From Pre-Account Takeover to Full Account Takeover using Google OAuth
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…Continue reading on Medium »
Read more...
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…Continue reading on Medium »
Read more...
Medium
From Pre-Account Takeover to Full Account Takeover using Google OAuth
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا، وَانْفَعْنَا…
Stop Wasting Time! The Secret Method to Find Exploits in Minutes
✨ Free Link in the first commentContinue reading on Medium »
Read more...
✨ Free Link in the first commentContinue reading on Medium »
Read more...
Medium
Stop Wasting Time! The Secret Method to Find Exploits in Minutes
✨ Free Link in the first comment
Informational Finding #1: Clickjacking on Non-Sensitive Action
OverviewContinue reading on Medium »
Read more...
OverviewContinue reading on Medium »
Read more...
Medium
Informational Finding #1: Clickjacking on Non-Sensitive Action
Overview
Hacking Flutter apps: Static, dynamic and beyond
Flutter is Google’s cross-platform app framework that lets developers write apps in Dart and ship them to Android, iOS, web, and desktop…Continue reading on Medium »
Read more...
Flutter is Google’s cross-platform app framework that lets developers write apps in Dart and ship them to Android, iOS, web, and desktop…Continue reading on Medium »
Read more...
Medium
Hacking Flutter apps: Static, dynamic and beyond
Flutter is Google’s cross-platform app framework that lets developers write apps in Dart and ship them to Android, iOS, web, and desktop…
From Curiosity to Critical: Uncovering Chained Vulnerabilities in a Private Web App Pentest
https://medium.com/@samruthsriram/from-curiosity-to-critical-uncovering-chained-vulnerabilities-in-a-private-web-app-pentest-febdc60a19ce?source=rss------bug_bounty-5
Sometimes, the difference between a standard pentest and a high-impact security discovery is simply… not stopping too early.Continue reading on Medium » (https://medium.com/@samruthsriram/from-curiosity-to-critical-uncovering-chained-vulnerabilities-in-a-private-web-app-pentest-febdc60a19ce?source=rss------bug_bounty-5)
https://medium.com/@samruthsriram/from-curiosity-to-critical-uncovering-chained-vulnerabilities-in-a-private-web-app-pentest-febdc60a19ce?source=rss------bug_bounty-5
Sometimes, the difference between a standard pentest and a high-impact security discovery is simply… not stopping too early.Continue reading on Medium » (https://medium.com/@samruthsriram/from-curiosity-to-critical-uncovering-chained-vulnerabilities-in-a-private-web-app-pentest-febdc60a19ce?source=rss------bug_bounty-5)
“Day 9: Cloud Heist Unlocked — How I Discovered a $100 AWS Vulnerability (Ethically)”
https://infosecwriteups.com/day-9-cloud-heist-unlocked-how-i-discovered-a-100-aws-vulnerability-ethically-15349c3ce4fb?source=rss------bug_bounty-5
https://infosecwriteups.com/day-9-cloud-heist-unlocked-how-i-discovered-a-100-aws-vulnerability-ethically-15349c3ce4fb?source=rss------bug_bounty-5
A White Hat’s Journey Through Lambda Misconfigurations & IAM DangersContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/day-9-cloud-heist-unlocked-how-i-discovered-a-100-aws-vulnerability-ethically-15349c3ce4fb?source=rss------bug_bounty-5)
Bug Bounty: Information Disclosure — Leaks, Logs & Loose Ends
https://medium.com/@rajkumarkumawat.workup/bug-bounty-information-disclosure-leaks-logs-loose-ends-54cf53dbbf09?source=rss------bug_bounty-5
https://medium.com/@rajkumarkumawat.workup/bug-bounty-information-disclosure-leaks-logs-loose-ends-54cf53dbbf09?source=rss------bug_bounty-5
“Information is power. If you control the flow of data, you control everything.”Continue reading on Medium » (https://medium.com/@rajkumarkumawat.workup/bug-bounty-information-disclosure-leaks-logs-loose-ends-54cf53dbbf09?source=rss------bug_bounty-5)
My 100 Hour Rule for Bug Bounty !
In this post, I share my 100-Hour Rule — how I structure every minute of hunting into focused phases, avoid the sunk cost trap, and boost…Continue reading on Medium »
Read more...
In this post, I share my 100-Hour Rule — how I structure every minute of hunting into focused phases, avoid the sunk cost trap, and boost…Continue reading on Medium »
Read more...
Medium
My 100 Hour Rule for Bug Bounty !
In this post, I share my 100-Hour Rule — how I structure every minute of hunting into focused phases, avoid the sunk cost trap, and boost…
I did the unthinkable and made a pentesting toolkit that works on iPhone!
https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/
https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/
<!-- SC_OFF -->It runs on iSH Shell, available on the app store. I modified some existing tools to work within it, made a few of my own and put it all together as a toolkit. Kinda like a Lazy Script for iPhone. I haven’t been able to test everything thoroughly but always looking for community feedback & suggestions! <!-- SC_ON --> submitted by /u/0x7_ (https://www.reddit.com/user/0x7_)
[link] (https://i.redd.it/xjpw70rcnlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/)
[link] (https://i.redd.it/xjpw70rcnlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/)
I did the unthinkable and made a pentesting toolkit that works on iPhone!
https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/
https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/
<!-- SC_OFF -->It runs on iSH Shell, available on the app store. I modified some existing tools to work within it, made a few of my own and put it all together as a toolkit. Kinda like a Lazy Script for iPhone. I haven’t been able to test everything thoroughly but always looking for community feedback & suggestions! <!-- SC_ON --> submitted by /u/0x7_ (https://www.reddit.com/user/0x7_)
[link] (https://i.redd.it/033p44ienlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/)
[link] (https://i.redd.it/033p44ienlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/)
Is Penetration Testing Financially Stable in the Long Run?
https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/
<!-- SC_OFF -->I’m at the very beginning of my journey into penetration testing, and I keep hearing mixed opinions about its financial stability as a career. Some people say the competition is fierce, stable positions are hard to get, and the income isn’t always worth the amount of effort required. I’ve also read that bug bounty programs aren’t as lucrative as many influencers make them seem, and relying on them for a consistent income can be unrealistic. From your perspective as an experienced penetration tester (or someone working in offensive security), do you think it’s worth continuing in this field if one of my main motivations is passion combined with the expectation of a financially rewarding career? I’d appreciate honest insights about what the real job market looks like and whether pen testing is still a viable long-term career option. <!-- SC_ON --> submitted by /u/n42- (https://www.reddit.com/user/n42-)
[link] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/) [comments] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/)
https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/
<!-- SC_OFF -->I’m at the very beginning of my journey into penetration testing, and I keep hearing mixed opinions about its financial stability as a career. Some people say the competition is fierce, stable positions are hard to get, and the income isn’t always worth the amount of effort required. I’ve also read that bug bounty programs aren’t as lucrative as many influencers make them seem, and relying on them for a consistent income can be unrealistic. From your perspective as an experienced penetration tester (or someone working in offensive security), do you think it’s worth continuing in this field if one of my main motivations is passion combined with the expectation of a financially rewarding career? I’d appreciate honest insights about what the real job market looks like and whether pen testing is still a viable long-term career option. <!-- SC_ON --> submitted by /u/n42- (https://www.reddit.com/user/n42-)
[link] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/) [comments] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/)
PenTest GPT
https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/
<!-- SC_OFF -->I am wondering if PenTest GPT is actually helpful, or if it is just another version of ChatGPT. Anyone has experience using it? <!-- SC_ON --> submitted by /u/turaoo (https://www.reddit.com/user/turaoo)
[link] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/)
https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/
<!-- SC_OFF -->I am wondering if PenTest GPT is actually helpful, or if it is just another version of ChatGPT. Anyone has experience using it? <!-- SC_ON --> submitted by /u/turaoo (https://www.reddit.com/user/turaoo)
[link] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/)
Google Cloud Partner API Credentials Found in Public Repo
Hey everyone,Continue reading on Medium »
Read more...
Hey everyone,Continue reading on Medium »
Read more...
Medium
Google Cloud Partner API Credentials Found in Public Repo
Hey everyone,