Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
I'm one of those shitty pentesters that people complain about
https://www.reddit.com/r/Pentesting/comments/1mkkjpv/im_one_of_those_shitty_pentesters_that_people/

<!-- SC_OFF -->I don't think I deserve to be here. I started as a pentester doing external tests. Worked my way up to red team operator then to red team leader but I don't think I deserve to lead. Whenever I work with other people I find they're so much smarter than me. I have all the certs everyone wants but they're just certs, it doesn't mean I know squat. I can bypass Crowdstrike but it's usually when working with someone else. I've written my own tools but they were just a copy of other people's stuff with modifications I wanted. It's not coming from my brain. I get domain admin sometimes and fail miserably other times. I know someone will say imposter syndrome but I honestly don't think I'm good enough to be at this level. Here's an example. I was doing a red team where I was responsible for everything external: recon, external pentesting and social engineering. The attack surface spans literally hundreds of domains, thousands of IPs. So I'm working away, trying to figure out how to get in and completely miss a bend new vulnerability in an externally facing piece of software that could have gotten me creds. I get asked in the standup "So did you test X?" And I had weeks earlier, found nothing and moved on. "Well there goes your chance. We patched already." That mistake has literally haunted me. I set myself up a set of feeds on the latest threat Intel and check them every day now. But this is what I'm saying. I should have been doing that for years, not starting now! I'm a straight up shitty pentester. You're probably going to laugh but I'm thinking of moving into management because I think pretty much everyone is smarter than me and I'm not cut out for this. It's only a matter of time before I get found out as a fraud. Honestly I'm surprised it hasn't happened by now. Thanks for reading. I really just needed to get this off my chest. <!-- SC_ON --> submitted by /u/petapex (https://www.reddit.com/user/petapex)
[link] (https://www.reddit.com/r/Pentesting/comments/1mkkjpv/im_one_of_those_shitty_pentesters_that_people/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mkkjpv/im_one_of_those_shitty_pentesters_that_people/)
Exploiting XSS to Bypass CSRF Defenses: Change Victim’s Email

Learn how a stored XSS flaw can be weaponized to defeat CSRF defenses and perform unauthorized actions on behalf of users.Continue reading on InfoSec Write-ups »
Read more...
Learn how a stored XSS flaw can be weaponized to defeat CSRF defenses and perform unauthorized actions on behalf of users.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/exploiting-xss-to-bypass-csrf-defenses-change-victims-email-dcdcbfe1d5df?source=rss------bug_bounty-5)
How I Bypassed a Strict WAF Using SQL Injection Tricks

The Silent SQL Injection Cloudflare Almost Hid From MeContinue reading on InfoSec Write-ups »
Read more...
Bug Bounty Methodology for Finding Bugs Easily

Welcome, bug bounty hunters! 🕵️‍♂️ Whether you’re just starting out or looking to sharpen your methodology, this guide will help you…Continue reading on InfoSec Write-ups »
Read more...
Think Fast: How Auto-Complete Suggested Me Passwords That Weren’t Mine ᾒf

Hey there!😁Continue reading on Medium »
Read more...
“Day 5: SSRF — How I Hacked AWS Keys & Stole $15,000 in Cloud Credits”

Three months ago, I found a “low-severity” SSRF (Server-Side Request Forgery) in a SaaS company’s API. What started as a simple internal…Continue reading on InfoSec Write-ups »
Read more...
How I Bypassed a Strict WAF Using SQL Injection Tricks

The Silent SQL Injection Cloudflare Almost Hid From MeContinue reading on InfoSec Write-ups »
Read more...
Exploiting XSS to Bypass CSRF Defenses: Change Victim’s Email

Learn how a stored XSS flaw can be weaponized to defeat CSRF defenses and perform unauthorized actions on behalf of users.Continue reading on InfoSec Write-ups »
Read more...
Bug Bounty Methodology for Finding Bugs Easily

Welcome, bug bounty hunters! 🕵️‍♂️ Whether you’re just starting out or looking to sharpen your methodology, this guide will help you…Continue reading on InfoSec Write-ups »
Read more...
Credential Stuffing: How One Stolen Password Can Unlock Thousands of Accounts

30-Second RundownContinue reading on Medium »
Read more...
Bifrost Launches $500,000 Bug Bounty with Immunefi — One Critical Find Could Change Everything

In DeFi, a single overlooked flaw can trigger millions in losses. Just ask Hydration — they recently paid a $500,000 whitehat bounty to…Continue reading on Medium »
Read more...
How I Became a University’s Worst Cybersecurity Nightmare And Forced an Upgrade

Sometimes, all it takes is one recon to unravel an entire infrastructure.Continue reading on Medium »
Read more...
Dork to find Laravel Debug Mode Enabled

Advanced FOFA & ZoomEye Dorking for HackersContinue reading on MeetCyber »
Read more...
Account Takeover via Email Injection Tricks

Sometimes, you don’t need an RCE or SQLi — just a weak email parser. Here’s a sneaky way to hijack accounts when signup/login flows have…Continue reading on Medium »
Read more...
From Zero to Hero

Our First Steps into Bug Bounty HuntingContinue reading on Medium »
Read more...
Become a hacker — 101, A list of resources

A massive list of resources to help you get into the wonderful world of ethical hacking …Continue reading on Medium »
Read more...