How I Got on a US Government Hall of Fame in 5 Minutes.
https://medium.com/@devanshpatel930/how-i-got-on-a-us-government-hall-of-fame-in-5-minutes-280be3993f79?source=rss------bug_bounty-5
https://medium.com/@devanshpatel930/how-i-got-on-a-us-government-hall-of-fame-in-5-minutes-280be3993f79?source=rss------bug_bounty-5
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…Continue reading on Medium » (https://medium.com/@devanshpatel930/how-i-got-on-a-us-government-hall-of-fame-in-5-minutes-280be3993f79?source=rss------bug_bounty-5)
XSS Reborn: 5 Killer Scenarios That Break Assumptions & Apps .. Advanced XSS Vol. 2
https://medium.com/meetcyber/xss-reborn-5-killer-scenarios-that-break-assumptions-apps-advanced-xss-vol-2-f36eac655919?source=rss------bug_bounty-5
https://medium.com/meetcyber/xss-reborn-5-killer-scenarios-that-break-assumptions-apps-advanced-xss-vol-2-f36eac655919?source=rss------bug_bounty-5
“Where Dev Assumptions Meet Hacker Reality”Continue reading on MeetCyber » (https://medium.com/meetcyber/xss-reborn-5-killer-scenarios-that-break-assumptions-apps-advanced-xss-vol-2-f36eac655919?source=rss------bug_bounty-5)
XSS Trap Card Series — Vol. 1
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ MitigationsContinue reading on Medium »
Read more...
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ MitigationsContinue reading on Medium »
Read more...
Medium
🚨 XSS Trap Card Series — Vol. 1
🎯 Real Scenarios | 💣 Payload Crafting | 🧠 Mindset | 🛡️ Mitigations
How I Got on a US Government Hall of Fame in 5 Minutes.
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…Continue reading on Medium »
Read more...
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…Continue reading on Medium »
Read more...
Medium
How I Got on a US Government Hall of Fame in 5 Minutes.
You’d think a government domain would be locked up tighter than a bank vault. Instead, I found a public directory listing that screamed…
XSS Reborn: 5 Killer Scenarios That Break Assumptions & Apps .. Advanced XSS Vol. 2
“Where Dev Assumptions Meet Hacker Reality”Continue reading on MeetCyber »
Read more...
“Where Dev Assumptions Meet Hacker Reality”Continue reading on MeetCyber »
Read more...
Medium
XSS Reborn: 5 Killer Scenarios That Break Assumptions & Apps .. Advanced XSS Vol. 2
“Where Dev Assumptions Meet Hacker Reality”
Should I start in networking if my goal is pentesting?
https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/
<!-- SC_OFF -->I just graduated with a bachelor’s in cybersecurity and got a job offer from one of the largest ISPs in my country. It’s a well-established company with a strong technical environment, so there's a lot of potential for learning, especially in areas like networks, infrastructure and operations. The role is related to networking (network engineer track). I actually want to do networking first because I believe having a solid foundation will help me become a better pentester in the long run. But pentesting is still my main goal. Right now, I’d say I’m between beginner and intermediate in pentesting. I’ve done a lot on TryHackMe, currently learning through HTB Academy, and about to take Sec+ and eJPT. My main concern is: if I spend a year or two in networking, will it be harder to transition into pentesting later due to lack of hands-on offensive security experience? Or will the networking background actually give me an edge? Would love to hear from anyone who's been in a similar spot. Thanks! <!-- SC_ON --> submitted by /u/Professional-Land549 (https://www.reddit.com/user/Professional-Land549)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/)
https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/
<!-- SC_OFF -->I just graduated with a bachelor’s in cybersecurity and got a job offer from one of the largest ISPs in my country. It’s a well-established company with a strong technical environment, so there's a lot of potential for learning, especially in areas like networks, infrastructure and operations. The role is related to networking (network engineer track). I actually want to do networking first because I believe having a solid foundation will help me become a better pentester in the long run. But pentesting is still my main goal. Right now, I’d say I’m between beginner and intermediate in pentesting. I’ve done a lot on TryHackMe, currently learning through HTB Academy, and about to take Sec+ and eJPT. My main concern is: if I spend a year or two in networking, will it be harder to transition into pentesting later due to lack of hands-on offensive security experience? Or will the networking background actually give me an edge? Would love to hear from anyone who's been in a similar spot. Thanks! <!-- SC_ON --> submitted by /u/Professional-Land549 (https://www.reddit.com/user/Professional-Land549)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi0htj/should_i_start_in_networking_if_my_goal_is/)
I Turned IDOR and XSS Into a Mass Account Takeover
Ever missed a critical bug because you didn’t chain vulnerabilities?Continue reading on InfoSec Write-ups »
Read more...
Ever missed a critical bug because you didn’t chain vulnerabilities?Continue reading on InfoSec Write-ups »
Read more...
Medium
I Turned IDOR and XSS Into a Mass Account Takeover
Ever missed a critical bug because you didn’t chain vulnerabilities?
Forgotten by Design: How an Unused Subdomain Gave Me Full Cloud Access ☁️
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
💡 Forgotten by Design: How an Unused Subdomain Gave Me Full Cloud Access ☁️🔑
Hey there!😁
Extracting Data from the Subdomain Grave
The buried aren’t always silentContinue reading on InfoSec Write-ups »
Read more...
The buried aren’t always silentContinue reading on InfoSec Write-ups »
Read more...
Medium
Extracting Data from the Subdomain Grave
The buried aren’t always silent
Reflected XSS Made Easy: Catching Real Bugs in the Wild
How a Simple Payload Uncovered a Real Vulnerability on MTN’s WebsiteContinue reading on InfoSec Write-ups »
Read more...
How a Simple Payload Uncovered a Real Vulnerability on MTN’s WebsiteContinue reading on InfoSec Write-ups »
Read more...
Medium
Reflected XSS Made Easy: Catching Real Bugs in the Wild
How a Simple Payload Uncovered a Real Vulnerability on MTN’s Website
I Turned IDOR and XSS Into a Mass Account Takeover
Ever missed a critical bug because you didn’t chain vulnerabilities?Continue reading on InfoSec Write-ups »
Read more...
Ever missed a critical bug because you didn’t chain vulnerabilities?Continue reading on InfoSec Write-ups »
Read more...
Medium
I Turned IDOR and XSS Into a Mass Account Takeover
Ever missed a critical bug because you didn’t chain vulnerabilities?
Reflected XSS Made Easy: Catching Real Bugs in the Wild
How a Simple Payload Uncovered a Real Vulnerability on MTN’s WebsiteContinue reading on InfoSec Write-ups »
Read more...
How a Simple Payload Uncovered a Real Vulnerability on MTN’s WebsiteContinue reading on InfoSec Write-ups »
Read more...
Medium
Reflected XSS Made Easy: Catching Real Bugs in the Wild
How a Simple Payload Uncovered a Real Vulnerability on MTN’s Website
Burp Suite For Beginners: How I Learned the Proxy and Interceptor
Ever tried to peek behind the curtain of a website? Maybe you’re curious how apps talk to each other. Or you keep hearing about “Burp…Continue reading on InfoSec Write-ups »
Read more...
Ever tried to peek behind the curtain of a website? Maybe you’re curious how apps talk to each other. Or you keep hearing about “Burp…Continue reading on InfoSec Write-ups »
Read more...
Medium
Burp Suite For Beginners: How I Learned the Proxy and Interceptor
Ever tried to peek behind the curtain of a website? Maybe you’re curious how apps talk to each other. Or you keep hearing about “Burp…
Ticket to Trouble: How I Hijacked Support Tickets to See Everyone’s Complaints ️
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Ticket to Trouble: How I Hijacked Support Tickets to See Everyone’s Complaints 🎟️😈
Free Link 🎈
DAY 1 Recon: Manual Reconnaissance: How I Explore Targets Like a Hacker (But With Good Intentions)
Before the tools come out, I like to get my hands dirty — and here’s why that matters.Continue reading on InfoSec Write-ups »
Read more...
Before the tools come out, I like to get my hands dirty — and here’s why that matters.Continue reading on InfoSec Write-ups »
Read more...
Medium
DAY 1 Recon: Manual Reconnaissance: How I Explore Targets Like a Hacker (But With Good Intentions)
Before the tools come out, I like to get my hands dirty — and here’s why that matters.
Day2 Recon: Scope Discovery: Finding Every Domain & IP with WHOIS, reverse WHOIS, IP lookups…
When I first started digging into bug bounty and cybersecurity, I kept hearing this one piece of advice over and over:Continue reading on InfoSec Write-ups »
Read more...
When I first started digging into bug bounty and cybersecurity, I kept hearing this one piece of advice over and over:Continue reading on InfoSec Write-ups »
Read more...
Medium
Day2 Recon: Scope Discovery: Finding Every Domain & IP with WHOIS, reverse WHOIS, IP lookups, certificate parsing
When I first started digging into bug bounty and cybersecurity, I kept hearing this one piece of advice over and over:
Filtering out Noise on Burp suite like a Pro
Often times during Bug Bounty and Pentests we come across a website that sends 100s of Analytics request per second to some random website…Continue reading on Medium »
Read more...
Often times during Bug Bounty and Pentests we come across a website that sends 100s of Analytics request per second to some random website…Continue reading on Medium »
Read more...
Medium
Filtering out Noise on Burp suite like a Pro
Often times during Bug Bounty and Pentests we come across a website that sends 100s of Analytics request per second to some random website…