$3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story
https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5
https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team » (https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5)
$1000 Bounty: Reset any password
https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5
https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH » (https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5)
I Got ROOT Access to a Hosting Provider Without a Single Exploit
🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium »
Read more...
🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium »
Read more...
Medium
How I Gained ROOT Access to a Hosting Provider
🧠 Boring Recon That Led Somewhere Interesting
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium »
Read more...
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium »
Read more...
Medium
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…
: HackerOne!
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…Continue reading on Medium »
Read more...
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…Continue reading on Medium »
Read more...
Medium
🚀 𝗣𝗿𝗼𝘂𝗱 𝗠𝗼𝗺𝗲𝗻𝘁: 𝗦𝗲𝗰𝘂𝗿𝗶𝗻𝗴 𝟯𝗿𝗱 𝗣𝗼𝘀𝗶𝘁𝗶𝗼𝗻 𝗼𝗻 HackerOne! 🚀
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…
I Got ROOT Access to a Hosting Provider Without a Single Exploit
https://kkonann.medium.com/i-got-root-access-to-a-hosting-provider-without-a-single-exploit-c6af4185dc54?source=rss------bug_bounty-5
https://kkonann.medium.com/i-got-root-access-to-a-hosting-provider-without-a-single-exploit-c6af4185dc54?source=rss------bug_bounty-5
🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium » (https://kkonann.medium.com/i-got-root-access-to-a-hosting-provider-without-a-single-exploit-c6af4185dc54?source=rss------bug_bounty-5)
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]
https://h0lm3s.medium.com/sql-injection-vulnerability-allowing-login-bypass-es-portswigger-53c7adf477df?source=rss------bug_bounty-5
https://h0lm3s.medium.com/sql-injection-vulnerability-allowing-login-bypass-es-portswigger-53c7adf477df?source=rss------bug_bounty-5
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium » (https://h0lm3s.medium.com/sql-injection-vulnerability-allowing-login-bypass-es-portswigger-53c7adf477df?source=rss------bug_bounty-5)
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…Continue reading on Medium » (https://medium.com/@umeryousuf26/hackerone-19b7aeaf7c6a?source=rss------bug_bounty-5)
Best Certifications in 2025 non beginner.
https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/
<!-- SC_OFF -->Throwing this out to the hive mind: after 4 years pentesting and playing red team full time (never bothered with certs, just dove straight into real exercises), I’m finally thinking of getting certified but not with a starter one since it overlaps my experience. What’s your “no nonsense” favorite cert for someone already living and breathing pentest/red team? OSCP, OSEP, CRTO, GPEN, CPTS, something else? I just want to improve my résumé <!-- SC_ON --> submitted by /u/wh1t3k4t (https://www.reddit.com/user/wh1t3k4t)
[link] (https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/)
https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/
<!-- SC_OFF -->Throwing this out to the hive mind: after 4 years pentesting and playing red team full time (never bothered with certs, just dove straight into real exercises), I’m finally thinking of getting certified but not with a starter one since it overlaps my experience. What’s your “no nonsense” favorite cert for someone already living and breathing pentest/red team? OSCP, OSEP, CRTO, GPEN, CPTS, something else? I just want to improve my résumé <!-- SC_ON --> submitted by /u/wh1t3k4t (https://www.reddit.com/user/wh1t3k4t)
[link] (https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/)
Fed up with pentesting methodology chaos? Built something to fix it.
https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/
<!-- SC_OFF -->Hello r/Pentesting (https://www.reddit.com/r/Pentesting) , Is anyone else tired of tracking methodologies across scattered notes, Excel sheets, and random text files? Ever find yourself thinking: Where did I put that command from last month? I remember that scenario... but what did I do last time? How do I clearly show this complex attack chain to my customer? Why is my methodology/documentation/life such a mess? Hmm what can I do at this point in my pentest mission? Did I have enough coverage? How can I share my findings or a whole "snapshot" of my current progress with my team? My friend and I developed a FOSS platform called Penflow to make our work easier as security engineers. Here's what we ended up with: Visual methodology organization Attack kill chain mapping with proper relationship tracking Built on Neo4j for the graph database magic AI powered chat and node suggestion UI that doesn't look like garbage from 2005 (we actually spent time on this) Looking for your feedback 🙏 GitHub: https://github.com/rb-x/penflow <!-- SC_ON --> submitted by /u/DoubleMirror1008 (https://www.reddit.com/user/DoubleMirror1008)
[link] (https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/)
https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/
<!-- SC_OFF -->Hello r/Pentesting (https://www.reddit.com/r/Pentesting) , Is anyone else tired of tracking methodologies across scattered notes, Excel sheets, and random text files? Ever find yourself thinking: Where did I put that command from last month? I remember that scenario... but what did I do last time? How do I clearly show this complex attack chain to my customer? Why is my methodology/documentation/life such a mess? Hmm what can I do at this point in my pentest mission? Did I have enough coverage? How can I share my findings or a whole "snapshot" of my current progress with my team? My friend and I developed a FOSS platform called Penflow to make our work easier as security engineers. Here's what we ended up with: Visual methodology organization Attack kill chain mapping with proper relationship tracking Built on Neo4j for the graph database magic AI powered chat and node suggestion UI that doesn't look like garbage from 2005 (we actually spent time on this) Looking for your feedback 🙏 GitHub: https://github.com/rb-x/penflow <!-- SC_ON --> submitted by /u/DoubleMirror1008 (https://www.reddit.com/user/DoubleMirror1008)
[link] (https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/)
“Bug Bounty ”Telerik Report Server Authentication Bypass — CVE-2024–4358 “POC”
Telerik Report Server Tool that helps to businesses to store, manage and share the reports in one Central placeContinue reading on Medium »
Read more...
Telerik Report Server Tool that helps to businesses to store, manage and share the reports in one Central placeContinue reading on Medium »
Read more...
Medium
“Bug Bounty ”Telerik Report Server Authentication Bypass — CVE-2024–4358 “POC”
Telerik Report Server Tool that helps to businesses to store, manage and share the reports in one Central place