to Test for IDOR Vulnerabilities
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium »
Read more...
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium »
Read more...
Medium
My Simple Method to Test for IDOR Vulnerabilities
I found a bug — but it was marked as duplicate. Here’s how I did it.
How to Create Hacking Lab ⚡
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team »
Read more...
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team »
Read more...
Medium
How to Create Hacking Lab 💻⚡
🚀 Introduction: Why You Need Your Own Hacking Lab
Bounty $$$: Grafana LFI
A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team »
Read more...
A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team »
Read more...
Medium
Bounty $$$: Grafana LFI
A simple plugin path traversal exposed sensitive server files on a public dashboard
$3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team »
Read more...
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team »
Read more...
Medium
🚀 $3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story 💸
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…
$1000 Bounty: Reset any password
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH »
Read more...
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH »
Read more...
Medium
$1000 Bounty: Reset any password
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bounty
My Simple Method to Test for IDOR Vulnerabilities
https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5
https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5)
How to Create Hacking Lab ⚡
https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5
https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5