🔐Free Article LinkContinue reading on Medium » (https://medium.com/@kumawatabhijeet2002/4-top-10-recon-tools-i-use-every-day-with-pro-tips-workflows-61665e79e65d?source=rss------bug_bounty-5)
Subdomain Scanner to HTTP Hunter:
https://medium.com/meetcyber/subdomain-scanner-to-http-hunter-e1b8abaf6fb3?source=rss------bug_bounty-5
https://medium.com/meetcyber/subdomain-scanner-to-http-hunter-e1b8abaf6fb3?source=rss------bug_bounty-5
How I Automated Burp Suite + Kali Linux to Hunt Web Assets Like a MachineContinue reading on MeetCyber » (https://medium.com/meetcyber/subdomain-scanner-to-http-hunter-e1b8abaf6fb3?source=rss------bug_bounty-5)
XSS Trap Card Series — Vol. 1
https://medium.com/@narendarlb123/xss-trap-card-series-vol-1-4a1fd177cc74?source=rss------bug_bounty-5
https://medium.com/@narendarlb123/xss-trap-card-series-vol-1-4a1fd177cc74?source=rss------bug_bounty-5
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ MitigationsContinue reading on Medium » (https://medium.com/@narendarlb123/xss-trap-card-series-vol-1-4a1fd177cc74?source=rss------bug_bounty-5)
How I Got on a US Government Hall of Fame in 5 Minutes.
https://medium.com/@devanshpatel930/how-i-got-on-a-us-government-hall-of-fame-in-5-minutes-280be3993f79?source=rss------bug_bounty-5
https://medium.com/@devanshpatel930/how-i-got-on-a-us-government-hall-of-fame-in-5-minutes-280be3993f79?source=rss------bug_bounty-5
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…Continue reading on Medium » (https://medium.com/@devanshpatel930/how-i-got-on-a-us-government-hall-of-fame-in-5-minutes-280be3993f79?source=rss------bug_bounty-5)
XSS Reborn: 5 Killer Scenarios That Break Assumptions & Apps .. Advanced XSS Vol. 2
https://medium.com/meetcyber/xss-reborn-5-killer-scenarios-that-break-assumptions-apps-advanced-xss-vol-2-f36eac655919?source=rss------bug_bounty-5
https://medium.com/meetcyber/xss-reborn-5-killer-scenarios-that-break-assumptions-apps-advanced-xss-vol-2-f36eac655919?source=rss------bug_bounty-5
“Where Dev Assumptions Meet Hacker Reality”Continue reading on MeetCyber » (https://medium.com/meetcyber/xss-reborn-5-killer-scenarios-that-break-assumptions-apps-advanced-xss-vol-2-f36eac655919?source=rss------bug_bounty-5)
XSS Trap Card Series — Vol. 1
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ MitigationsContinue reading on Medium »
Read more...
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ MitigationsContinue reading on Medium »
Read more...
Medium
🚨 XSS Trap Card Series — Vol. 1
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ Mitigations
How I Got on a US Government Hall of Fame in 5 Minutes.
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…Continue reading on Medium »
Read more...
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…Continue reading on Medium »
Read more...
Medium
How I Got on a US Government Hall of Fame in 5 Minutes.
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…
XSS Reborn: 5 Killer Scenarios That Break Assumptions & Apps .. Advanced XSS Vol. 2
“Where Dev Assumptions Meet Hacker Reality”Continue reading on MeetCyber »
Read more...
“Where Dev Assumptions Meet Hacker Reality”Continue reading on MeetCyber »
Read more...
Medium
XSS Reborn: 5 Killer Scenarios That Break Assumptions & Apps .. Advanced XSS Vol. 2
“Where Dev Assumptions Meet Hacker Reality”
Should I start in networking if my goal is pentesting?
https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/
<!-- SC_OFF -->I just graduated with a bachelor’s in cybersecurity and got a job offer from one of the largest ISPs in my country. It’s a well-established company with a strong technical environment, so there's a lot of potential for learning, especially in areas like networks, infrastructure and operations. The role is related to networking (network engineer track). I actually want to do networking first because I believe having a solid foundation will help me become a better pentester in the long run. But pentesting is still my main goal. Right now, I’d say I’m between beginner and intermediate in pentesting. I’ve done a lot on TryHackMe, currently learning through HTB Academy, and about to take Sec+ and eJPT. My main concern is: if I spend a year or two in networking, will it be harder to transition into pentesting later due to lack of hands-on offensive security experience? Or will the networking background actually give me an edge? Would love to hear from anyone who's been in a similar spot. Thanks! <!-- SC_ON --> submitted by /u/Professional-Land549 (https://www.reddit.com/user/Professional-Land549)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/)
https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/
<!-- SC_OFF -->I just graduated with a bachelor’s in cybersecurity and got a job offer from one of the largest ISPs in my country. It’s a well-established company with a strong technical environment, so there's a lot of potential for learning, especially in areas like networks, infrastructure and operations. The role is related to networking (network engineer track). I actually want to do networking first because I believe having a solid foundation will help me become a better pentester in the long run. But pentesting is still my main goal. Right now, I’d say I’m between beginner and intermediate in pentesting. I’ve done a lot on TryHackMe, currently learning through HTB Academy, and about to take Sec+ and eJPT. My main concern is: if I spend a year or two in networking, will it be harder to transition into pentesting later due to lack of hands-on offensive security experience? Or will the networking background actually give me an edge? Would love to hear from anyone who's been in a similar spot. Thanks! <!-- SC_ON --> submitted by /u/Professional-Land549 (https://www.reddit.com/user/Professional-Land549)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/)
I Turned IDOR and XSS Into a Mass Account Takeover
Ever missed a critical bug because you didn’t chain vulnerabilities?Continue reading on InfoSec Write-ups »
Read more...
Ever missed a critical bug because you didn’t chain vulnerabilities?Continue reading on InfoSec Write-ups »
Read more...
Medium
I Turned IDOR and XSS Into a Mass Account Takeover
Ever missed a critical bug because you didn’t chain vulnerabilities?
Forgotten by Design: How an Unused Subdomain Gave Me Full Cloud Access ☁️
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
💡 Forgotten by Design: How an Unused Subdomain Gave Me Full Cloud Access ☁️🔑
Hey there!😁
Extracting Data from the Subdomain Grave
The buried aren’t always silentContinue reading on InfoSec Write-ups »
Read more...
The buried aren’t always silentContinue reading on InfoSec Write-ups »
Read more...
Medium
Extracting Data from the Subdomain Grave
The buried aren’t always silent
Reflected XSS Made Easy: Catching Real Bugs in the Wild
How a Simple Payload Uncovered a Real Vulnerability on MTN’s WebsiteContinue reading on InfoSec Write-ups »
Read more...
How a Simple Payload Uncovered a Real Vulnerability on MTN’s WebsiteContinue reading on InfoSec Write-ups »
Read more...
Medium
Reflected XSS Made Easy: Catching Real Bugs in the Wild
How a Simple Payload Uncovered a Real Vulnerability on MTN’s Website