Path Confusion: The Subtle Trick That Fooled the Cache
https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5
https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5
What is Web Cache Deception?
Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium » (https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5)
Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium » (https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5)
Logical 2FA Bypass via Missing clientId Parameter in Profile Update Endpoint
https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5)
https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@mhmodgm54/logical-2fa-bypass-via-missing-clientid-parameter-in-profile-update-endpoint-3f054bc651d6?source=rss------bug_bounty-5)
Pen testing Methodology Suggestions?
https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/
<!-- SC_OFF -->Hello, I am a Security Engineer with a solid IT background — over 10 years of experience spanning systems, networking, and security. Penetration testing is relatively new to me (about a year of hands-on experimentation), and during that time, I have gained a strong understanding of the tools and their functionality and have been tasked with performing pen testing for our clients. However, one area that continues to challenge me is initial access — specifically, how ethical hackers obtain credentials or NTLM hashes to begin testing. I notice that many pen testers seem to have a local machine on the target network as a starting point and are able to find the NTLM hashes with no problem, but this continues to stump me I would greatly appreciate insights from experienced ethical hackers regarding their methodology. What are your go-to techniques for gaining initial access (excluding phishing exercises and situations where the password is provided, no longer a Blackbox/grey box scenario)? In your experience, what are the most common approaches to getting that first foothold in a network, so I can get better at replicating and providing sufficient reports to our clients Tools I have used/learned: Responder Impacket(secrets dump LSASS dump, dcsync etc) Bloodhound hashcat/jack the ripper wireshark Vulnerability Scanners (Nessus/ OpenVas) OSINT Recon tools (information Gathering) There are other, but I didn't want to waste time listing them. Any help would be appreciated. <!-- SC_ON --> submitted by /u/Imaginary-Rise7393 (https://www.reddit.com/user/Imaginary-Rise7393)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/)
https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/
<!-- SC_OFF -->Hello, I am a Security Engineer with a solid IT background — over 10 years of experience spanning systems, networking, and security. Penetration testing is relatively new to me (about a year of hands-on experimentation), and during that time, I have gained a strong understanding of the tools and their functionality and have been tasked with performing pen testing for our clients. However, one area that continues to challenge me is initial access — specifically, how ethical hackers obtain credentials or NTLM hashes to begin testing. I notice that many pen testers seem to have a local machine on the target network as a starting point and are able to find the NTLM hashes with no problem, but this continues to stump me I would greatly appreciate insights from experienced ethical hackers regarding their methodology. What are your go-to techniques for gaining initial access (excluding phishing exercises and situations where the password is provided, no longer a Blackbox/grey box scenario)? In your experience, what are the most common approaches to getting that first foothold in a network, so I can get better at replicating and providing sufficient reports to our clients Tools I have used/learned: Responder Impacket(secrets dump LSASS dump, dcsync etc) Bloodhound hashcat/jack the ripper wireshark Vulnerability Scanners (Nessus/ OpenVas) OSINT Recon tools (information Gathering) There are other, but I didn't want to waste time listing them. Any help would be appreciated. <!-- SC_ON --> submitted by /u/Imaginary-Rise7393 (https://www.reddit.com/user/Imaginary-Rise7393)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/)
I’m a skid
https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/
<!-- SC_OFF -->Im completely a skid I don’t know how to write code I use it though and it think it’s pretty cool I find cool GitHub’s for the m5 stick and use the files on there but I want to learn how to pen test on my iPhone or wtv I have no idea how I have the ish app but I have no idea how to use it please help.. Ik I suck. <!-- SC_ON --> submitted by /u/Enricozz13 (https://www.reddit.com/user/Enricozz13)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/)
https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/
<!-- SC_OFF -->Im completely a skid I don’t know how to write code I use it though and it think it’s pretty cool I find cool GitHub’s for the m5 stick and use the files on there but I want to learn how to pen test on my iPhone or wtv I have no idea how I have the ish app but I have no idea how to use it please help.. Ik I suck. <!-- SC_ON --> submitted by /u/Enricozz13 (https://www.reddit.com/user/Enricozz13)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/)
CVE-2023–38646 – Pre-Auth RCE in Metabase: One Token to Rule Them All
By 24bkdoorContinue reading on Medium »
Read more...
By 24bkdoorContinue reading on Medium »
Read more...
Medium
CVE-2023–38646 – Pre-Auth RCE in Metabase: One Token to Rule Them All
By 24bkdoor
Beginner interested in all things ethical hacking
https://www.reddit.com/r/Pentesting/comments/1mpo0a4/beginner_interested_in_all_things_ethical_hacking/
<!-- SC_OFF -->Hope yall are doing well. Currently studying on thm about to start the junior pentester path. I have some very basic networking, linux, and web experience and looking to learn from others with more experience than me. Im down for ctfs, study sessions, discussions, projects, etc... I Just basically want to be a part of a community and improve, none of my friends are into this stuff. Send me a pm with discord invites or we can colab through reddit whatevers easier. <!-- SC_ON --> submitted by /u/Cheap-Ad-957 (https://www.reddit.com/user/Cheap-Ad-957)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpo0a4/beginner_interested_in_all_things_ethical_hacking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpo0a4/beginner_interested_in_all_things_ethical_hacking/)
https://www.reddit.com/r/Pentesting/comments/1mpo0a4/beginner_interested_in_all_things_ethical_hacking/
<!-- SC_OFF -->Hope yall are doing well. Currently studying on thm about to start the junior pentester path. I have some very basic networking, linux, and web experience and looking to learn from others with more experience than me. Im down for ctfs, study sessions, discussions, projects, etc... I Just basically want to be a part of a community and improve, none of my friends are into this stuff. Send me a pm with discord invites or we can colab through reddit whatevers easier. <!-- SC_ON --> submitted by /u/Cheap-Ad-957 (https://www.reddit.com/user/Cheap-Ad-957)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpo0a4/beginner_interested_in_all_things_ethical_hacking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpo0a4/beginner_interested_in_all_things_ethical_hacking/)
what tools should I learn for Android pentesting?
https://www.reddit.com/r/Pentesting/comments/1mpovo5/what_tools_should_i_learn_for_android_pentesting/
<!-- SC_OFF -->I’m new to hacking and curious about Android pentesting and methodologies behind it. What tools do you usually use for testing Android apps? I’d love to try some and start learning, so any beginner-friendly suggestions would be great. <!-- SC_ON --> submitted by /u/Whitebear_0one (https://www.reddit.com/user/Whitebear_0one)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpovo5/what_tools_should_i_learn_for_android_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpovo5/what_tools_should_i_learn_for_android_pentesting/)
https://www.reddit.com/r/Pentesting/comments/1mpovo5/what_tools_should_i_learn_for_android_pentesting/
<!-- SC_OFF -->I’m new to hacking and curious about Android pentesting and methodologies behind it. What tools do you usually use for testing Android apps? I’d love to try some and start learning, so any beginner-friendly suggestions would be great. <!-- SC_ON --> submitted by /u/Whitebear_0one (https://www.reddit.com/user/Whitebear_0one)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpovo5/what_tools_should_i_learn_for_android_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpovo5/what_tools_should_i_learn_for_android_pentesting/)
IDOR via Websockets allow me to takeover any users account
Hi everyone I hope you all are doing great and scoring lots of bounties. I am TeamDh49 Admin I am from India and I do bug bounty full time…Continue reading on Medium »
Read more...
Hi everyone I hope you all are doing great and scoring lots of bounties. I am TeamDh49 Admin I am from India and I do bug bounty full time…Continue reading on Medium »
Read more...
Medium
IDOR via Websockets allow me to takeover any users account
Hi everyone I hope you all are doing great and scoring lots of bounties. I am TeamDh49 Admin I am from India and I do bug bounty full time…
CVE-2023–38646 – Pre-Auth RCE in Metabase: One Token to Rule Them All
https://medium.com/@24bkdoor/cve-2023-38646-pre-auth-rce-in-metabase-one-token-to-rule-them-all-9bc6b5caa9c1?source=rss------bug_bounty-5
https://medium.com/@24bkdoor/cve-2023-38646-pre-auth-rce-in-metabase-one-token-to-rule-them-all-9bc6b5caa9c1?source=rss------bug_bounty-5
By 24bkdoorContinue reading on Medium » (https://medium.com/@24bkdoor/cve-2023-38646-pre-auth-rce-in-metabase-one-token-to-rule-them-all-9bc6b5caa9c1?source=rss------bug_bounty-5)
IDOR via Websockets allow me to takeover any users account
https://teamdh49.medium.com/idor-via-websockets-allow-me-to-takeover-any-users-account-b0dc23c8bcf5?source=rss------bug_bounty-5
https://teamdh49.medium.com/idor-via-websockets-allow-me-to-takeover-any-users-account-b0dc23c8bcf5?source=rss------bug_bounty-5
Hi everyone I hope you all are doing great and scoring lots of bounties. I am TeamDh49 Admin I am from India and I do bug bounty full time…Continue reading on Medium » (https://teamdh49.medium.com/idor-via-websockets-allow-me-to-takeover-any-users-account-b0dc23c8bcf5?source=rss------bug_bounty-5)
Top 5 Bug Bounty Tips
Top 5 Bug Bounty Tips (With Real-World Examples)Continue reading on Medium »
Read more...
Top 5 Bug Bounty Tips (With Real-World Examples)Continue reading on Medium »
Read more...
Medium
Top 5 Bug Bounty Tips
Top 5 Bug Bounty Tips (With Real-World Examples)
Dorks For Sensitive Information Disclosure Part-3
Look google’s crawlers just got some juicy info……….Continue reading on InfoSec Write-ups »
Read more...
Look google’s crawlers just got some juicy info……….Continue reading on InfoSec Write-ups »
Read more...
Medium
Dorks For Sensitive Information Disclosure Part-3
Look google’s crawlers just got some juicy info……….
️ How to Bypass Web Application Firewalls (WAFs)
Hey 👋, Web Application Firewalls (WAFs) areContinue reading on InfoSec Write-ups »
Read more...
Hey 👋, Web Application Firewalls (WAFs) areContinue reading on InfoSec Write-ups »
Read more...
Medium
🛡️ How to Bypass Web Application Firewalls (WAFs)
Hey 👋, Web Application Firewalls (WAFs) are
How I Found a Horizontal Privilege Escalation Vulnerability — From Recon to Exploit
How I Found a Horizontal Privilege Escalation Vulnerability — From Recon to Exploit Hi Researchers this is my 4rd Blog.Introduction During one of my bug bounty sessions, I came across a Horizontal Privilege Escalation vulnerability in a web application. This bug allowed me to access another user’s account and even reset their password — without their permission. In this post, I’ll walk you through how I approached the target, the steps I took, and how I finally exploited the bug.What is Horizontal Privilege Escalation? Horizontal privilege escalation occurs when an attacker gains access to another user’s data or actions without having elevated privileges. Unlike vertical privilege escalation (user → admin), horizontal escalation stays within the same permission level but jumps between accounts. Example:User A can access User B’s account by manipulating parameters like User ID.The attacker does not become an admin but still compromises sensitive data.Reconnaissance Phase Before I found the bug, I performed my usual recon routine:Account Setup I created two separate accounts on the target platform — let’s call them Account A and Account B.Browser Isolation To simulate real users, I opened both accounts in different browsers:Account A → FirefoxAccount B → Firefox IncognitoExploring the Application I browsed through the “My Account” and “Users” sections for both accounts, noting every feature and action available.Identifying the Vulnerability While exploring Account A, I navigated to: My Account → Users → Settings for a specific user. I noticed that the URL or request contained a GUID (a unique User ID). This looked something like:/user/settings?id=23f9a9b1-xxxx-xxxx-xxxx-xxxxxxxxxxx At this point, I suspected that if I replaced this GUID with another user’s ID, I might be able to access their data.Exploitation Here’s the step-by-step breakdown:Copy the Target User’s GUID In Account A, I right-clicked on another user’s “Settings” and copied their GUID.Trigger the Sensitive Action in Account B In Account B, I went to the “Reset Password” option for a user and captured the request in Burp Suite.Modify the Request In Burp, I replaced Account B’s GUID with the copied GUID from Account A.Send to Repeater After sending the modified request to the repeater and clicking Go, the response revealed the target user’s password reset token — effectively letting me take over the account.Impact This vulnerability meant that any authenticated user could:Reset passwords for other users.Gain access to sensitive user data.Cause account takeovers without user consent. Such an issue can lead to:Loss of trust from users.Legal issues due to privacy violations.Financial damages for the organization.References If you want to read more about horizontal privilege escalation:Dark Roast Security: Intro to Privilege EscalationHorizontal Privilege Escalation ExplainedHackerOne Report #244567HackerOne Report #246419Conclusion Horizontal privilege escalation bugs might seem small, but they can be as dangerous as admin-level exploits when sensitive actions like password resets are possible. In this case, simply swapping a GUID allowed me to control another user’s account — a reminder that ID-based access control should always be enforced on the server side. 💡 Tip for fellow hunters: Always check if IDs, tokens, or parameters in requests are validated properly. Something as simple as replacing an ID can lead to a critical bug. Dont forgot to join our Telegram Channel :https://t.me/anon_courses How I Found a Horizontal Privilege Escalation Vulnerability — From Recon to Exploit was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
How I Found a Horizontal Privilege Escalation Vulnerability — From Recon to Exploit Hi Researchers this is my 4rd Blog.Introduction During one of my bug bounty sessions, I came across a Horizontal Privilege Escalation vulnerability in a web application. This bug allowed me to access another user’s account and even reset their password — without their permission. In this post, I’ll walk you through how I approached the target, the steps I took, and how I finally exploited the bug.What is Horizontal Privilege Escalation? Horizontal privilege escalation occurs when an attacker gains access to another user’s data or actions without having elevated privileges. Unlike vertical privilege escalation (user → admin), horizontal escalation stays within the same permission level but jumps between accounts. Example:User A can access User B’s account by manipulating parameters like User ID.The attacker does not become an admin but still compromises sensitive data.Reconnaissance Phase Before I found the bug, I performed my usual recon routine:Account Setup I created two separate accounts on the target platform — let’s call them Account A and Account B.Browser Isolation To simulate real users, I opened both accounts in different browsers:Account A → FirefoxAccount B → Firefox IncognitoExploring the Application I browsed through the “My Account” and “Users” sections for both accounts, noting every feature and action available.Identifying the Vulnerability While exploring Account A, I navigated to: My Account → Users → Settings for a specific user. I noticed that the URL or request contained a GUID (a unique User ID). This looked something like:/user/settings?id=23f9a9b1-xxxx-xxxx-xxxx-xxxxxxxxxxx At this point, I suspected that if I replaced this GUID with another user’s ID, I might be able to access their data.Exploitation Here’s the step-by-step breakdown:Copy the Target User’s GUID In Account A, I right-clicked on another user’s “Settings” and copied their GUID.Trigger the Sensitive Action in Account B In Account B, I went to the “Reset Password” option for a user and captured the request in Burp Suite.Modify the Request In Burp, I replaced Account B’s GUID with the copied GUID from Account A.Send to Repeater After sending the modified request to the repeater and clicking Go, the response revealed the target user’s password reset token — effectively letting me take over the account.Impact This vulnerability meant that any authenticated user could:Reset passwords for other users.Gain access to sensitive user data.Cause account takeovers without user consent. Such an issue can lead to:Loss of trust from users.Legal issues due to privacy violations.Financial damages for the organization.References If you want to read more about horizontal privilege escalation:Dark Roast Security: Intro to Privilege EscalationHorizontal Privilege Escalation ExplainedHackerOne Report #244567HackerOne Report #246419Conclusion Horizontal privilege escalation bugs might seem small, but they can be as dangerous as admin-level exploits when sensitive actions like password resets are possible. In this case, simply swapping a GUID allowed me to control another user’s account — a reminder that ID-based access control should always be enforced on the server side. 💡 Tip for fellow hunters: Always check if IDs, tokens, or parameters in requests are validated properly. Something as simple as replacing an ID can lead to a critical bug. Dont forgot to join our Telegram Channel :https://t.me/anon_courses How I Found a Horizontal Privilege Escalation Vulnerability — From Recon to Exploit was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
Mastering Nmap: The Ultimate Guide to Network Scanning and Vulnerability Detection
Unleashing Nmap: Your Ultimate Guide to Network Exploration and Vulnerability HuntingContinue reading on InfoSec Write-ups »
Read more...
Unleashing Nmap: Your Ultimate Guide to Network Exploration and Vulnerability HuntingContinue reading on InfoSec Write-ups »
Read more...
Medium
Mastering Nmap: The Ultimate Guide to Network Scanning and Vulnerability Detection
Unleashing Nmap: Your Ultimate Guide to Network Exploration and Vulnerability Hunting