The Secret Behind “Big Sleep” and “Xbow”: AI’s Foray into Vulnerability DiscoveryContinue reading on Medium » (https://medium.com/@yahya.abouhashim/beyond-human-eyes-how-ai-uncovers-critical-security-vulnerabilities-cd7266bc05e5?source=rss------bug_bounty-5)
How Attackers Steal Data Using CORS Misconfigurations — Step-by-Step Breakdown!
https://medium.com/@zoningxtr/how-attackers-steal-data-using-cors-misconfigurations-step-by-step-breakdown-b483b5f10cc5?source=rss------bug_bounty-5
https://medium.com/@zoningxtr/how-attackers-steal-data-using-cors-misconfigurations-step-by-step-breakdown-b483b5f10cc5?source=rss------bug_bounty-5
By ZoningxtrContinue reading on Medium » (https://medium.com/@zoningxtr/how-attackers-steal-data-using-cors-misconfigurations-step-by-step-breakdown-b483b5f10cc5?source=rss------bug_bounty-5)
🛡️ Understanding HTTP Parameter Pollution (HPP)Continue reading on Medium » (https://mrsi13nt.medium.com/http-parameter-pollution-0af3dcd1f96c?source=rss------bug_bounty-5)
When an Android App Whispers Secrets: How I Found Plaintext Credentials in Logcat
https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5
“The real magic in security doesn’t always lie in breaking into systems.
Sometimes, it’s in seeing what was never meant to be seen.”
—…Continue reading on Medium » (https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5)
https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5
“The real magic in security doesn’t always lie in breaking into systems.
Sometimes, it’s in seeing what was never meant to be seen.”
—…Continue reading on Medium » (https://medium.com/@rutxploit/when-an-android-app-whispers-secrets-how-i-found-plaintext-credentials-in-logcat-e44abf0856e3?source=rss------bug_bounty-5)
My Simple Method to Test for IDOR Vulnerabilities
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium »
Read more...
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium »
Read more...
Medium
My Simple Method to Test for IDOR Vulnerabilities
I found a bug — but it was marked as duplicate. Here’s how I did it.
How to Create Hacking Lab ⚡
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team »
Read more...
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team »
Read more...
Medium
How to Create Hacking Lab 💻⚡
🚀 Introduction: Why You Need Your Own Hacking Lab
Bounty $$$: Grafana LFI
A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team »
Read more...
A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team »
Read more...
Medium
Bounty $$$: Grafana LFI
A simple plugin path traversal exposed sensitive server files on a public dashboard
$3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team »
Read more...
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team »
Read more...
Medium
🚀 $3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story 💸
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…
$1000 Bounty: Reset any password
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH »
Read more...
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH »
Read more...
Medium
$1000 Bounty: Reset any password
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bounty
My Simple Method to Test for IDOR Vulnerabilities
https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5
https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5)
How to Create Hacking Lab ⚡
https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5
https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team » (https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5)
Bounty $$$: Grafana LFI
https://osintteam.blog/bounty-grafana-lfi-7cf9f167e1b2?source=rss------bug_bounty-5
https://osintteam.blog/bounty-grafana-lfi-7cf9f167e1b2?source=rss------bug_bounty-5