Bug Hunting Story: You Won’t Believe What I Found Hidden in a RetToken Parameter
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…Continue reading on InfoSec Write-ups »
Read more...
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…Continue reading on InfoSec Write-ups »
Read more...
Medium
Bug Hunting Story: You Won’t Believe What I Found Hidden in a RetToken Parameter
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…
Bug Hunting Story: You Won’t Believe What I Found Hidden in a RetToken Parameter
https://infosecwriteups.com/bug-hunting-story-you-wont-believe-what-i-found-hidden-in-a-rettoken-parameter-781b9ec7e3f5?source=rss------bug_bounty-5
https://infosecwriteups.com/bug-hunting-story-you-wont-believe-what-i-found-hidden-in-a-rettoken-parameter-781b9ec7e3f5?source=rss------bug_bounty-5
In cybersecurity, passive reconnaissance is often underestimated. Unlike active attacks, it doesn’t involve directly exploiting a system —…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/bug-hunting-story-you-wont-believe-what-i-found-hidden-in-a-rettoken-parameter-781b9ec7e3f5?source=rss------bug_bounty-5)
25 Hidden Google Dorks for 2025 Bug Bounty Hunters: Real Targets, Real Bounties
https://medium.com/@qaafqasim/25-hidden-google-dorks-for-2025-bug-bounty-hunters-real-targets-real-bounties-0bf8dd18d8bb?source=rss------bug_bounty-5
https://medium.com/@qaafqasim/25-hidden-google-dorks-for-2025-bug-bounty-hunters-real-targets-real-bounties-0bf8dd18d8bb?source=rss------bug_bounty-5
What if I told you that your next $500 bug bounty is just one search query away?Continue reading on Medium » (https://medium.com/@qaafqasim/25-hidden-google-dorks-for-2025-bug-bounty-hunters-real-targets-real-bounties-0bf8dd18d8bb?source=rss------bug_bounty-5)
25 Hidden Google Dorks for 2025 Bug Bounty Hunters: Real Targets, Real Bounties
What if I told you that your next $500 bug bounty is just one search query away?Continue reading on Medium »
Read more...
What if I told you that your next $500 bug bounty is just one search query away?Continue reading on Medium »
Read more...
Medium
🔍 25 Hidden Google Dorks for 2025 Bug Bounty Hunters: Real Targets, Real Bounties 💸💻
What if I told you that your next $500 bug bounty is just one search query away?
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and…
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…Continue reading on Medium »
Read more...
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…Continue reading on Medium »
Read more...
Medium
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and Backticks Unicode-Escaped
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…
Open Redirect on Logout Page — When Shopping Got Too Redirected
“I came to shop, not to teleport!” – Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium »
Read more...
“I came to shop, not to teleport!” – Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium »
Read more...
Medium
Open Redirect on Logout Page — When Shopping Got Too Redirected
“I came to shop, not to teleport!”
– Me, after discovering an Open Redirect bug on a shopping site’s logout page
– Me, after discovering an Open Redirect bug on a shopping site’s logout page
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium »
Read more...
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium »
Read more...
Medium
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.
How I Found a $4,750 Security Flaw by Accident
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium »
Read more...
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium »
Read more...
Medium
How I Found a $4,750 Security Flaw by Accident
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium »
Read more...
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium »
Read more...
Medium
Microsoft Raises Zero Day Quest Prize Pool to $5 Million to Tackle AI and Cloud Vulnerabilities
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…
Anyone here done HIPAA-compliant pentesting? What are your go-to tools and challenges?
https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/
<!-- SC_OFF -->Hey folks, I’m working on a project involving HIPAA-compliant penetration testing for a healthcare provider, and I’m curious to learn from others who’ve been through it. What tools or platforms have you found effective for HIPAA-focused environments? Do you usually go with manual or automated approaches (or a mix)? How do you typically handle things like risk reporting, PHI data handling, and compliance documentation? Also, how often do you recommend running tests for continuous compliance (beyond the once-a-year minimum)? Would love to hear your experiences, best practices, or even war stories from the field. Thanks in advance! <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/)
https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/
<!-- SC_OFF -->Hey folks, I’m working on a project involving HIPAA-compliant penetration testing for a healthcare provider, and I’m curious to learn from others who’ve been through it. What tools or platforms have you found effective for HIPAA-focused environments? Do you usually go with manual or automated approaches (or a mix)? How do you typically handle things like risk reporting, PHI data handling, and compliance documentation? Also, how often do you recommend running tests for continuous compliance (beyond the once-a-year minimum)? Would love to hear your experiences, best practices, or even war stories from the field. Thanks in advance! <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mi57df/anyone_here_done_hipaacompliant_pentesting_what/)
Reflected XSS Into a Template Literal With Angle Brackets, Single, Double Quotes, Backslash and…
https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5
https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5
Discover how attackers bypass Unicode-escaped quotes, angle brackets, and backticks inside JavaScript template literals to exploit…Continue reading on Medium » (https://bashoverflow.medium.com/reflected-xss-into-a-template-literal-with-angle-brackets-single-double-quotes-backslash-and-695c75db1c54?source=rss------bug_bounty-5)
Open Redirect on Logout Page — When Shopping Got Too Redirected
https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5
https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5
“I came to shop, not to teleport!”
– Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium » (https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5)
– Me, after discovering an Open Redirect bug on a shopping site’s logout pageContinue reading on Medium » (https://medium.com/@aryamevada2853/open-redirect-on-logout-page-when-shopping-got-too-redirected-31549480a630?source=rss------bug_bounty-5)
I Found a Major Privacy Leak in a Popular Social App Just Because a Friend Said “Check This Out”
https://kkonann.medium.com/i-found-a-major-privacy-leak-in-a-popular-social-app-just-because-a-friend-said-check-this-out-cd7edd798e32?source=rss------bug_bounty-5
https://kkonann.medium.com/i-found-a-major-privacy-leak-in-a-popular-social-app-just-because-a-friend-said-check-this-out-cd7edd798e32?source=rss------bug_bounty-5