Recon Dorking: The Art of Advanced Information Gathering for Cybersecurity
Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in ReconnaissanceContinue reading on Medium »
Read more...
Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in ReconnaissanceContinue reading on Medium »
Read more...
Medium
Recon Dorking: The Art of Advanced Information Gathering for Cybersecurity
Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in Reconnaissance
A Hacker’s Christmas: Bug Bounties by Candlelight
While the world sleeps under tinsel and cheer, We grep through endpoints, one eye on the year. Firewalls whisper, logs softly confess…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
While the world sleeps under tinsel and cheer, We grep through endpoints, one eye on the year. Firewalls whisper, logs softly confess…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Medium
🎄 A Hacker’s Christmas: Bug Bounties by Candlelight 🎄
While the world sleeps under tinsel and cheer,
We grep through endpoints, one eye on the year.
Firewalls whisper, logs softly confess…
We grep through endpoints, one eye on the year.
Firewalls whisper, logs softly confess…
Buried in JavaScript: How One Comment Led Me to a Production API Key
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Buried in JavaScript: How One Comment Led Me to a Production API Key 💻🔑
Free Link 🎈
Bug Bounty Burnout and the Boredom of Repetitive Tasks
https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5
https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5
Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…Continue reading on Medium » (https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5)
CSRF vs JWT: The One Story That Finally Makes It Click
https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5
https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5
Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do.
Today, let’s meet their sneaky…Continue reading on Medium » (https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5)
Today, let’s meet their sneaky…Continue reading on Medium » (https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5)
Deep Dive: OAuth 2.0 Vulnerabilities & Exploitation Guide
https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5
https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…Continue reading on MeetCyber » (https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5)
Negative AddOn to Financial Flaw — Business Logic Vulnerability
https://vrushabhd.medium.com/negative-addon-to-financial-flaw-business-logic-vulnerability-ea40f269e173?source=rss------bug_bounty-5
https://vrushabhd.medium.com/negative-addon-to-financial-flaw-business-logic-vulnerability-ea40f269e173?source=rss------bug_bounty-5
My Journey into a Rental Car Service’s Financial FlawContinue reading on Medium » (https://vrushabhd.medium.com/negative-addon-to-financial-flaw-business-logic-vulnerability-ea40f269e173?source=rss------bug_bounty-5)
## 🚀 Introduction
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…Continue reading on Medium » (https://medium.com/@abdulbarhacker/beginner-bug-bounty-guide-dfd886cfafd3?source=rss------bug_bounty-5)
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…Continue reading on Medium » (https://medium.com/@abdulbarhacker/beginner-bug-bounty-guide-dfd886cfafd3?source=rss------bug_bounty-5)
⚡ The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…
Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium »
Read more...
Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium »
Read more...
Medium
⚡ The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak Point
Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…
Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium »
Read more...
Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium »
Read more...
Medium
🌐 The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an Entire Server Environment
Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…
⚡ The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…
https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5
Some vulnerabilities feel almost poetic.
A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium » (https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5
Some vulnerabilities feel almost poetic.
A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium » (https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5)
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…
https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5
Every bug hunter knows this feeling:
You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium » (https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5
Every bug hunter knows this feeling:
You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium » (https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5)
How I Used an IDOR to Trigger XSS and Take Over All Accounts
The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium »
Read more...
The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium »
Read more...
Medium
How I Used an IDOR to Trigger XSS and Take Over All Accounts
The IDOR-to-XSS chain that compromised an entire platform.
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium »
Read more...
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium »
Read more...
Medium
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.
How I Used an IDOR to Trigger XSS and Take Over All Accounts
https://medium.com/@codii/how-i-used-an-idor-to-trigger-xss-and-take-over-all-accounts-09ceca8e843a?source=rss------bug_bounty-5
https://medium.com/@codii/how-i-used-an-idor-to-trigger-xss-and-take-over-all-accounts-09ceca8e843a?source=rss------bug_bounty-5
The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium » (https://medium.com/@codii/how-i-used-an-idor-to-trigger-xss-and-take-over-all-accounts-09ceca8e843a?source=rss------bug_bounty-5)