️♂️ My Complete Recon Workflow for Bug Bounty Hunting (2025 Edition)
https://medium.com/@Purushothamr/%EF%B8%8F-%EF%B8%8F-my-complete-recon-workflow-for-bug-bounty-hunting-2025-edition-587b903385c0?source=rss------bug_bounty-5
https://medium.com/@Purushothamr/%EF%B8%8F-%EF%B8%8F-my-complete-recon-workflow-for-bug-bounty-hunting-2025-edition-587b903385c0?source=rss------bug_bounty-5
If you want to find real bugs, you have to start with real recon.Continue reading on Medium » (https://medium.com/@Purushothamr/%EF%B8%8F-%EF%B8%8F-my-complete-recon-workflow-for-bug-bounty-hunting-2025-edition-587b903385c0?source=rss------bug_bounty-5)
What a Honeypot Taught Me About Real-World Deception in Cybersecurity
https://osintteam.blog/what-a-honeypot-taught-me-about-real-world-deception-in-cybersecurity-0e8ea5241a34?source=rss------bug_bounty-5
https://osintteam.blog/what-a-honeypot-taught-me-about-real-world-deception-in-cybersecurity-0e8ea5241a34?source=rss------bug_bounty-5
Most people think cybersecurity is about breaking things — finding bugs, crashing systems, getting a shell. It’s the highlight reel. But…Continue reading on OSINT Team » (https://osintteam.blog/what-a-honeypot-taught-me-about-real-world-deception-in-cybersecurity-0e8ea5241a34?source=rss------bug_bounty-5)
CVE-2025-55182: A Pre-Authentication RCE in Next.js - Complete Guide
Hey there, back again with another post! 😄Continue reading on InfoSec Write-ups »
Read more...
Hey there, back again with another post! 😄Continue reading on InfoSec Write-ups »
Read more...
Medium
CVE-2025-55182: A Pre-Authentication RCE in Next.js - Complete Guide
Hey there, back again with another post! 😄
️ I Discovered a Parameter Pollution Vulnerability in a Payment QR System
BY NIMIT AHIR | “🚨 I Can Buy Anything for ₹5 by Exploiting a Payment QR Vulnerability ⚠️💸” | LinkedInContinue reading on Medium »
Read more...
BY NIMIT AHIR | “🚨 I Can Buy Anything for ₹5 by Exploiting a Payment QR Vulnerability ⚠️💸” | LinkedInContinue reading on Medium »
Read more...
Medium
🛡️ I Discovered a Parameter Pollution Vulnerability in a Payment QR System
BY NIMIT AHIR | “🚨 I Can Buy Anything for ₹5 by Exploiting a Payment QR Vulnerability ⚠️💸” | LinkedIn
JWT Authentication Bypass via Algorithm Confusion With No Exposed Key
How weak JWT algorithm handling exposes admin-level access without leaking a private key.Continue reading on MeetCyber »
Read more...
How weak JWT algorithm handling exposes admin-level access without leaking a private key.Continue reading on MeetCyber »
Read more...
Medium
JWT Authentication Bypass via Algorithm Confusion With No Exposed Key
How weak JWT algorithm handling exposes admin-level access without leaking a private key.
The Unconventional OSINT: How Dark Web Tools Gave Me the Edge to Find a $ Bug ️♂️
Free Link🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
The Unconventional OSINT: How Dark Web Tools Gave Me the Edge to Find a $ Bug 🕵️♂️💡
Free Link🎈
Backdoor CTF-2025: Flask of Cookies writeup | by Dargham Ali
Flask of Cookies WEB writeup by Dargham Ali for Backdoor CTF 2025: exploiting weak Flask SECRET_KEY to forge admin session cookie.Continue reading on Medium »
Read more...
Flask of Cookies WEB writeup by Dargham Ali for Backdoor CTF 2025: exploiting weak Flask SECRET_KEY to forge admin session cookie.Continue reading on Medium »
Read more...
Medium
Backdoor CTF-2025: Flask of Cookies writeup | by Dargham Ali
Flask of Cookies WEB writeup by Dargham Ali for Backdoor CTF 2025: exploiting weak Flask SECRET_KEY to forge admin session cookie.
Linux Network Sniffing & Packet Capture for Hackers
Network traffic analysis is one of the most critical skills for hackers, defenders, and red‑team operators. Today we cover tcpdump, Tshark…Continue reading on Medium »
Read more...
Network traffic analysis is one of the most critical skills for hackers, defenders, and red‑team operators. Today we cover tcpdump, Tshark…Continue reading on Medium »
Read more...
Medium
Linux Network Sniffing & Packet Capture for Hackers
Network traffic analysis is one of the most critical skills for hackers, defenders, and red‑team operators. Today we cover tcpdump, Tshark…
When One Slash Broke the Rules — Finding an Open Redirect on a Major Marketplace
Some bugs are loud and dramatic. Others slip in quietly, hiding in tiny assumptions — like how a website handles its URLs.Continue reading on Medium »
Read more...
Some bugs are loud and dramatic. Others slip in quietly, hiding in tiny assumptions — like how a website handles its URLs.Continue reading on Medium »
Read more...
Medium
🎯 When One Slash Broke the Rules — Finding an Open Redirect on a Major Marketplace
Some bugs are loud and dramatic. Others slip in quietly, hiding in tiny assumptions — like how a website handles its URLs.
The Day I Found a Public Laravel Log Viewer — And Why It Could Have Exposed an Entire Hospital…
Bug bounty hunting isn’t always about breaking into systems or crafting clever payloads. Sometimes, it’s about discovering something…Continue reading on Medium »
Read more...
Bug bounty hunting isn’t always about breaking into systems or crafting clever payloads. Sometimes, it’s about discovering something…Continue reading on Medium »
Read more...
Medium
📜 The Day I Found a Public Laravel Log Viewer — And Why It Could Have Exposed an Entire Hospital System
Bug bounty hunting isn’t always about breaking into systems or crafting clever payloads. Sometimes, it’s about discovering something…
API8:2023 Security Misconfiguration: Detección, Impacto y Mitigación
Guía completa sobre la vulnerabilidad API8:2023 (Security Misconfiguration): Ejemplos, metodología de detección y mitigación esencial.Continue reading on Medium »
Read more...
Guía completa sobre la vulnerabilidad API8:2023 (Security Misconfiguration): Ejemplos, metodología de detección y mitigación esencial.Continue reading on Medium »
Read more...
Medium
API8:2023 Security Misconfiguration: Detección, Impacto y Mitigación
Guía completa sobre la vulnerabilidad API8:2023 (Security Misconfiguration): Ejemplos, metodología de detección y mitigación esencial.
Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works
The Exact Recon → Bug → Report Flow That Still Pays in 2025Continue reading on OSINT Team »
Read more...
The Exact Recon → Bug → Report Flow That Still Pays in 2025Continue reading on OSINT Team »
Read more...
Medium
Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works
The Exact Recon → Bug → Report Flow That Still Pays in 2025
LazyHook
https://www.reddit.com/r/redteamsec/comments/1phn4n4/lazyhook/
<!-- SC_OFF -->Evade behavioral analysis/hips by executing malicious code within trusted Microsoft call stacks. <!-- SC_ON --> submitted by /u/One_Calligrapher6903 (https://www.reddit.com/user/One_Calligrapher6903)
[link] (https://github.com/hwbp/LazyHook) [comments] (https://www.reddit.com/r/redteamsec/comments/1phn4n4/lazyhook/)
https://www.reddit.com/r/redteamsec/comments/1phn4n4/lazyhook/
<!-- SC_OFF -->Evade behavioral analysis/hips by executing malicious code within trusted Microsoft call stacks. <!-- SC_ON --> submitted by /u/One_Calligrapher6903 (https://www.reddit.com/user/One_Calligrapher6903)
[link] (https://github.com/hwbp/LazyHook) [comments] (https://www.reddit.com/r/redteamsec/comments/1phn4n4/lazyhook/)
Phantom Keylogger per simulazioni di sicurezza
https://www.reddit.com/r/redteamsec/comments/1phq5g8/phantom_keylogger_per_simulazioni_di_sicurezza/
<!-- SC_OFF -->Ho pubblicato "Phantom Keylogger", un progetto pensato per simulazioni di red team e ricerca sulla sicurezza. Combina keylogging, cattura visiva e meccanismi di persistenza Perché provarlo? Perché se il tuo stack difensivo non riesce a rilevarlo, hai appena trovato un punto cieco. Se invece lo intercetta, hai una conferma che le tue contromisure funzionano. Repo pubblico: https://github.com/MattiaAlessi/phantom-keylogger Clona, installa le dipendenze Python e avvia il server: in pochi minuti hai un ambiente realistico per esercitazioni Vi sarei grato per qualsiasi consiglio o miglioramento <!-- SC_ON --> submitted by /u/Both_Animator_1120 (https://www.reddit.com/user/Both_Animator_1120)
[link] (https://github.com/MattiaAlessi/phantom-keylogger) [comments] (https://www.reddit.com/r/redteamsec/comments/1phq5g8/phantom_keylogger_per_simulazioni_di_sicurezza/)
https://www.reddit.com/r/redteamsec/comments/1phq5g8/phantom_keylogger_per_simulazioni_di_sicurezza/
<!-- SC_OFF -->Ho pubblicato "Phantom Keylogger", un progetto pensato per simulazioni di red team e ricerca sulla sicurezza. Combina keylogging, cattura visiva e meccanismi di persistenza Perché provarlo? Perché se il tuo stack difensivo non riesce a rilevarlo, hai appena trovato un punto cieco. Se invece lo intercetta, hai una conferma che le tue contromisure funzionano. Repo pubblico: https://github.com/MattiaAlessi/phantom-keylogger Clona, installa le dipendenze Python e avvia il server: in pochi minuti hai un ambiente realistico per esercitazioni Vi sarei grato per qualsiasi consiglio o miglioramento <!-- SC_ON --> submitted by /u/Both_Animator_1120 (https://www.reddit.com/user/Both_Animator_1120)
[link] (https://github.com/MattiaAlessi/phantom-keylogger) [comments] (https://www.reddit.com/r/redteamsec/comments/1phq5g8/phantom_keylogger_per_simulazioni_di_sicurezza/)
️ I Discovered a Parameter Pollution Vulnerability in a Payment QR System
https://medium.com/@nimitahir7631/%EF%B8%8F-i-discovered-a-parameter-pollution-vulnerability-in-a-payment-qr-system-0072038da4f6?source=rss------bug_bounty-5
https://medium.com/@nimitahir7631/%EF%B8%8F-i-discovered-a-parameter-pollution-vulnerability-in-a-payment-qr-system-0072038da4f6?source=rss------bug_bounty-5
BY NIMIT AHIR | “🚨 I Can Buy Anything for ₹5 by Exploiting a Payment QR Vulnerability ⚠️💸” | LinkedInContinue reading on Medium » (https://medium.com/@nimitahir7631/%EF%B8%8F-i-discovered-a-parameter-pollution-vulnerability-in-a-payment-qr-system-0072038da4f6?source=rss------bug_bounty-5)
JWT Authentication Bypass via Algorithm Confusion With No Exposed Key
https://medium.com/meetcyber/jwt-authentication-bypass-via-algorithm-confusion-with-no-exposed-key-a9958117b6a2?source=rss------bug_bounty-5
https://medium.com/meetcyber/jwt-authentication-bypass-via-algorithm-confusion-with-no-exposed-key-a9958117b6a2?source=rss------bug_bounty-5
How weak JWT algorithm handling exposes admin-level access without leaking a private key.Continue reading on MeetCyber » (https://medium.com/meetcyber/jwt-authentication-bypass-via-algorithm-confusion-with-no-exposed-key-a9958117b6a2?source=rss------bug_bounty-5)