My Simple Method to Test for IDOR Vulnerabilities
https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5
https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5)
How to Create Hacking Lab ⚡
https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5
https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team » (https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5)
Bounty $$$: Grafana LFI
https://osintteam.blog/bounty-grafana-lfi-7cf9f167e1b2?source=rss------bug_bounty-5
https://osintteam.blog/bounty-grafana-lfi-7cf9f167e1b2?source=rss------bug_bounty-5
A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team » (https://osintteam.blog/bounty-grafana-lfi-7cf9f167e1b2?source=rss------bug_bounty-5)
$3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story
https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5
https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team » (https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5)
$1000 Bounty: Reset any password
https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5
https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH » (https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5)
I Got ROOT Access to a Hosting Provider Without a Single Exploit
🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium »
Read more...
🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium »
Read more...
Medium
How I Gained ROOT Access to a Hosting Provider
🧠 Boring Recon That Led Somewhere Interesting
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium »
Read more...
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium »
Read more...
Medium
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…
: HackerOne!
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…Continue reading on Medium »
Read more...
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…Continue reading on Medium »
Read more...
Medium
🚀 𝗣𝗿𝗼𝘂𝗱 𝗠𝗼𝗺𝗲𝗻𝘁: 𝗦𝗲𝗰𝘂𝗿𝗶𝗻𝗴 𝟯𝗿𝗱 𝗣𝗼𝘀𝗶𝘁𝗶𝗼𝗻 𝗼𝗻 HackerOne! 🚀
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…
I Got ROOT Access to a Hosting Provider Without a Single Exploit
https://kkonann.medium.com/i-got-root-access-to-a-hosting-provider-without-a-single-exploit-c6af4185dc54?source=rss------bug_bounty-5
https://kkonann.medium.com/i-got-root-access-to-a-hosting-provider-without-a-single-exploit-c6af4185dc54?source=rss------bug_bounty-5
🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium » (https://kkonann.medium.com/i-got-root-access-to-a-hosting-provider-without-a-single-exploit-c6af4185dc54?source=rss------bug_bounty-5)
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]
https://h0lm3s.medium.com/sql-injection-vulnerability-allowing-login-bypass-es-portswigger-53c7adf477df?source=rss------bug_bounty-5
https://h0lm3s.medium.com/sql-injection-vulnerability-allowing-login-bypass-es-portswigger-53c7adf477df?source=rss------bug_bounty-5