Known-Plaintext Attack on PHP-Proxy: From Broken Encryption to FastCGI RCE
How a Caesar cipher implementation turned URL encryption into a complete server compromise through known-plaintext attack and FastCGI…Continue reading on Medium »
Read more...
How a Caesar cipher implementation turned URL encryption into a complete server compromise through known-plaintext attack and FastCGI…Continue reading on Medium »
Read more...
Medium
Known-Plaintext Attack on PHP-Proxy: From Broken Encryption to FastCGI RCE
How a Caesar cipher implementation turned URL encryption into a complete server compromise through known-plaintext attack and FastCGI…
The Best Vulnerability Disclosure Programs (VDP): A 2026 Guide for Security Researchers
Meta Description (SEO): Discover the best Vulnerability Disclosure Programs (VDPs) in 2026, including top platforms, pros & cons, and…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Meta Description (SEO): Discover the best Vulnerability Disclosure Programs (VDPs) in 2026, including top platforms, pros & cons, and…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Medium
The Best Vulnerability Disclosure Programs (VDP): A 2026 Guide for Security Researchers
Meta Description (SEO):
Discover the best Vulnerability Disclosure Programs (VDPs) in 2026, including top platforms, pros & cons, and…
Discover the best Vulnerability Disclosure Programs (VDPs) in 2026, including top platforms, pros & cons, and…
Internal vs External Pentest: 12 Tools Clients Don’t Know Exist (and How Pros Use Them)
Ever sat across from a client, nodding as they ask about “just running Nessus or nmap” for their pentest? Here’s a stat: 80% of successful…Continue reading on Medium »
Read more...
Ever sat across from a client, nodding as they ask about “just running Nessus or nmap” for their pentest? Here’s a stat: 80% of successful…Continue reading on Medium »
Read more...
Medium
Internal vs External Pentest: 12 Tools Clients Don’t Know Exist (and How Pros Use Them)
Ever sat across from a client, nodding as they ask about “just running Nessus or nmap” for their pentest? Here’s a stat: 80% of successful…
DoS on a live streaming and chatting App (Ethically).
Assalam-O-Alaikum , I hope you are doing well. Today, I will share one of my DoS findings and walk you through the idea behind it. I hope…Continue reading on Medium »
Read more...
Assalam-O-Alaikum , I hope you are doing well. Today, I will share one of my DoS findings and walk you through the idea behind it. I hope…Continue reading on Medium »
Read more...
Medium
DoS on a live streaming and chatting App (Ethically).
Assalam-O-Alaikum , I hope you are doing well. Today, I will share one of my DoS findings and walk you through the idea behind it. I hope…
How I Made $5,000 (₹4.49 Lakh) in Just 1 Hour by Scanning JavaScript Files
Hi everyone, It’s been a while since I published something useful, so here’s a quick write-up of how I made $5,000 in about one hour of…Continue reading on Medium »
Read more...
Hi everyone, It’s been a while since I published something useful, so here’s a quick write-up of how I made $5,000 in about one hour of…Continue reading on Medium »
Read more...
Medium
How I Made $5,000 (₹4.49 Lakh) in Just 1 Hour by Scanning JavaScript Files
Hi everyone,
It’s been a while since I published something useful, so here’s a quick write-up of how I made $5,000 in about one hour of…
It’s been a while since I published something useful, so here’s a quick write-up of how I made $5,000 in about one hour of…
API Breach Forensics Toolkit: Step-by-Step Tools to Uncover Every Hidden Threat
Ever heard about the 2023 API breach that exposed millions of private records in under 24 hours? It wasn’t some fancy zero-day — it was a…Continue reading on Medium »
Read more...
Ever heard about the 2023 API breach that exposed millions of private records in under 24 hours? It wasn’t some fancy zero-day — it was a…Continue reading on Medium »
Read more...
Medium
API Breach Forensics Toolkit: Step-by-Step Tools to Uncover Every Hidden Threat
Ever heard about the 2023 API breach that exposed millions of private records in under 24 hours? It wasn’t some fancy zero-day — it was a…
Bug Bounty Hunting — Complete Guide (Part-158)
🎨 RGB (Red-Green-Blue) Color ModelContinue reading on Medium »
Read more...
🎨 RGB (Red-Green-Blue) Color ModelContinue reading on Medium »
Read more...
Medium
Bug Bounty Hunting — Complete Guide (Part-158)
🎨 RGB (Red-Green-Blue) Color Model
Bug Bounty Hunting — Complete Guide (Part-159)
📱 RIL (Radio Interface Layer) ExplainedContinue reading on Medium »
Read more...
📱 RIL (Radio Interface Layer) ExplainedContinue reading on Medium »
Read more...
Medium
Bug Bounty Hunting — Complete Guide (Part-159)
📱 RIL (Radio Interface Layer) Explained
I got €€ for finding a bug that others missed
I was hunting on a self-hosted program and trying to understand the application as it was a sass platform.Continue reading on Medium »
Read more...
I was hunting on a self-hosted program and trying to understand the application as it was a sass platform.Continue reading on Medium »
Read more...
Medium
I got €€ for finding a bug that others missed
I was hunting on a self-hosted program and trying to understand the application as it was a sass platform.
Discovering Cloud Misconfigurations with Google Dorks
Find exposed sensitive data in AWS, Google Cloud, and other platforms when private information becomes searchable on Google.Continue reading on InfoSec Write-ups »
Read more...
Find exposed sensitive data in AWS, Google Cloud, and other platforms when private information becomes searchable on Google.Continue reading on InfoSec Write-ups »
Read more...
Medium
Discovering Cloud Misconfigurations with Google Dorks
Find exposed sensitive data in AWS, Google Cloud, and other platforms when private information becomes searchable on Google.
Members Can Prevent Admins/Owners from Accessing Reviews via Manipulated UUID
DescriptionContinue reading on Medium »
Read more...
DescriptionContinue reading on Medium »
Read more...
Medium
Members Can Prevent Admins/Owners from Accessing Reviews via Manipulated UUID
Description
This bug take to me 4 days to understand how is work
إِنَّ اللَّهَ وَمَلَائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّ ۚ يَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًاContinue reading on Medium »
Read more...
إِنَّ اللَّهَ وَمَلَائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّ ۚ يَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًاContinue reading on Medium »
Read more...
Medium
This bug take to me 4 days to understand how is work
إِنَّ اللَّهَ وَمَلَائِكَتَهُ يُصَلُّونَ عَلَى النَّبِيِّ ۚ يَا أَيُّهَا الَّذِينَ آمَنُوا صَلُّوا عَلَيْهِ وَسَلِّمُوا تَسْلِيمًا
[Broken Access Control] Members can pin/unpin any post in a Microsoft Teams community
The “Member” role can pin/unpin any post in the community via the API, whereas previously only the community owner could do so.Continue reading on Medium »
Read more...
The “Member” role can pin/unpin any post in the community via the API, whereas previously only the community owner could do so.Continue reading on Medium »
Read more...
Medium
[Broken Access Control] Members can pin/unpin any post in a Microsoft Teams community
The “Member” role can pin/unpin any post in the community via the API, whereas previously only the community owner could do so.
Call/Message anyone on Facebook directly, bypassing the message request ($$$$+$$$$$)
An Interesting bug on a not-so-interesting Meta PlatformContinue reading on InfoSec Write-ups »
Read more...
An Interesting bug on a not-so-interesting Meta PlatformContinue reading on InfoSec Write-ups »
Read more...
Medium
Call/Message anyone on Facebook directly, bypassing the message request ($$$$+$$$$$)
An Interesting bug on a not-so-interesting Meta Platform — Messenger Kids
API Breach Forensics Toolkit: Step-by-Step Tools to Uncover Every Hidden Threat
https://medium.com/@verylazytech/api-breach-forensics-toolkit-step-by-step-tools-to-uncover-every-hidden-threat-a593991f05ff?source=rss------bug_bounty-5
https://medium.com/@verylazytech/api-breach-forensics-toolkit-step-by-step-tools-to-uncover-every-hidden-threat-a593991f05ff?source=rss------bug_bounty-5
Ever heard about the 2023 API breach that exposed millions of private records in under 24 hours? It wasn’t some fancy zero-day — it was a…Continue reading on Medium » (https://medium.com/@verylazytech/api-breach-forensics-toolkit-step-by-step-tools-to-uncover-every-hidden-threat-a593991f05ff?source=rss------bug_bounty-5)
Bug Bounty Hunting — Complete Guide (Part-158)
https://medium.com/@rafid19/bug-bounty-hunting-complete-guide-part-158-bd392c1a970f?source=rss------bug_bounty-5
https://medium.com/@rafid19/bug-bounty-hunting-complete-guide-part-158-bd392c1a970f?source=rss------bug_bounty-5
🎨 RGB (Red-Green-Blue) Color ModelContinue reading on Medium » (https://medium.com/@rafid19/bug-bounty-hunting-complete-guide-part-158-bd392c1a970f?source=rss------bug_bounty-5)
Bug Bounty Hunting — Complete Guide (Part-159)
https://medium.com/@rafid19/bug-bounty-hunting-complete-guide-part-159-159c17d767e2?source=rss------bug_bounty-5
https://medium.com/@rafid19/bug-bounty-hunting-complete-guide-part-159-159c17d767e2?source=rss------bug_bounty-5
📱 RIL (Radio Interface Layer) ExplainedContinue reading on Medium » (https://medium.com/@rafid19/bug-bounty-hunting-complete-guide-part-159-159c17d767e2?source=rss------bug_bounty-5)