FileJacking – Initial Access with File System API
https://www.reddit.com/r/redteamsec/comments/1mhe8y7/filejacking_initial_access_with_file_system_api/
submitted by /u/Print3M (https://www.reddit.com/user/Print3M)
[link] (https://print3m.github.io/blog/filejacking-initial-access-with-file-system-api) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhe8y7/filejacking_initial_access_with_file_system_api/)
https://www.reddit.com/r/redteamsec/comments/1mhe8y7/filejacking_initial_access_with_file_system_api/
submitted by /u/Print3M (https://www.reddit.com/user/Print3M)
[link] (https://print3m.github.io/blog/filejacking-initial-access-with-file-system-api) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhe8y7/filejacking_initial_access_with_file_system_api/)
Finding vulnerabilities in Claude code
https://www.reddit.com/r/redteamsec/comments/1mhizx3/finding_vulnerabilities_in_claude_code/
submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/cve-2025-547954-54795-claude-inverseprompt/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhizx3/finding_vulnerabilities_in_claude_code/)
https://www.reddit.com/r/redteamsec/comments/1mhizx3/finding_vulnerabilities_in_claude_code/
submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/cve-2025-547954-54795-claude-inverseprompt/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhizx3/finding_vulnerabilities_in_claude_code/)
DNS proxy for C2 communications
https://www.reddit.com/r/redteamsec/comments/1mhjgqf/dns_proxy_for_c2_communications/
<!-- SC_OFF -->Hello there, I write a medium tutorial about How to setup DNS proxy for C2 commuications and a example with Myhic <!-- SC_ON --> submitted by /u/umbraXsecure (https://www.reddit.com/user/umbraXsecure)
[link] (https://medium.com/@umbraxsecure/dns-proxy-for-c2-servers-c1a3f2cf4944) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhjgqf/dns_proxy_for_c2_communications/)
https://www.reddit.com/r/redteamsec/comments/1mhjgqf/dns_proxy_for_c2_communications/
<!-- SC_OFF -->Hello there, I write a medium tutorial about How to setup DNS proxy for C2 commuications and a example with Myhic <!-- SC_ON --> submitted by /u/umbraXsecure (https://www.reddit.com/user/umbraXsecure)
[link] (https://medium.com/@umbraxsecure/dns-proxy-for-c2-servers-c1a3f2cf4944) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhjgqf/dns_proxy_for_c2_communications/)
I Found 50+ XSS Flaws Using Just My Browser
https://medium.com/@ibtissamhammadi1/i-found-50-xss-flaws-using-just-my-browser-a00caba76c48?source=rss------bug_bounty-5
https://medium.com/@ibtissamhammadi1/i-found-50-xss-flaws-using-just-my-browser-a00caba76c48?source=rss------bug_bounty-5
How a Simple Chrome Trick Turned Into a $5,000 Bug BountyContinue reading on Medium » (https://medium.com/@ibtissamhammadi1/i-found-50-xss-flaws-using-just-my-browser-a00caba76c48?source=rss------bug_bounty-5)
Bypassing Authentication and Triggering XSS via Simple URL Manipulation
https://medium.com/@aloneinjector1/bypassing-authentication-and-triggering-xss-via-simple-url-manipulation-a3d56c66b136?source=rss------bug_bounty-5
In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…Continue reading on Medium » (https://medium.com/@aloneinjector1/bypassing-authentication-and-triggering-xss-via-simple-url-manipulation-a3d56c66b136?source=rss------bug_bounty-5)
https://medium.com/@aloneinjector1/bypassing-authentication-and-triggering-xss-via-simple-url-manipulation-a3d56c66b136?source=rss------bug_bounty-5
In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…Continue reading on Medium » (https://medium.com/@aloneinjector1/bypassing-authentication-and-triggering-xss-via-simple-url-manipulation-a3d56c66b136?source=rss------bug_bounty-5)
Bypassing Authentication and Triggering XSS via Simple URL Manipulation
In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…Continue reading on Medium »
Read more...
In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…Continue reading on Medium »
Read more...
Medium
🔓 Bypassing Authentication and Triggering XSS via Simple URL Manipulation
In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…
The 2025 GitHub Recon Checklist for Bug Bounty Hunters
GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…Continue reading on Medium »
Read more...
GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…Continue reading on Medium »
Read more...
Medium
The 2025 GitHub Recon Checklist for Bug Bounty Hunters
GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…
The 2025 GitHub Recon Checklist for Bug Bounty Hunters
https://medium.com/@tillson.galloway/the-2025-github-recon-checklist-for-bug-bounty-hunters-e626ee1a1012?source=rss------bug_bounty-5
GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…Continue reading on Medium » (https://medium.com/@tillson.galloway/the-2025-github-recon-checklist-for-bug-bounty-hunters-e626ee1a1012?source=rss------bug_bounty-5)
https://medium.com/@tillson.galloway/the-2025-github-recon-checklist-for-bug-bounty-hunters-e626ee1a1012?source=rss------bug_bounty-5
GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…Continue reading on Medium » (https://medium.com/@tillson.galloway/the-2025-github-recon-checklist-for-bug-bounty-hunters-e626ee1a1012?source=rss------bug_bounty-5)
Need help with a virtual machine
https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/
<!-- SC_OFF -->Hello, For the past few months, I have been learning about offensive cybersecurity. So I created a Linux virtual machine on VirtualBox (Kali). The problem is that it has very poor performance. However, it has 14GB of RAM, 220MB of video memory, 8 processor core, plenty of disk space, and I even enabled 3D acceleration. I'm using a fairly recent ThinkPad with 32 GB of RAM. But my virtual machine is still slow and has poor visual performance. So I'd like to know if there's a hidden option or something that needs to be changed in its configuration. (I have version 7.1.8 of VirtualBox.) <!-- SC_ON --> submitted by /u/Annual-Stress2264 (https://www.reddit.com/user/Annual-Stress2264)
[link] (https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/)
https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/
<!-- SC_OFF -->Hello, For the past few months, I have been learning about offensive cybersecurity. So I created a Linux virtual machine on VirtualBox (Kali). The problem is that it has very poor performance. However, it has 14GB of RAM, 220MB of video memory, 8 processor core, plenty of disk space, and I even enabled 3D acceleration. I'm using a fairly recent ThinkPad with 32 GB of RAM. But my virtual machine is still slow and has poor visual performance. So I'd like to know if there's a hidden option or something that needs to be changed in its configuration. (I have version 7.1.8 of VirtualBox.) <!-- SC_ON --> submitted by /u/Annual-Stress2264 (https://www.reddit.com/user/Annual-Stress2264)
[link] (https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/)
Is a degree required for pentest role?
https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/
<!-- SC_OFF -->Hi,Im still beginner in ethical hacking world(2 months in) and had seen a lot of experience one before me doing amazing things in penetration testing and it makes me wonder since its a technical role,is a degree needed for this role to even be seen let alone landing a business position?Im looking foward for any opinion regarding this “controversial” topic.Thanks! <!-- SC_ON --> submitted by /u/Emotional-Aside8923 (https://www.reddit.com/user/Emotional-Aside8923)
[link] (https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/)
https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/
<!-- SC_OFF -->Hi,Im still beginner in ethical hacking world(2 months in) and had seen a lot of experience one before me doing amazing things in penetration testing and it makes me wonder since its a technical role,is a degree needed for this role to even be seen let alone landing a business position?Im looking foward for any opinion regarding this “controversial” topic.Thanks! <!-- SC_ON --> submitted by /u/Emotional-Aside8923 (https://www.reddit.com/user/Emotional-Aside8923)
[link] (https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/)
Will a WiFi adapter support monitor mode and packet injection in kali linux ?
https://www.reddit.com/r/Pentesting/comments/1mhee77/will_a_wifi_adapter_support_monitor_mode_and/
https://www.reddit.com/r/Pentesting/comments/1mhee77/will_a_wifi_adapter_support_monitor_mode_and/
<!-- SC_OFF -->Will this wifi module support monitor mode and packet ejection? It has ralink RT5370 chipset ? I have found this in a electronic shop and I bought it. Will it worth it or just a failed purchase? <!-- SC_ON --> submitted by /u/thepardaox (https://www.reddit.com/user/thepardaox)
[link] (https://www.reddit.com/gallery/1mhee77) [comments] (https://www.reddit.com/r/Pentesting/comments/1mhee77/will_a_wifi_adapter_support_monitor_mode_and/)
[link] (https://www.reddit.com/gallery/1mhee77) [comments] (https://www.reddit.com/r/Pentesting/comments/1mhee77/will_a_wifi_adapter_support_monitor_mode_and/)
IDS Nedir ve Çeşitlerinde Bulunan Güvenlik Açıkları ?
IDS (Intrusion Detection System) yani Türkçe adı ile izinsiz giriş tespit sistemi/sistemleri , olası güvenlik ihlalleri ve yetkisiz erişim…Continue reading on Medium »
Read more...
IDS (Intrusion Detection System) yani Türkçe adı ile izinsiz giriş tespit sistemi/sistemleri , olası güvenlik ihlalleri ve yetkisiz erişim…Continue reading on Medium »
Read more...
Medium
IDS Nedir ve Çeşitlerinde Bulunan Güvenlik Açıkları ?
IDS (Intrusion Detection System) yani Türkçe adı ile izinsiz giriş tespit sistemi/sistemleri , olası güvenlik ihlalleri ve yetkisiz erişim…
How a Simple .git/config Check Earned Me $1000
🕵️♂️ “Oops, You Left Your .git Open!" – How I Stumbled Upon a $1000 Bounty by AccidentContinue reading on Medium »
Read more...
🕵️♂️ “Oops, You Left Your .git Open!" – How I Stumbled Upon a $1000 Bounty by AccidentContinue reading on Medium »
Read more...
Medium
How a Simple .git/config Check Earned Me $1000
🕵️♂️ “Oops, You Left Your .git Open!" – How I Stumbled Upon a $1000 Bounty by Accident
Security Logging and Monitoring Failures (OWASP A09): Guía Completa de Hacking, Bug Bounty
Descubre cómo la falta de logs y alertas facilita ataques, permite el borrado de huellas y oculta movimientos laterales.Continue reading on Medium »
Read more...
Descubre cómo la falta de logs y alertas facilita ataques, permite el borrado de huellas y oculta movimientos laterales.Continue reading on Medium »
Read more...
Medium
Security Logging and Monitoring Failures (OWASP A09): Guía Completa de Hacking y Bug Bounty
Descubre cómo la falta de logs y alertas facilita ataques, permite el borrado de huellas y oculta movimientos laterales.
IDS Nedir ve Çeşitlerinde Bulunan Güvenlik Açıkları ?
https://medium.com/@eren.klai2/ids-nedir-ve-%C3%A7e%C5%9Fitlerinde-bulunan-g%C3%BCvenlik-a%C3%A7%C4%B1klar%C4%B1-6d5fbf4492b1?source=rss------bug_bounty-5
https://medium.com/@eren.klai2/ids-nedir-ve-%C3%A7e%C5%9Fitlerinde-bulunan-g%C3%BCvenlik-a%C3%A7%C4%B1klar%C4%B1-6d5fbf4492b1?source=rss------bug_bounty-5
IDS (Intrusion Detection System) yani Türkçe adı ile izinsiz giriş tespit sistemi/sistemleri , olası güvenlik ihlalleri ve yetkisiz erişim…Continue reading on Medium » (https://medium.com/@eren.klai2/ids-nedir-ve-%C3%A7e%C5%9Fitlerinde-bulunan-g%C3%BCvenlik-a%C3%A7%C4%B1klar%C4%B1-6d5fbf4492b1?source=rss------bug_bounty-5)
How a Simple .git/config Check Earned Me $1000
https://medium.com/@syedshorox27/how-a-simple-git-config-check-earned-me-1000-23699662a134?source=rss------bug_bounty-5
https://medium.com/@syedshorox27/how-a-simple-git-config-check-earned-me-1000-23699662a134?source=rss------bug_bounty-5