Red teaming Help
https://www.reddit.com/r/Pentesting/comments/1n4p7qa/red_teaming_help/
<!-- SC_OFF -->Hi people , So i am a security researcher who majorly comes from appsec background I have always had keen interest in red teaming but never got the opportunity Finally i have a project where in i can explore and learn some stuff but unfortunately I don't have any friends or anyone to seek guidance from. So far I have managed to get access to the network Now my initial plan was to identify how vlans are there like what segment contains server , dbs , nw devices etc and then try to find a valid cred and then maybe run bloodhound and try to find a path to DA But I would like to understand how you people approach this also what tools do u guys use Ty for the help <!-- SC_ON --> submitted by /u/Grouchy-Community-17 (https://www.reddit.com/user/Grouchy-Community-17)
[link] (https://www.reddit.com/r/Pentesting/comments/1n4p7qa/red_teaming_help/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n4p7qa/red_teaming_help/)
https://www.reddit.com/r/Pentesting/comments/1n4p7qa/red_teaming_help/
<!-- SC_OFF -->Hi people , So i am a security researcher who majorly comes from appsec background I have always had keen interest in red teaming but never got the opportunity Finally i have a project where in i can explore and learn some stuff but unfortunately I don't have any friends or anyone to seek guidance from. So far I have managed to get access to the network Now my initial plan was to identify how vlans are there like what segment contains server , dbs , nw devices etc and then try to find a valid cred and then maybe run bloodhound and try to find a path to DA But I would like to understand how you people approach this also what tools do u guys use Ty for the help <!-- SC_ON --> submitted by /u/Grouchy-Community-17 (https://www.reddit.com/user/Grouchy-Community-17)
[link] (https://www.reddit.com/r/Pentesting/comments/1n4p7qa/red_teaming_help/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n4p7qa/red_teaming_help/)
Seeking advice on career switch
https://www.reddit.com/r/Pentesting/comments/1n4wn8h/seeking_advice_on_career_switch/
<!-- SC_OFF -->Hi all, I hope you can help me. I am a software developer based in the UK who has 4 yoe as a developer and wanting to switch to pen testing. I am currently working through the INE eJPT and look forward to doing the HTB CPTS once I've done the eJPT exam. I wanted to ask if there are other certs I should look into getting as most of the UK jobs seem to ask for CREST/CHECK certifications <!-- SC_ON --> submitted by /u/SpeedPositive1224 (https://www.reddit.com/user/SpeedPositive1224)
[link] (https://www.reddit.com/r/Pentesting/comments/1n4wn8h/seeking_advice_on_career_switch/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n4wn8h/seeking_advice_on_career_switch/)
https://www.reddit.com/r/Pentesting/comments/1n4wn8h/seeking_advice_on_career_switch/
<!-- SC_OFF -->Hi all, I hope you can help me. I am a software developer based in the UK who has 4 yoe as a developer and wanting to switch to pen testing. I am currently working through the INE eJPT and look forward to doing the HTB CPTS once I've done the eJPT exam. I wanted to ask if there are other certs I should look into getting as most of the UK jobs seem to ask for CREST/CHECK certifications <!-- SC_ON --> submitted by /u/SpeedPositive1224 (https://www.reddit.com/user/SpeedPositive1224)
[link] (https://www.reddit.com/r/Pentesting/comments/1n4wn8h/seeking_advice_on_career_switch/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n4wn8h/seeking_advice_on_career_switch/)
Does anyone know to brute force Facebook password without hitting the rate limiting.Note: This is for ethical Authorized pentesing purpose
https://www.reddit.com/r/Pentesting/comments/1n5c06l/does_anyone_know_to_brute_force_facebook_password/
submitted by /u/cheemse01 (https://www.reddit.com/user/cheemse01)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5c06l/does_anyone_know_to_brute_force_facebook_password/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5c06l/does_anyone_know_to_brute_force_facebook_password/)
https://www.reddit.com/r/Pentesting/comments/1n5c06l/does_anyone_know_to_brute_force_facebook_password/
submitted by /u/cheemse01 (https://www.reddit.com/user/cheemse01)
[link] (https://www.reddit.com/r/Pentesting/comments/1n5c06l/does_anyone_know_to_brute_force_facebook_password/) [comments] (https://www.reddit.com/r/Pentesting/comments/1n5c06l/does_anyone_know_to_brute_force_facebook_password/)
Why Ransomware Gangs Are Now Targeting APIs and SaaS Apps
https://medium.com/@paritoshblogs/why-ransomware-gangs-are-now-targeting-apis-and-saas-apps-eb08cd045ad2?source=rss------bug_bounty-5
https://medium.com/@paritoshblogs/why-ransomware-gangs-are-now-targeting-apis-and-saas-apps-eb08cd045ad2?source=rss------bug_bounty-5
Ransomware has evolved.
In the early days, attackers focused on encrypting files on endpoints. Then, they moved to corporate networks…Continue reading on Medium » (https://medium.com/@paritoshblogs/why-ransomware-gangs-are-now-targeting-apis-and-saas-apps-eb08cd045ad2?source=rss------bug_bounty-5)
In the early days, attackers focused on encrypting files on endpoints. Then, they moved to corporate networks…Continue reading on Medium » (https://medium.com/@paritoshblogs/why-ransomware-gangs-are-now-targeting-apis-and-saas-apps-eb08cd045ad2?source=rss------bug_bounty-5)
Anatomy of Email Security Vulnerabilities: How Spoofing, Protocol Weaknesses, and Misconfigurations…
Introduction In 2025, email remains the beating heart of enterprise collaboration, but it is also the most weaponized channel for…Continue reading on Medium »
Read more...
Introduction In 2025, email remains the beating heart of enterprise collaboration, but it is also the most weaponized channel for…Continue reading on Medium »
Read more...
Medium
Anatomy of Email Security Vulnerabilities: How Spoofing, Protocol Weaknesses, and Misconfigurations…
Introduction
In 2025, email remains the beating heart of enterprise collaboration, but it is also the most weaponized channel for…
In 2025, email remains the beating heart of enterprise collaboration, but it is also the most weaponized channel for…
Security Engineer Interview Questions Part-1
With 6+ years of experience in the field of security, I’ve had the opportunity to participate in numerous interviews for Security…Continue reading on InfoSec Write-ups »
Read more...
With 6+ years of experience in the field of security, I’ve had the opportunity to participate in numerous interviews for Security…Continue reading on InfoSec Write-ups »
Read more...
Medium
Security Engineer Interview Questions Part-1
With 6+ years of experience in the field of security, I’ve had the opportunity to participate in numerous interviews for Security…
“Day 24: The Polyglot Poison — How I Turned a Resume Upload into a Remote Shell”
Bypassing Modern File Upload Protections with a Multi-Headed FileContinue reading on InfoSec Write-ups »
Read more...
Bypassing Modern File Upload Protections with a Multi-Headed FileContinue reading on InfoSec Write-ups »
Read more...
Medium
“Day 24: The Polyglot Poison — How I Turned a Resume Upload into a Remote Shell”
Bypassing Modern File Upload Protections with a Multi-Headed File
Boost Subdomain Discovery with Subfinder and API Integrations
Subfinder is a popular open-source tool created by Project Discovery which is designed for discovering and enumerating subdomains.Continue reading on InfoSec Write-ups »
Read more...
Subfinder is a popular open-source tool created by Project Discovery which is designed for discovering and enumerating subdomains.Continue reading on InfoSec Write-ups »
Read more...
Medium
Boost Subdomain Discovery with Subfinder and API Integrations
Subfinder is a popular open-source tool created by Project Discovery which is designed for discovering and enumerating subdomains.
The Cookie Bomb: My First $10K in Bug Bounties
When I started bug bounty hunting in 2019–2020, I came across a vulnerability that was simple to exploit yet surprisingly widespread. I began calling it the Cookie Bomb — and it earned me over $10,000 in my first year.Where It All Started While reading public HackerOne reports, I saw a bug where a query parameter value was directly written into a cookie. Since cookies are sent back to the server with every request, an attacker could inject an oversized string into a cookie, and the victim’s browser would keep sending it in every request. This led to a self-DoS situation:The victim’s browser stored the malicious cookie.Every request to the backend included that cookie.The server hit header size limits → requests failed.The victim’s session was essentially bricked until they cleared cookies. That idea stuck in my mind: could this be happening on other sites too?Hunting for Query Parameters That Set Cookies I started experimenting with query parameters that are commonly used for tracking and analytics, like:gclid (Google Ads)utm_source, utm_medium, utm_campaign (Google Analytics)fbclid (Facebook)dclid I used Wappalyzer to quickly identify whether a target was using Google or Facebook tracking. Then, I crafted requests with random 4000-character strings (around the max size for cookies).https://target.com/?gclid=AAAA...4000 chars…AAAA On reload, I checked if the string was stored as a cookie.Sometimes one parameter was enough to trigger the DoS.Other times, I had to combine multiple parameters (gclid + utmcampaign, etc.) to push total cookie size over the limit.In a few cases, I had to repeat the attack across multiple subdomains in order to set several malicious cookies. Only after combining them did the total cookie size exceed the backend’s header size limit and trigger the DoS.The Cookie Bomb Effect When successful, here’s what happened:Victim clicks the malicious link.Tracking parameter(s) get stored as cookies.Cookies exceed header size limit.All further requests fail with errors like 400 Bad Request or 414 URI Too Large.Victim can no longer use the application until they clear their cookies.A Few rewarded reportsRewards reports on Hackerone and Bugcrowd The Cookie Bomb: My First $10K in Bug Bounties was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
[Read more...](https://infosecwriteups.com/the-cookie-bomb-my-first-10k-in-bug-bounties-f86cb22c37fa?source=rss----7b722bfd1b8d--bugbounty)
When I started bug bounty hunting in 2019–2020, I came across a vulnerability that was simple to exploit yet surprisingly widespread. I began calling it the Cookie Bomb — and it earned me over $10,000 in my first year.Where It All Started While reading public HackerOne reports, I saw a bug where a query parameter value was directly written into a cookie. Since cookies are sent back to the server with every request, an attacker could inject an oversized string into a cookie, and the victim’s browser would keep sending it in every request. This led to a self-DoS situation:The victim’s browser stored the malicious cookie.Every request to the backend included that cookie.The server hit header size limits → requests failed.The victim’s session was essentially bricked until they cleared cookies. That idea stuck in my mind: could this be happening on other sites too?Hunting for Query Parameters That Set Cookies I started experimenting with query parameters that are commonly used for tracking and analytics, like:gclid (Google Ads)utm_source, utm_medium, utm_campaign (Google Analytics)fbclid (Facebook)dclid I used Wappalyzer to quickly identify whether a target was using Google or Facebook tracking. Then, I crafted requests with random 4000-character strings (around the max size for cookies).https://target.com/?gclid=AAAA...4000 chars…AAAA On reload, I checked if the string was stored as a cookie.Sometimes one parameter was enough to trigger the DoS.Other times, I had to combine multiple parameters (gclid + utmcampaign, etc.) to push total cookie size over the limit.In a few cases, I had to repeat the attack across multiple subdomains in order to set several malicious cookies. Only after combining them did the total cookie size exceed the backend’s header size limit and trigger the DoS.The Cookie Bomb Effect When successful, here’s what happened:Victim clicks the malicious link.Tracking parameter(s) get stored as cookies.Cookies exceed header size limit.All further requests fail with errors like 400 Bad Request or 414 URI Too Large.Victim can no longer use the application until they clear their cookies.A Few rewarded reportsRewards reports on Hackerone and Bugcrowd The Cookie Bomb: My First $10K in Bug Bounties was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
[Read more...](https://infosecwriteups.com/the-cookie-bomb-my-first-10k-in-bug-bounties-f86cb22c37fa?source=rss----7b722bfd1b8d--bugbounty)
Target
Target : Expect More. Pay Less.
Shop Target online and in-store for everything from groceries and essentials to clothing and electronics. Choose contactless pickup or delivery today.
Sensitive Endpoint Wordlist for Bug Hunting
Uncover Hidden Flaws: A Powerful Wordlist for Bug Bounty SuccessContinue reading on InfoSec Write-ups »
Read more...
Uncover Hidden Flaws: A Powerful Wordlist for Bug Bounty SuccessContinue reading on InfoSec Write-ups »
Read more...
Medium
Sensitive Endpoint Wordlist for Bug Hunting
Uncover Hidden Flaws: A Powerful Wordlist for Bug Bounty Success
Sliver is my favourite C2. Change my mind
https://www.reddit.com/r/redteamsec/comments/1n4udsr/sliver_is_my_favourite_c2_change_my_mind/
<!-- SC_OFF -->Change my mind: Rock-Solid Sessions Once a beacon lands, it stays put. I’ve left shells for months and if a connection fails a few times it'll reconnect based on the retry configuration you set up. Customization kinda easy: Cross-platform: Native clients for Windows, macOS, and Linux mean no awkward juggling. CLI based: Tab-complete everything, vps friendly, linux -tism friendly. I mean you can probably design a UI for this but why. Partial “task automation” baked-in: Now available for sessions i think but with a bit of custom thingy can work for beacons as well for sure (haven't tried yet, it's in my backlog) Nice to have features: Nonce+TOTP encryption by default: No extra flags, no forgotten certs—traffic’s wrapped the moment the beacon calls back. Custom HTTP requests: Being able to customize strings and extensions in the http requests is nice MTLS beacons: Bit less incognito stuff but still nice in some environments. Donut launcher built-in: Fire raw shellcode/assembly on the fly. God tier for executing tools through the beacon ETW patch & AMSI bypass: Haven’t stress-tested them yet, but early smoke tests look promising. Evasion: I rc4 encrypt the compiled beacons, and pack them inside a custom loader so, no much to say here. Around 90% bypass rate against the EDR in real exercises and testing. (Not a very crazy loader neither, made it just to work) Some more gimmicks i really haven't used much like canaries and watchtower or wireguard sessions and stuff. True that Linux beacons and sessions are kinda trash. Mainly focused on Windows targets but do someone have any C2 that truly dethrones Sliver? Or do you agree.. <!-- SC_ON --> submitted by /u/wh1t3k4t (https://www.reddit.com/user/wh1t3k4t)
[link] (https://github.com/BishopFox/sliver) [comments] (https://www.reddit.com/r/redteamsec/comments/1n4udsr/sliver_is_my_favourite_c2_change_my_mind/)
https://www.reddit.com/r/redteamsec/comments/1n4udsr/sliver_is_my_favourite_c2_change_my_mind/
<!-- SC_OFF -->Change my mind: Rock-Solid Sessions Once a beacon lands, it stays put. I’ve left shells for months and if a connection fails a few times it'll reconnect based on the retry configuration you set up. Customization kinda easy: Cross-platform: Native clients for Windows, macOS, and Linux mean no awkward juggling. CLI based: Tab-complete everything, vps friendly, linux -tism friendly. I mean you can probably design a UI for this but why. Partial “task automation” baked-in: Now available for sessions i think but with a bit of custom thingy can work for beacons as well for sure (haven't tried yet, it's in my backlog) Nice to have features: Nonce+TOTP encryption by default: No extra flags, no forgotten certs—traffic’s wrapped the moment the beacon calls back. Custom HTTP requests: Being able to customize strings and extensions in the http requests is nice MTLS beacons: Bit less incognito stuff but still nice in some environments. Donut launcher built-in: Fire raw shellcode/assembly on the fly. God tier for executing tools through the beacon ETW patch & AMSI bypass: Haven’t stress-tested them yet, but early smoke tests look promising. Evasion: I rc4 encrypt the compiled beacons, and pack them inside a custom loader so, no much to say here. Around 90% bypass rate against the EDR in real exercises and testing. (Not a very crazy loader neither, made it just to work) Some more gimmicks i really haven't used much like canaries and watchtower or wireguard sessions and stuff. True that Linux beacons and sessions are kinda trash. Mainly focused on Windows targets but do someone have any C2 that truly dethrones Sliver? Or do you agree.. <!-- SC_ON --> submitted by /u/wh1t3k4t (https://www.reddit.com/user/wh1t3k4t)
[link] (https://github.com/BishopFox/sliver) [comments] (https://www.reddit.com/r/redteamsec/comments/1n4udsr/sliver_is_my_favourite_c2_change_my_mind/)
Adaptix c2 framework extender tab not showing.
https://www.reddit.com/r/redteamsec/comments/1n5dz6w/adaptix_c2_framework_extender_tab_not_showing/
<!-- SC_OFF -->Hi im new to using Adaptix C2, but I can’t seem to load up extension kit because the extender tab isn’t showing but instead AxScript. Can someone help? I’d appreciate it. Since I can’t upload a photo. The tabs shown are Projects > AxScript > Settings <!-- SC_ON --> submitted by /u/Maleficent-Can3175 (https://www.reddit.com/user/Maleficent-Can3175)
[link] (https://adaptix-framework.gitbook.io/adaptix-framework) [comments] (https://www.reddit.com/r/redteamsec/comments/1n5dz6w/adaptix_c2_framework_extender_tab_not_showing/)
https://www.reddit.com/r/redteamsec/comments/1n5dz6w/adaptix_c2_framework_extender_tab_not_showing/
<!-- SC_OFF -->Hi im new to using Adaptix C2, but I can’t seem to load up extension kit because the extender tab isn’t showing but instead AxScript. Can someone help? I’d appreciate it. Since I can’t upload a photo. The tabs shown are Projects > AxScript > Settings <!-- SC_ON --> submitted by /u/Maleficent-Can3175 (https://www.reddit.com/user/Maleficent-Can3175)
[link] (https://adaptix-framework.gitbook.io/adaptix-framework) [comments] (https://www.reddit.com/r/redteamsec/comments/1n5dz6w/adaptix_c2_framework_extender_tab_not_showing/)
Puzzle to Pwnage: Decoding Hidden Endpoints for Maximum Exploitation
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🧩 Puzzle to Pwnage: Decoding Hidden Endpoints for Maximum Exploitation
Hey there!😁
How I Bypassed VPN Detection, Broke Client-Side Crypto and Found Multiple IDORS
A security test on a popular local mobile wallet Flutter-based Android App…Continue reading on Medium »
Read more...
A security test on a popular local mobile wallet Flutter-based Android App…Continue reading on Medium »
Read more...
Medium
How I Bypassed VPN Detection, Broke Client-Side Crypto and Found Multiple IDORS
A security test on a popular local mobile wallet Flutter-based Android App…
BackDoor 1: Walkthrough of NET-SQUARE Hacking Warm-Up Mobile Application Challenge
Recently got an opportunity to participate in a CTF (Capture-The-Flag) event which was organized by NET-SQUARE. They had their different…Continue reading on InfoSec Write-ups »
Read more...
Recently got an opportunity to participate in a CTF (Capture-The-Flag) event which was organized by NET-SQUARE. They had their different…Continue reading on InfoSec Write-ups »
Read more...
Medium
BackDoor 1: Walkthrough of NET-SQUARE Hacking Warm-Up Mobile Application Challenge
Recently got an opportunity to participate in a CTF (Capture-The-Flag) event which was organized by NET-SQUARE. They had their different…
How I Exploited a JWT Misconfiguration for Account Takeover and Admin Access in 5 Minutes
Hey there, back again with another post! 😄 In this post I’ll be sharing an interesting finding from an internal web pentest where I…Continue reading on InfoSec Write-ups »
Read more...
Hey there, back again with another post! 😄 In this post I’ll be sharing an interesting finding from an internal web pentest where I…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Exploited a JWT Misconfiguration for Account Takeover and Admin Access in 5 Minutes
Hey there, back again with another post! 😄 In this post I’ll be sharing an interesting finding from an internal web pentest where I…
Anatomy of Email Security Vulnerabilities: How Spoofing, Protocol Weaknesses, and Misconfigurations…
https://medium.com/@mohamednfe78/anatomy-of-email-security-vulnerabilities-how-spoofing-protocol-weaknesses-and-misconfigurations-e3264c712479?source=rss------bug_bounty-5
https://medium.com/@mohamednfe78/anatomy-of-email-security-vulnerabilities-how-spoofing-protocol-weaknesses-and-misconfigurations-e3264c712479?source=rss------bug_bounty-5