When I first started digging into bug bounty and cybersecurity, I kept hearing this one piece of advice over and over:Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/day2-recon-scope-discovery-finding-every-domain-ip-with-whois-reverse-whois-ip-lookups-b69238aa5fe2?source=rss------bug_bounty-5)
Filtering out Noise on Burp suite like a Pro
https://normalitee.medium.com/filtering-out-noise-on-burp-suite-like-a-pro-b3fa2423a34b?source=rss------bug_bounty-5
https://normalitee.medium.com/filtering-out-noise-on-burp-suite-like-a-pro-b3fa2423a34b?source=rss------bug_bounty-5
Often times during Bug Bounty and Pentests we come across a website that sends 100s of Analytics request per second to some random website…Continue reading on Medium » (https://normalitee.medium.com/filtering-out-noise-on-burp-suite-like-a-pro-b3fa2423a34b?source=rss------bug_bounty-5)
Bug Hunting Story: You Won’t Believe What I Found Hidden in a RetToken Parameter
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…Continue reading on InfoSec Write-ups »
Read more...
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…Continue reading on InfoSec Write-ups »
Read more...
Medium
Bug Hunting Story: You Won’t Believe What I Found Hidden in a RetToken Parameter
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…
Bug Hunting Story: You Won’t Believe What I Found Hidden in a RetToken Parameter
https://infosecwriteups.com/bug-hunting-story-you-wont-believe-what-i-found-hidden-in-a-rettoken-parameter-781b9ec7e3f5?source=rss------bug_bounty-5
https://infosecwriteups.com/bug-hunting-story-you-wont-believe-what-i-found-hidden-in-a-rettoken-parameter-781b9ec7e3f5?source=rss------bug_bounty-5
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/bug-hunting-story-you-wont-believe-what-i-found-hidden-in-a-rettoken-parameter-781b9ec7e3f5?source=rss------bug_bounty-5)
25 Hidden Google Dorks for 2025 Bug Bounty Hunters: Real Targets, Real Bounties
https://medium.com/@qaafqasim/25-hidden-google-dorks-for-2025-bug-bounty-hunters-real-targets-real-bounties-0bf8dd18d8bb?source=rss------bug_bounty-5
https://medium.com/@qaafqasim/25-hidden-google-dorks-for-2025-bug-bounty-hunters-real-targets-real-bounties-0bf8dd18d8bb?source=rss------bug_bounty-5
What if I told you that your next $500 bug bounty is just one search query away?Continue reading on Medium » (https://medium.com/@qaafqasim/25-hidden-google-dorks-for-2025-bug-bounty-hunters-real-targets-real-bounties-0bf8dd18d8bb?source=rss------bug_bounty-5)
25 Hidden Google Dorks for 2025 Bug Bounty Hunters: Real Targets, Real Bounties
What if I told you that your next $500 bug bounty is just one search query away?Continue reading on Medium »
Read more...
What if I told you that your next $500 bug bounty is just one search query away?Continue reading on Medium »
Read more...
Medium
🔍 25 Hidden Google Dorks for 2025 Bug Bounty Hunters: Real Targets, Real Bounties 💸💻
What if I told you that your next $500 bug bounty is just one search query away?
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and…
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…Continue reading on Medium »
Read more...
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…Continue reading on Medium »
Read more...
Medium
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and Backticks Unicode-Escaped
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…
Open Redirect on Logout Page — When Shopping Got Too Redirected
“I came to shop, not to teleport!” – Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium »
Read more...
“I came to shop, not to teleport!” – Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium »
Read more...
Medium
Open Redirect on Logout Page — When Shopping Got Too Redirected
“I came to shop, not to teleport!”
– Me, after discovering an Open Redirect bug on a shopping site’s logout page
– Me, after discovering an Open Redirect bug on a shopping site’s logout page
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium »
Read more...
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium »
Read more...
Medium
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.
How I Found a $4,750 Security Flaw by Accident
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium »
Read more...
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium »
Read more...
Medium
How I Found a $4,750 Security Flaw by Accident
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium »
Read more...
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium »
Read more...
Medium
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…
Anyone here done HIPAA-compliant pentesting? What are your go-to tools and challenges?
https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/
<!-- SC_OFF -->Hey folks, I’m working on a project involving HIPAA-compliant penetration testing for a healthcare provider, and I’m curious to learn from others who’ve been through it. What tools or platforms have you found effective for HIPAA-focused environments? Do you usually go with manual or automated approaches (or a mix)? How do you typically handle things like risk reporting, PHI data handling, and compliance documentation? Also, how often do you recommend running tests for continuous compliance (beyond the once-a-year minimum)? Would love to hear your experiences, best practices, or even war stories from the field. Thanks in advance! <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/)
https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/
<!-- SC_OFF -->Hey folks, I’m working on a project involving HIPAA-compliant penetration testing for a healthcare provider, and I’m curious to learn from others who’ve been through it. What tools or platforms have you found effective for HIPAA-focused environments? Do you usually go with manual or automated approaches (or a mix)? How do you typically handle things like risk reporting, PHI data handling, and compliance documentation? Also, how often do you recommend running tests for continuous compliance (beyond the once-a-year minimum)? Would love to hear your experiences, best practices, or even war stories from the field. Thanks in advance! <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/)
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and…
https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5
https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5