When AI Gossips: How I Eavesdropped on a Federated Learning System
You know that feeling when you’re at a party, and you can piece together everyone’s drama just by listening to random conversation…Continue reading on InfoSec Write-ups »
Read more...
You know that feeling when you’re at a party, and you can piece together everyone’s drama just by listening to random conversation…Continue reading on InfoSec Write-ups »
Read more...
Medium
When AI Gossips: How I Eavesdropped on a Federated Learning System
You know that feeling when you’re at a party, and you can piece together everyone’s drama just by listening to random conversation…
How I Check for Subdomain Takeovers Part 1
Subdomain takeovers is a high risk vulnerability that negatively impacts businesses, but if found, can result in big rewards for a bug…Continue reading on InfoSec Write-ups »
Read more...
Subdomain takeovers is a high risk vulnerability that negatively impacts businesses, but if found, can result in big rewards for a bug…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Check for Subdomain Takeovers Part 1
Subdomain takeovers is a high risk vulnerability that negatively impacts businesses, but if found, can result in big rewards for a bug…
A new Tool for Silent Device Tracking
https://www.reddit.com/r/redteamsec/comments/1pn0ea2/a_new_tool_for_silent_device_tracking/
<!-- SC_OFF --> Hey everyone, I just released WaSonar, an WhatsApp reconnaissance tool that can enumerate how many devices are linked to an account (Desktop/Web/Phone), figure out when they come online using silent RTT probes, and remotely exhaust a target's battery, data, and performance with zero user interaction or alerts. Try it out (no setup needed): npx wasonar-cli login or install via npm install -g wasonar-cli Source: https://github.com/AjayAntoIsDev/wasonar <!-- SC_ON --> submitted by /u/Floopy1704 (https://www.reddit.com/user/Floopy1704)
[link] (https://github.com/AjayAntoIsDev/WaSonar) [comments] (https://www.reddit.com/r/redteamsec/comments/1pn0ea2/a_new_tool_for_silent_device_tracking/)
https://www.reddit.com/r/redteamsec/comments/1pn0ea2/a_new_tool_for_silent_device_tracking/
<!-- SC_OFF --> Hey everyone, I just released WaSonar, an WhatsApp reconnaissance tool that can enumerate how many devices are linked to an account (Desktop/Web/Phone), figure out when they come online using silent RTT probes, and remotely exhaust a target's battery, data, and performance with zero user interaction or alerts. Try it out (no setup needed): npx wasonar-cli login or install via npm install -g wasonar-cli Source: https://github.com/AjayAntoIsDev/wasonar <!-- SC_ON --> submitted by /u/Floopy1704 (https://www.reddit.com/user/Floopy1704)
[link] (https://github.com/AjayAntoIsDev/WaSonar) [comments] (https://www.reddit.com/r/redteamsec/comments/1pn0ea2/a_new_tool_for_silent_device_tracking/)
Your Browser Is Spying On You — Here’s Proof
Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…Continue reading on InfoSec Write-ups »
Read more...
Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…Continue reading on InfoSec Write-ups »
Read more...
Medium
Your Browser Is Spying On You 👀 — Here’s Proof
Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…
I Didn’t Hack Anything — The App Gave Me Admin Access by Itself
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🪜🔓 I Didn’t Hack Anything — The App Gave Me Admin Access by Itself
Hey there!😁
How I Bypassed Voucher Limits Using a Race Condition Vulnerability
So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…Continue reading on InfoSec Write-ups »
Read more...
So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Bypassed Voucher Limits Using a Race Condition Vulnerability
So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…
The Paradox of the 3.4 Million: Why You Can’t Find a Job in a “Desperate” Industry
If you scroll through LinkedIn or read the latest annual reports from (ISC)², you will see the same headline repeated ad nauseam: “The…Continue reading on InfoSec Write-ups »
Read more...
If you scroll through LinkedIn or read the latest annual reports from (ISC)², you will see the same headline repeated ad nauseam: “The…Continue reading on InfoSec Write-ups »
Read more...
Medium
The Paradox of the 3.4 Million: Why You Can’t Find a Job in a “Desperate” Industry
** Not a Member?? CLICK HERE to read Full-Story**
dig Command Explained: A Simple Guide to DNS Lookups for Networking & Cybersecurity
Learn what the dig command is, how DNS works, and how dig helps debug and investigate DNS in networking and cybersecurity.Continue reading on Medium »
Read more...
Learn what the dig command is, how DNS works, and how dig helps debug and investigate DNS in networking and cybersecurity.Continue reading on Medium »
Read more...
Medium
🔍 dig Command Explained: A Simple Guide to DNS Lookups for Networking & Cybersecurity
Learn what the dig command is, how DNS works, and how dig helps debug and investigate DNS in networking and cybersecurity.
Your Browser Is Spying On You — Here’s Proof
Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…Continue reading on InfoSec Write-ups »
Read more...
Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…Continue reading on InfoSec Write-ups »
Read more...
Medium
Your Browser Is Spying On You 👀 — Here’s Proof
Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…
How I Bypassed Voucher Limits Using a Race Condition Vulnerability
So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…Continue reading on InfoSec Write-ups »
Read more...
So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…Continue reading on InfoSec Write-ups »
Read more...
Medium
How I Bypassed Voucher Limits Using a Race Condition Vulnerability
So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…
The Paradox of the 3.4 Million: Why You Can’t Find a Job in a “Desperate” Industry
If you scroll through LinkedIn or read the latest annual reports from (ISC)², you will see the same headline repeated ad nauseam: “The…Continue reading on InfoSec Write-ups »
Read more...
If you scroll through LinkedIn or read the latest annual reports from (ISC)², you will see the same headline repeated ad nauseam: “The…Continue reading on InfoSec Write-ups »
Read more...
Medium
The Paradox of the 3.4 Million: Why You Can’t Find a Job in a “Desperate” Industry
** Not a Member?? CLICK HERE to read Full-Story**
Bug Bounty Burnout and the Boredom of Repetitive Tasks
Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…Continue reading on Medium »
Read more...
Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…Continue reading on Medium »
Read more...
Medium
Bug Bounty Burnout and the Boredom of Repetitive Tasks
Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…
CSRF vs JWT: The One Story That Finally Makes It Click
Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do. Today, let’s meet their sneaky…Continue reading on Medium »
Read more...
Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do. Today, let’s meet their sneaky…Continue reading on Medium »
Read more...
Medium
🎭 CSRF vs JWT: The One Story That Finally Makes It Click
Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do.
Today, let’s meet their sneaky…
Today, let’s meet their sneaky…
Deep Dive: OAuth 2.0 Vulnerabilities & Exploitation Guide
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…Continue reading on MeetCyber »
Read more...
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…Continue reading on MeetCyber »
Read more...
Medium
Deep Dive: OAuth 2.0 Vulnerabilities & Exploitation Guide
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…
Negative AddOn to Financial Flaw — Business Logic Vulnerability
My Journey into a Rental Car Service’s Financial FlawContinue reading on Medium »
Read more...
My Journey into a Rental Car Service’s Financial FlawContinue reading on Medium »
Read more...
Medium
Negative AddOn to Financial Flaw — Business Logic Vulnerability
My Journey into a Rental Car Service’s Financial Flaw
Beginner Bug Bounty Guide
## 🚀 Introduction Bug bounty is one of the easiest ways to enter cybersecurity without a degree. If you understand how websites work and…Continue reading on Medium »
Read more...
## 🚀 Introduction Bug bounty is one of the easiest ways to enter cybersecurity without a degree. If you understand how websites work and…Continue reading on Medium »
Read more...
Medium
Beginner Bug Bounty Guide
## 🚀 Introduction
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…
# Common Web Vulnerabilities Every Developer Should Know
## 🔍 Introduction Most successful hacks don’t use advanced techniques. They exploit basic web vulnerabilities that developers often…Continue reading on Medium »
Read more...
## 🔍 Introduction Most successful hacks don’t use advanced techniques. They exploit basic web vulnerabilities that developers often…Continue reading on Medium »
Read more...
Medium
# Common Web Vulnerabilities Every Developer Should Know
## 🔍 Introduction
Most successful hacks don’t use advanced techniques. They exploit basic web vulnerabilities that developers often…
Most successful hacks don’t use advanced techniques. They exploit basic web vulnerabilities that developers often…
$25,000| Critical Vulnerability was Found on HackerOne
In the world of bug bounty hunting, finding a vulnerability on the platform itself — HackerOne — is the ultimate “Inception” moment.Continue reading on Medium »
Read more...
In the world of bug bounty hunting, finding a vulnerability on the platform itself — HackerOne — is the ultimate “Inception” moment.Continue reading on Medium »
Read more...
Recon Dorking: The Art of Advanced Information Gathering for Cybersecurity
Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in ReconnaissanceContinue reading on Medium »
Read more...
Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in ReconnaissanceContinue reading on Medium »
Read more...
Medium
Recon Dorking: The Art of Advanced Information Gathering for Cybersecurity
Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in Reconnaissance
A Hacker’s Christmas: Bug Bounties by Candlelight
While the world sleeps under tinsel and cheer, We grep through endpoints, one eye on the year. Firewalls whisper, logs softly confess…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
While the world sleeps under tinsel and cheer, We grep through endpoints, one eye on the year. Firewalls whisper, logs softly confess…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Medium
🎄 A Hacker’s Christmas: Bug Bounties by Candlelight 🎄
While the world sleeps under tinsel and cheer,
We grep through endpoints, one eye on the year.
Firewalls whisper, logs softly confess…
We grep through endpoints, one eye on the year.
Firewalls whisper, logs softly confess…
Buried in JavaScript: How One Comment Led Me to a Production API Key
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Buried in JavaScript: How One Comment Led Me to a Production API Key 💻🔑
Free Link 🎈