How I Exploited a JWT Misconfiguration for Account Takeover and Admin Access in 5 Minutes
Hey there, back again with another post! 😄 In this post I’ll be sharing an interesting finding from an internal web pentest where I…Continue reading on InfoSec Write-ups »
Read more...
Hey there, back again with another post! 😄 In this post I’ll be sharing an interesting finding from an internal web pentest where I…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Exploited a JWT Misconfiguration for Account Takeover and Admin Access in 5 Minutes
Hey there, back again with another post! 😄 In this post I’ll be sharing an interesting finding from an internal web pentest where I…
Anatomy of Email Security Vulnerabilities: How Spoofing, Protocol Weaknesses, and Misconfigurations…
https://medium.com/@mohamednfe78/anatomy-of-email-security-vulnerabilities-how-spoofing-protocol-weaknesses-and-misconfigurations-e3264c712479?source=rss------bug_bounty-5
https://medium.com/@mohamednfe78/anatomy-of-email-security-vulnerabilities-how-spoofing-protocol-weaknesses-and-misconfigurations-e3264c712479?source=rss------bug_bounty-5
Introduction
In 2025, email remains the beating heart of enterprise collaboration, but it is also the most weaponized channel for…Continue reading on Medium » (https://medium.com/@mohamednfe78/anatomy-of-email-security-vulnerabilities-how-spoofing-protocol-weaknesses-and-misconfigurations-e3264c712479?source=rss------bug_bounty-5)
In 2025, email remains the beating heart of enterprise collaboration, but it is also the most weaponized channel for…Continue reading on Medium » (https://medium.com/@mohamednfe78/anatomy-of-email-security-vulnerabilities-how-spoofing-protocol-weaknesses-and-misconfigurations-e3264c712479?source=rss------bug_bounty-5)
I Broke Rate Limits to Hijack Accounts — Without Getting Blocked
During a bug bounty hunt, a single flaw was discovered that allowed me to reset any user’s password, without a single click from the…Continue reading on Medium »
Read more...
During a bug bounty hunt, a single flaw was discovered that allowed me to reset any user’s password, without a single click from the…Continue reading on Medium »
Read more...
Medium
I Broke Rate Limits to Hijack Accounts — Without Getting Blocked
During a bug bounty hunt, a single flaw was discovered that allowed me to reset any user’s password, without a single click from the…
Ultimate Bug Bounty Guide 2025: Top 100 Essential Tools + 100 Proven Techniques for Ethical Hackers
Stop learning cybersecurity the wrong way. While most aspiring ethical hackers waste months jumping between random tutorials and outdated…Continue reading on Medium »
Read more...
Stop learning cybersecurity the wrong way. While most aspiring ethical hackers waste months jumping between random tutorials and outdated…Continue reading on Medium »
Read more...
Medium
Ultimate Bug Bounty Guide 2025: Top 100 Essential Tools + 100 Proven Techniques for Ethical Hackers
Stop learning cybersecurity the wrong way. While most aspiring ethical hackers waste months jumping between random tutorials and outdated…
Critical Unauthorized Data Disclosure via HTTP Method Manipulation: A Lesson in API Security in…
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…Continue reading on Medium »
Read more...
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…Continue reading on Medium »
Read more...
Medium
Critical But very easy Unauthorized Data Disclosure via HTTP Method Manipulation: A Lesson in API Security in private bug bounty…
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…
Understanding the OWASP Top 10: The Simplest Guide for Web Security
The OWASP Top 10 is a globally recognized list of the most critical web application security risks, published by the Open Web Application…Continue reading on Medium »
Read more...
The OWASP Top 10 is a globally recognized list of the most critical web application security risks, published by the Open Web Application…Continue reading on Medium »
Read more...
Medium
Understanding the OWASP Top 10: The Simplest Guide for Web Security
The OWASP Top 10 is a globally recognized list of the most critical web application security risks, published by the Open Web Application…
Cloudflare Tunnel — Origin Exposure Weaponized
🔎 IntroductionContinue reading on Medium »
Read more...
🔎 IntroductionContinue reading on Medium »
Read more...
Medium
Cloudflare Tunnel — Origin Exposure Weaponized
🔎 Introduction
The Little CV + CSRF That Broke an Account
السَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ. اللَّهُمَّ صَلِّ عَلَى مُحَمَّدٍ وَعَلَى آلِ مُحَمَّدٍ، كَمَا صَلَّيْتَ عَلَى…Continue reading on Medium »
Read more...
السَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ. اللَّهُمَّ صَلِّ عَلَى مُحَمَّدٍ وَعَلَى آلِ مُحَمَّدٍ، كَمَا صَلَّيْتَ عَلَى…Continue reading on Medium »
Read more...
Medium
The Little CV + CSRF That Broke an Account
السَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ. اللَّهُمَّ صَلِّ عَلَى مُحَمَّدٍ وَعَلَى آلِ مُحَمَّدٍ، كَمَا صَلَّيْتَ عَلَى…
Linux File Permissions Exploits Every Hacker Should Know
Understanding Linux file permissions is critical for both system administrators and penetration testers. When misconfigured, file…Continue reading on Medium »
Read more...
Understanding Linux file permissions is critical for both system administrators and penetration testers. When misconfigured, file…Continue reading on Medium »
Read more...
Medium
Linux File Permissions Exploits Every Hacker Should Know
Understanding Linux file permissions is critical for both system administrators and penetration testers. When misconfigured, file…
The Psychology of a Hacker’s Click — Why Bug Bounty is More Mindset Than Tools
🧠 IntroductionContinue reading on Medium »
Read more...
🧠 IntroductionContinue reading on Medium »
Read more...
Medium
The Psychology of a Hacker’s Click — Why Bug Bounty is More Mindset Than Tools
🧠 Introduction
The Ghost Vulnerabilities — How “Fixed Bugs” Come Back From the Dead
👻 IntroductionContinue reading on Medium »
Read more...
👻 IntroductionContinue reading on Medium »
Read more...
Medium
The Ghost Vulnerabilities — How “Fixed Bugs” Come Back From the Dead
👻 Introduction
Not All Vulnerabilities Require Highly Technical Exploits | Security Misconfiguration
A Story of Security MisconfigurationContinue reading on Medium »
Read more...
A Story of Security MisconfigurationContinue reading on Medium »
Read more...
Medium
Not All Vulnerabilities Require Highly Technical Exploits | Security Misconfiguration
A Story of Security Misconfiguration
Critical but very easy Unauthorized Data Disclosure via HTTP Method Manipulation: A Lesson in API…
https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…Continue reading on Medium » (https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5)
https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5
Assalam o alaikum for muslim brothers, sisters and hello for non muslims. i hope all of you are doing well and learning new things day by…Continue reading on Medium » (https://medium.com/@InsbatArshad/critical-unauthorized-data-disclosure-via-http-method-manipulation-a-lesson-in-api-security-in-5d55c1ffd961?source=rss------bug_bounty-5)
Understanding the OWASP Top 10: The Simplest Guide for Web Security
https://medium.com/@cybersenpai/understanding-the-owasp-top-10-the-simplest-guide-for-web-security-8986530582d6?source=rss------bug_bounty-5
https://medium.com/@cybersenpai/understanding-the-owasp-top-10-the-simplest-guide-for-web-security-8986530582d6?source=rss------bug_bounty-5
The OWASP Top 10 is a globally recognized list of the most critical web application security risks, published by the Open Web Application…Continue reading on Medium » (https://medium.com/@cybersenpai/understanding-the-owasp-top-10-the-simplest-guide-for-web-security-8986530582d6?source=rss------bug_bounty-5)
Recon to Responsible Disclosure
https://saurabh-jain.medium.com/recon-to-responsible-disclosure-ee3d308a3b69?source=rss------bug_bounty-5
https://saurabh-jain.medium.com/recon-to-responsible-disclosure-ee3d308a3b69?source=rss------bug_bounty-5