Buried in JavaScript: How One Comment Led Me to a Production API Key
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Buried in JavaScript: How One Comment Led Me to a Production API Key 💻🔑
Free Link 🎈
Bug Bounty Burnout and the Boredom of Repetitive Tasks
https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5
https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5
Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…Continue reading on Medium » (https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5)
CSRF vs JWT: The One Story That Finally Makes It Click
https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5
https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5
Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do.
Today, let’s meet their sneaky…Continue reading on Medium » (https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5)
Today, let’s meet their sneaky…Continue reading on Medium » (https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5)
Deep Dive: OAuth 2.0 Vulnerabilities & Exploitation Guide
https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5
https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…Continue reading on MeetCyber » (https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5)
Negative AddOn to Financial Flaw — Business Logic Vulnerability
https://vrushabhd.medium.com/negative-addon-to-financial-flaw-business-logic-vulnerability-ea40f269e173?source=rss------bug_bounty-5
https://vrushabhd.medium.com/negative-addon-to-financial-flaw-business-logic-vulnerability-ea40f269e173?source=rss------bug_bounty-5
My Journey into a Rental Car Service’s Financial FlawContinue reading on Medium » (https://vrushabhd.medium.com/negative-addon-to-financial-flaw-business-logic-vulnerability-ea40f269e173?source=rss------bug_bounty-5)
## 🚀 Introduction
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…Continue reading on Medium » (https://medium.com/@abdulbarhacker/beginner-bug-bounty-guide-dfd886cfafd3?source=rss------bug_bounty-5)
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…Continue reading on Medium » (https://medium.com/@abdulbarhacker/beginner-bug-bounty-guide-dfd886cfafd3?source=rss------bug_bounty-5)
⚡ The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…
Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium »
Read more...
Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium »
Read more...
Medium
⚡ The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak Point
Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…
Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium »
Read more...
Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium »
Read more...
Medium
🌐 The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an Entire Server Environment
Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…
⚡ The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…
https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5
Some vulnerabilities feel almost poetic.
A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium » (https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5
Some vulnerabilities feel almost poetic.
A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium » (https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5)
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…
https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5
Every bug hunter knows this feeling:
You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium » (https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5
Every bug hunter knows this feeling:
You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium » (https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5)
How I Used an IDOR to Trigger XSS and Take Over All Accounts
The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium »
Read more...
The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium »
Read more...
Medium
How I Used an IDOR to Trigger XSS and Take Over All Accounts
The IDOR-to-XSS chain that compromised an entire platform.
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium »
Read more...
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium »
Read more...
Medium
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.
How I Used an IDOR to Trigger XSS and Take Over All Accounts
https://medium.com/@codii/how-i-used-an-idor-to-trigger-xss-and-take-over-all-accounts-09ceca8e843a?source=rss------bug_bounty-5
https://medium.com/@codii/how-i-used-an-idor-to-trigger-xss-and-take-over-all-accounts-09ceca8e843a?source=rss------bug_bounty-5
The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium » (https://medium.com/@codii/how-i-used-an-idor-to-trigger-xss-and-take-over-all-accounts-09ceca8e843a?source=rss------bug_bounty-5)
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación
https://medium.com/@jpablo13/api10-2023-unsafe-consumption-of-apis-explotaci%C3%B3n-y-mitigaci%C3%B3n-2ec626af806e?source=rss------bug_bounty-5
https://medium.com/@jpablo13/api10-2023-unsafe-consumption-of-apis-explotaci%C3%B3n-y-mitigaci%C3%B3n-2ec626af806e?source=rss------bug_bounty-5
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium » (https://medium.com/@jpablo13/api10-2023-unsafe-consumption-of-apis-explotaci%C3%B3n-y-mitigaci%C3%B3n-2ec626af806e?source=rss------bug_bounty-5)