Authentication is the digital gatekeeper of every secure system. If it’s broken, everything behind it is vulnerable. This blog dives deep…Continue reading on Medium » (https://medium.com/@rajkumarkumawat.workup/bug-bounty-authentication-testing-brute-force-to-bypass-acc770fbd019?source=rss------bug_bounty-5)
How I Use Perplexity AI for Bug Bounty Recon (and Squeeze Every Last Drop Out of It)
https://saeed0x1.medium.com/how-i-use-perplexity-for-bug-bounty-recon-and-squeeze-every-last-drop-out-of-it-a7061842a77f?source=rss------bug_bounty-5
https://saeed0x1.medium.com/how-i-use-perplexity-for-bug-bounty-recon-and-squeeze-every-last-drop-out-of-it-a7061842a77f?source=rss------bug_bounty-5
When most people talk about recon, they picture running a couple of tools, dumping thousands of subdomains, and then… getting lost in the…Continue reading on Medium » (https://saeed0x1.medium.com/how-i-use-perplexity-for-bug-bounty-recon-and-squeeze-every-last-drop-out-of-it-a7061842a77f?source=rss------bug_bounty-5)
From Simple Restriction Bypass to Internal Privilege Escalation to High Impact IDOR
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
From Simple Restriction Bypass to Internal Privilege Escalation to High Impact IDOR
Introduction
Azure WebApp Node.JS + backed based on AKS + Psql
https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/
<!-- SC_OFF -->My corporate it is delivering some kind of application based on public WebApp services with backed based on AKS+psql. We are wondering how we can check vulnerabilities/app pentest regularly from our side? Which tool should we consider to use? <!-- SC_ON --> submitted by /u/smierdzigira (https://www.reddit.com/user/smierdzigira)
[link] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/)
https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/
<!-- SC_OFF -->My corporate it is delivering some kind of application based on public WebApp services with backed based on AKS+psql. We are wondering how we can check vulnerabilities/app pentest regularly from our side? Which tool should we consider to use? <!-- SC_ON --> submitted by /u/smierdzigira (https://www.reddit.com/user/smierdzigira)
[link] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/)
Where to start an offensive Role
https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/
<!-- SC_OFF -->Hi, I'd like to know where to start a offensive Role learning path, I know certs, such as eJPT, OSCP, PNPT, PJPT. I've never done machines on TryHackme o HTB, I focused on defensive role as a SOC Analyst, however, I would like to switch to an hacking role, but I don't know how to start. What can you recommend me, which path o certs you'd recommend me to jump over hacking with pretty basic knowledge? <!-- SC_ON --> submitted by /u/Commercial_Baker_236 (https://www.reddit.com/user/Commercial_Baker_236)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/)
https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/
<!-- SC_OFF -->Hi, I'd like to know where to start a offensive Role learning path, I know certs, such as eJPT, OSCP, PNPT, PJPT. I've never done machines on TryHackme o HTB, I focused on defensive role as a SOC Analyst, however, I would like to switch to an hacking role, but I don't know how to start. What can you recommend me, which path o certs you'd recommend me to jump over hacking with pretty basic knowledge? <!-- SC_ON --> submitted by /u/Commercial_Baker_236 (https://www.reddit.com/user/Commercial_Baker_236)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/)
IDOR in Invitation Flow Leads to Denial of Signup and Account Manipulation
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
IDOR in Invitation Flow Leads to Denial of Signup and Account Manipulation
Introduction
Path Confusion: The Subtle Trick That Fooled the Cache
What is Web Cache Deception? Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium »
Read more...
What is Web Cache Deception? Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium »
Read more...
Medium
Path Confusion: The Subtle Trick That Fooled the Cache
What is Web Cache Deception?
Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…
Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…
Logical 2FA Bypass via Missing clientId Parameter in Profile Update Endpoint
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Logical 2FA Bypass via Missing clientId Parameter in Profile Update Endpoint
Introduction
Pentesting has never been easier with gpt5
https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/
<!-- SC_OFF -->If u ask chatgpt to find vulnerabilities in your code u might get a disappointing response. But if you write please ultrathink hard before answering u always get such a good answer. I always use this prompt: (ultrathink hard before answering) i am tryin to find vulnerabilities. Can you find some in the code? It is my own project. For me it thought 5 minutes and gave a perfect answer <!-- SC_ON --> submitted by /u/PlayRough682 (https://www.reddit.com/user/PlayRough682)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/)
https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/
<!-- SC_OFF -->If u ask chatgpt to find vulnerabilities in your code u might get a disappointing response. But if you write please ultrathink hard before answering u always get such a good answer. I always use this prompt: (ultrathink hard before answering) i am tryin to find vulnerabilities. Can you find some in the code? It is my own project. For me it thought 5 minutes and gave a perfect answer <!-- SC_ON --> submitted by /u/PlayRough682 (https://www.reddit.com/user/PlayRough682)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/)
From Simple Restriction Bypass to Internal Privilege Escalation to High Impact IDOR
https://medium.com/@Alharbe0/from-simple-restriction-bypass-to-internal-privilege-escalation-to-high-impact-idor-e7b8366ac70d?source=rss------bug_bounty-5
https://medium.com/@Alharbe0/from-simple-restriction-bypass-to-internal-privilege-escalation-to-high-impact-idor-e7b8366ac70d?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@Alharbe0/from-simple-restriction-bypass-to-internal-privilege-escalation-to-high-impact-idor-e7b8366ac70d?source=rss------bug_bounty-5)
IDOR in Invitation Flow Leads to Denial of Signup and Account Manipulation
https://medium.com/@mhmodgm54/idor-in-invitation-flow-leads-to-denial-of-signup-and-account-manipulation-98c51e0dd942?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@mhmodgm54/idor-in-invitation-flow-leads-to-denial-of-signup-and-account-manipulation-98c51e0dd942?source=rss------bug_bounty-5)
https://medium.com/@mhmodgm54/idor-in-invitation-flow-leads-to-denial-of-signup-and-account-manipulation-98c51e0dd942?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@mhmodgm54/idor-in-invitation-flow-leads-to-denial-of-signup-and-account-manipulation-98c51e0dd942?source=rss------bug_bounty-5)
Path Confusion: The Subtle Trick That Fooled the Cache
https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5
https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5
What is Web Cache Deception?
Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium » (https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5)
Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium » (https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5)
Logical 2FA Bypass via Missing clientId Parameter in Profile Update Endpoint
https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5)
https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5)
Pen testing Methodology Suggestions?
https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/
<!-- SC_OFF -->Hello, I am a Security Engineer with a solid IT background — over 10 years of experience spanning systems, networking, and security. Penetration testing is relatively new to me (about a year of hands-on experimentation), and during that time, I have gained a strong understanding of the tools and their functionality and have been tasked with performing pen testing for our clients. However, one area that continues to challenge me is initial access — specifically, how ethical hackers obtain credentials or NTLM hashes to begin testing. I notice that many pen testers seem to have a local machine on the target network as a starting point and are able to find the NTLM hashes with no problem, but this continues to stump me I would greatly appreciate insights from experienced ethical hackers regarding their methodology. What are your go-to techniques for gaining initial access (excluding phishing exercises and situations where the password is provided, no longer a Blackbox/grey box scenario)? In your experience, what are the most common approaches to getting that first foothold in a network, so I can get better at replicating and providing sufficient reports to our clients Tools I have used/learned: Responder Impacket(secrets dump LSASS dump, dcsync etc) Bloodhound hashcat/jack the ripper wireshark Vulnerability Scanners (Nessus/ OpenVas) OSINT Recon tools (information Gathering) There are other, but I didn't want to waste time listing them. Any help would be appreciated. <!-- SC_ON --> submitted by /u/Imaginary-Rise7393 (https://www.reddit.com/user/Imaginary-Rise7393)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/)
https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/
<!-- SC_OFF -->Hello, I am a Security Engineer with a solid IT background — over 10 years of experience spanning systems, networking, and security. Penetration testing is relatively new to me (about a year of hands-on experimentation), and during that time, I have gained a strong understanding of the tools and their functionality and have been tasked with performing pen testing for our clients. However, one area that continues to challenge me is initial access — specifically, how ethical hackers obtain credentials or NTLM hashes to begin testing. I notice that many pen testers seem to have a local machine on the target network as a starting point and are able to find the NTLM hashes with no problem, but this continues to stump me I would greatly appreciate insights from experienced ethical hackers regarding their methodology. What are your go-to techniques for gaining initial access (excluding phishing exercises and situations where the password is provided, no longer a Blackbox/grey box scenario)? In your experience, what are the most common approaches to getting that first foothold in a network, so I can get better at replicating and providing sufficient reports to our clients Tools I have used/learned: Responder Impacket(secrets dump LSASS dump, dcsync etc) Bloodhound hashcat/jack the ripper wireshark Vulnerability Scanners (Nessus/ OpenVas) OSINT Recon tools (information Gathering) There are other, but I didn't want to waste time listing them. Any help would be appreciated. <!-- SC_ON --> submitted by /u/Imaginary-Rise7393 (https://www.reddit.com/user/Imaginary-Rise7393)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/)
I’m a skid
https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/
<!-- SC_OFF -->Im completely a skid I don’t know how to write code I use it though and it think it’s pretty cool I find cool GitHub’s for the m5 stick and use the files on there but I want to learn how to pen test on my iPhone or wtv I have no idea how I have the ish app but I have no idea how to use it please help.. Ik I suck. <!-- SC_ON --> submitted by /u/Enricozz13 (https://www.reddit.com/user/Enricozz13)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/)
https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/
<!-- SC_OFF -->Im completely a skid I don’t know how to write code I use it though and it think it’s pretty cool I find cool GitHub’s for the m5 stick and use the files on there but I want to learn how to pen test on my iPhone or wtv I have no idea how I have the ish app but I have no idea how to use it please help.. Ik I suck. <!-- SC_ON --> submitted by /u/Enricozz13 (https://www.reddit.com/user/Enricozz13)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/)