Logs Don’t Lie: How a GraphQL Debug Endpoint Spilled the Entire Database ️
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
📜 Logs Don’t Lie: How a GraphQL Debug Endpoint Spilled the Entire Database 🗄️💥
Hey there!😁
“Day 8: Mobile Hacking — How I Cracked a Banking App’s PIN in 10 Seconds ($5000 Bug)”
Two weeks ago, I reverse-engineered a “secure” banking app that claimed to use “military-grade encryption.” Turns out, they stored user…Continue reading on InfoSec Write-ups »
Read more...
Two weeks ago, I reverse-engineered a “secure” banking app that claimed to use “military-grade encryption.” Turns out, they stored user…Continue reading on InfoSec Write-ups »
Read more...
Medium
“Day 8: Mobile Hacking — How I Cracked a Banking App’s PIN in 10 Seconds ($5000 Bug)”
Two weeks ago, I reverse-engineered a “secure” banking app that claimed to use “military-grade encryption.” Turns out, they stored user…
Dorks For Sensitive Information Disclosure Part-3
Look google’s crawlers just got some juicy info……….Continue reading on Medium »
Read more...
Look google’s crawlers just got some juicy info……….Continue reading on Medium »
Read more...
Medium
Dorks For Sensitive Information Disclosure Part-3
Look google’s crawlers just got some juicy info……….
Certify 2.0 ... 🔥🔥🔥
https://www.reddit.com/r/redteamsec/comments/1mnp4fj/certify_20/
submitted by /u/SuperSaiyanSavSanta0 (https://www.reddit.com/user/SuperSaiyanSavSanta0)
[link] (https://specterops.io/blog/2025/08/11/certify-2-0/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mnp4fj/certify_20/)
https://www.reddit.com/r/redteamsec/comments/1mnp4fj/certify_20/
submitted by /u/SuperSaiyanSavSanta0 (https://www.reddit.com/user/SuperSaiyanSavSanta0)
[link] (https://specterops.io/blog/2025/08/11/certify-2-0/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mnp4fj/certify_20/)
Did you try this hackcubes challenge?
https://www.reddit.com/r/redteamsec/comments/1mo099d/did_you_try_this_hackcubes_challenge/
<!-- SC_OFF -->I stumbled upon a new platform called HackCubes (hackcubes.com) that has an invite-style challenge, kind of like the one HackTheBox used to have back in the day. It’s still pretty new, so I’m curious to see how it turns out — I’m planning to give it a try just for fun, they are giving away free APPsec exam vouchers. It reminded me of another CTF platform that’s been around for a while now, ParrotCTF (parrotctf.com), which some of you might have already checked out. Has anyone else here tried either of these kinds of invite challenges lately? <!-- SC_ON --> submitted by /u/EfficientRepeat6679 (https://www.reddit.com/user/EfficientRepeat6679)
[link] (http://hackcubes.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mo099d/did_you_try_this_hackcubes_challenge/)
https://www.reddit.com/r/redteamsec/comments/1mo099d/did_you_try_this_hackcubes_challenge/
<!-- SC_OFF -->I stumbled upon a new platform called HackCubes (hackcubes.com) that has an invite-style challenge, kind of like the one HackTheBox used to have back in the day. It’s still pretty new, so I’m curious to see how it turns out — I’m planning to give it a try just for fun, they are giving away free APPsec exam vouchers. It reminded me of another CTF platform that’s been around for a while now, ParrotCTF (parrotctf.com), which some of you might have already checked out. Has anyone else here tried either of these kinds of invite challenges lately? <!-- SC_ON --> submitted by /u/EfficientRepeat6679 (https://www.reddit.com/user/EfficientRepeat6679)
[link] (http://hackcubes.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mo099d/did_you_try_this_hackcubes_challenge/)
Rate Limiting in Web Applications: Bug That Pays Your Rent
Taming the flood before it drowns your system.Continue reading on Medium »
Read more...
Taming the flood before it drowns your system.Continue reading on Medium »
Read more...
Medium
Rate Limiting in Web Applications: Bug That Pays Your Rent
Taming the flood before it drowns your system.
A New Write-Up for a Vulnerability
Sensitive Information Leakage via Referrer Header in Password…
https://medium.com/@yousefezzeldin/a-new-write-up-for-a-vulnerability-sensitive-information-leakage-via-referrer-header-in-password-96ff2ef64b24?source=rss------bug_bounty-5
Sensitive Information Leakage via Referrer Header in Password…
https://medium.com/@yousefezzeldin/a-new-write-up-for-a-vulnerability-sensitive-information-leakage-via-referrer-header-in-password-96ff2ef64b24?source=rss------bug_bounty-5
الحمد لله رب العالمينContinue reading on Medium » (https://medium.com/@yousefezzeldin/a-new-write-up-for-a-vulnerability-sensitive-information-leakage-via-referrer-header-in-password-96ff2ef64b24?source=rss------bug_bounty-5)
Day5 Recon: Hacking Hidden Endpoints: How to Use Burp Suite & OWASP ZAP for Web Spidering and…
https://infosecwriteups.com/day5-recon-hacking-hidden-endpoints-how-to-use-burp-suite-owasp-zap-for-web-spidering-and-2a69aa4ffd3d?source=rss------bug_bounty-5
https://infosecwriteups.com/day5-recon-hacking-hidden-endpoints-how-to-use-burp-suite-owasp-zap-for-web-spidering-and-2a69aa4ffd3d?source=rss------bug_bounty-5
Learn how to automate endpoint discovery using Burp and ZAP — two powerful tools for bug bounty hunting and pentesting.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/day5-recon-hacking-hidden-endpoints-how-to-use-burp-suite-owasp-zap-for-web-spidering-and-2a69aa4ffd3d?source=rss------bug_bounty-5)
How ExpressVPN Vulnerability Enables Silent Card Abuse — And Calls It “Expected Behavior”
https://medium.com/@krivadna/how-expressvpn-vulnerability-enables-silent-card-abuse-and-calls-it-expected-behavior-7650a0b7a304?source=rss------bug_bounty-5
https://medium.com/@krivadna/how-expressvpn-vulnerability-enables-silent-card-abuse-and-calls-it-expected-behavior-7650a0b7a304?source=rss------bug_bounty-5
Free story linkContinue reading on Medium » (https://medium.com/@krivadna/how-expressvpn-vulnerability-enables-silent-card-abuse-and-calls-it-expected-behavior-7650a0b7a304?source=rss------bug_bounty-5)
Bug Bounty + AI = This Prompt List Will Change Your Game
https://javascript.plainenglish.io/bug-bounty-ai-this-prompt-list-will-change-your-game-4005a77d09bf?source=rss------bug_bounty-5
🧠 PROMPT CATEGORIESContinue reading on JavaScript in Plain English » (https://javascript.plainenglish.io/bug-bounty-ai-this-prompt-list-will-change-your-game-4005a77d09bf?source=rss------bug_bounty-5)
https://javascript.plainenglish.io/bug-bounty-ai-this-prompt-list-will-change-your-game-4005a77d09bf?source=rss------bug_bounty-5
🧠 PROMPT CATEGORIESContinue reading on JavaScript in Plain English » (https://javascript.plainenglish.io/bug-bounty-ai-this-prompt-list-will-change-your-game-4005a77d09bf?source=rss------bug_bounty-5)
Prompt Engineering Toolkit (2025 Edition)
https://medium.com/meetcyber/prompt-engineering-toolkit-2025-edition-8c3372944618?source=rss------bug_bounty-5
“JavaScript files don’t just power the frontend — they spill secrets, expose APIs, and open attack paths. You just need to ask the right…Continue reading on MeetCyber » (https://medium.com/meetcyber/prompt-engineering-toolkit-2025-edition-8c3372944618?source=rss------bug_bounty-5)
https://medium.com/meetcyber/prompt-engineering-toolkit-2025-edition-8c3372944618?source=rss------bug_bounty-5
“JavaScript files don’t just power the frontend — they spill secrets, expose APIs, and open attack paths. You just need to ask the right…Continue reading on MeetCyber » (https://medium.com/meetcyber/prompt-engineering-toolkit-2025-edition-8c3372944618?source=rss------bug_bounty-5)
Bug Bounty Entry: Getting Started with Platforms like HackerOne and Bugcrowd
In the rapidly evolving digital landscape, cyber threats loom large, and organizations are increasingly relying on proactive defense…Continue reading on Medium »
Read more...
In the rapidly evolving digital landscape, cyber threats loom large, and organizations are increasingly relying on proactive defense…Continue reading on Medium »
Read more...
Medium
Bug Bounty Entry: Getting Started with Platforms like HackerOne and Bugcrowd
In the rapidly evolving digital landscape, cyber threats loom large, and organizations are increasingly relying on proactive defense…
How I could Takeover any Account by Bypassing OTP Rate Limits
Every penetration tester dreams of finding that one flaw that flips a security model upside down. In my recent assessment, I stumbled…Continue reading on Medium »
Read more...
Every penetration tester dreams of finding that one flaw that flips a security model upside down. In my recent assessment, I stumbled…Continue reading on Medium »
Read more...
Medium
How I could Takeover any Account by Bypassing OTP Rate Limits
Every penetration tester dreams of finding that one flaw that flips a security model upside down. In my recent assessment, I stumbled…
The 3 Best Tools for Bug Bounty / Pentesting
There are lots of web application security tools. A lot of these tools are not being used to their fullest potential by bug hunters…Continue reading on Medium »
Read more...
There are lots of web application security tools. A lot of these tools are not being used to their fullest potential by bug hunters…Continue reading on Medium »
Read more...
Medium
The 3 Best Tools for Bug Bounty / Pentesting
There are lots of web application security tools. A lot of these tools are not being used to their fullest potential by bug hunters…
How I Found a Critical Bug in My First 24 Hours
A Beginner’s Guide to Finding Critical Bugs FastContinue reading on Medium »
Read more...
A Beginner’s Guide to Finding Critical Bugs FastContinue reading on Medium »
Read more...
Medium
How I Found a Critical Bug in My First 24 Hours
A Beginner’s Guide to Finding Critical Bugs Fast