Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems
After years in bug bounty, here’s something most beginners don’t realize:Continue reading on OSINT Team »
Read more...
After years in bug bounty, here’s something most beginners don’t realize:Continue reading on OSINT Team »
Read more...
Medium
Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems 🧠💰
After years in bug bounty, here’s something most beginners don’t realize:
$5,000 Bounty: How I Hijacked Google Gemini’s UI via Python Code Execution
This exploit can be weaponized to target anyone,no user is beyond its reach.Continue reading on Medium »
Read more...
This exploit can be weaponized to target anyone,no user is beyond its reach.Continue reading on Medium »
Read more...
Medium
$5,000 Bounty: How I Hijacked Google Gemini’s UI via Python Code Execution
This exploit can be weaponized to target anyone,no user is beyond its reach.
GitHub - 3lp4tr0n/SessionHop: Windows Session Hijacking via COM
https://www.reddit.com/r/redteamsec/comments/1poqgiv/github_3lp4tr0nsessionhop_windows_session/
submitted by /u/intuentis0x0 (https://www.reddit.com/user/intuentis0x0)
[link] (https://github.com/3lp4tr0n/SessionHop/) [comments] (https://www.reddit.com/r/redteamsec/comments/1poqgiv/github_3lp4tr0nsessionhop_windows_session/)
https://www.reddit.com/r/redteamsec/comments/1poqgiv/github_3lp4tr0nsessionhop_windows_session/
submitted by /u/intuentis0x0 (https://www.reddit.com/user/intuentis0x0)
[link] (https://github.com/3lp4tr0n/SessionHop/) [comments] (https://www.reddit.com/r/redteamsec/comments/1poqgiv/github_3lp4tr0nsessionhop_windows_session/)
SILPH -- Dump LSA, SAM, and DCC2 via indirect syscalls without writing to disk
https://www.reddit.com/r/redteamsec/comments/1poru00/silph_dump_lsa_sam_and_dcc2_via_indirect_syscalls/
submitted by /u/h4r0r (https://www.reddit.com/user/h4r0r)
[link] (https://github.com/almounah/silph) [comments] (https://www.reddit.com/r/redteamsec/comments/1poru00/silph_dump_lsa_sam_and_dcc2_via_indirect_syscalls/)
https://www.reddit.com/r/redteamsec/comments/1poru00/silph_dump_lsa_sam_and_dcc2_via_indirect_syscalls/
submitted by /u/h4r0r (https://www.reddit.com/user/h4r0r)
[link] (https://github.com/almounah/silph) [comments] (https://www.reddit.com/r/redteamsec/comments/1poru00/silph_dump_lsa_sam_and_dcc2_via_indirect_syscalls/)
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096)
https://www.reddit.com/r/redteamsec/comments/1pp4th5/inside_posthog_how_ssrf_a_clickhouse_sql_escaping/
submitted by /u/wtfse (https://www.reddit.com/user/wtfse)
[link] (https://mdisec.com/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/) [comments] (https://www.reddit.com/r/redteamsec/comments/1pp4th5/inside_posthog_how_ssrf_a_clickhouse_sql_escaping/)
https://www.reddit.com/r/redteamsec/comments/1pp4th5/inside_posthog_how_ssrf_a_clickhouse_sql_escaping/
submitted by /u/wtfse (https://www.reddit.com/user/wtfse)
[link] (https://mdisec.com/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/) [comments] (https://www.reddit.com/r/redteamsec/comments/1pp4th5/inside_posthog_how_ssrf_a_clickhouse_sql_escaping/)
The Bug Bounty Automation Stack That Can Generate $10K+ (Open Source Tools Only)
https://systemweakness.com/the-bug-bounty-automation-stack-that-can-generate-10k-open-source-tools-only-93ed3e8b3ee7?source=rss------bug_bounty-5
https://systemweakness.com/the-bug-bounty-automation-stack-that-can-generate-10k-open-source-tools-only-93ed3e8b3ee7?source=rss------bug_bounty-5
Automation doesn’t find bugs. Automated workflows combined with manual validation do. While beginners waste time running Nuclei on random…Continue reading on System Weakness » (https://systemweakness.com/the-bug-bounty-automation-stack-that-can-generate-10k-open-source-tools-only-93ed3e8b3ee7?source=rss------bug_bounty-5)
# The API Endpoint That Shouldn’t Have Exposed 50,000 User Records
https://medium.com/@abdulbarhacker/the-api-endpoint-that-shouldnt-have-exposed-50-000-user-records-4b29b9f20df2?source=rss------bug_bounty-5
https://medium.com/@abdulbarhacker/the-api-endpoint-that-shouldnt-have-exposed-50-000-user-records-4b29b9f20df2?source=rss------bug_bounty-5
## 🌙 A Long Night of Nothing
I had been testing this e-commerce platform for almost eight hours straight.
No XSS. No SQL injection. No…Continue reading on Medium » (https://medium.com/@abdulbarhacker/the-api-endpoint-that-shouldnt-have-exposed-50-000-user-records-4b29b9f20df2?source=rss------bug_bounty-5)
I had been testing this e-commerce platform for almost eight hours straight.
No XSS. No SQL injection. No…Continue reading on Medium » (https://medium.com/@abdulbarhacker/the-api-endpoint-that-shouldnt-have-exposed-50-000-user-records-4b29b9f20df2?source=rss------bug_bounty-5)
How a Public readme.txt Led to a Critical WordPress CVE
https://samael0x4.medium.com/how-a-public-readme-txt-led-to-a-critical-wordpress-cve-dc8776454011?source=rss------bug_bounty-5
https://samael0x4.medium.com/how-a-public-readme-txt-led-to-a-critical-wordpress-cve-dc8776454011?source=rss------bug_bounty-5
Sometimes the most critical vulnerabilities don’t start with complex payloads, fuzzers, or zero‑day chains.Continue reading on Medium » (https://samael0x4.medium.com/how-a-public-readme-txt-led-to-a-critical-wordpress-cve-dc8776454011?source=rss------bug_bounty-5)
One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
https://infosecwriteups.com/one-harmless-parameter-full-account-takeover-my-favorite-bug-bounty-find-1e4c9cf7c17d?source=rss------bug_bounty-5
https://infosecwriteups.com/one-harmless-parameter-full-account-takeover-my-favorite-bug-bounty-find-1e4c9cf7c17d?source=rss------bug_bounty-5
Hey there!😁Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/one-harmless-parameter-full-account-takeover-my-favorite-bug-bounty-find-1e4c9cf7c17d?source=rss------bug_bounty-5)
Forensics: Flag in Flame — When Logs Turn Into Images
https://medium.com/@VulnHunt3r/forensics-flag-in-flame-when-logs-turn-into-images-3fc526d0a5bf?source=rss------bug_bounty-5
https://medium.com/@VulnHunt3r/forensics-flag-in-flame-when-logs-turn-into-images-3fc526d0a5bf?source=rss------bug_bounty-5
In real-world SOC investigations, attackers often disguise malicious data as normal-looking logs.
This picoCTF challenge recreates that…Continue reading on Medium » (https://medium.com/@VulnHunt3r/forensics-flag-in-flame-when-logs-turn-into-images-3fc526d0a5bf?source=rss------bug_bounty-5)
This picoCTF challenge recreates that…Continue reading on Medium » (https://medium.com/@VulnHunt3r/forensics-flag-in-flame-when-logs-turn-into-images-3fc526d0a5bf?source=rss------bug_bounty-5)
First Pentesting
https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/
<!-- SC_OFF -->Hey folks, I’ve been given the chance to do pentesting on a web app my company is building. I’m really into cybersecurity and this feels like a big opportunity for me. The thing is… I’m kinda lost. I know the basics (OWASP Top 10, how web apps work, endpoints, etc.), but when it comes to actually doing a pentest, I freeze. I don’t really know how to turn theory into practice. It feels like I just need a push to get started and gain confidence. How did you handle your first real pentest?
Any advice on how to approach it without overthinking everything? Appreciate any tips or personal experiences. Stay safe :) <!-- SC_ON --> submitted by /u/Abject-Offer3045 (https://www.reddit.com/user/Abject-Offer3045)
[link] (https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/)
https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/
<!-- SC_OFF -->Hey folks, I’ve been given the chance to do pentesting on a web app my company is building. I’m really into cybersecurity and this feels like a big opportunity for me. The thing is… I’m kinda lost. I know the basics (OWASP Top 10, how web apps work, endpoints, etc.), but when it comes to actually doing a pentest, I freeze. I don’t really know how to turn theory into practice. It feels like I just need a push to get started and gain confidence. How did you handle your first real pentest?
Any advice on how to approach it without overthinking everything? Appreciate any tips or personal experiences. Stay safe :) <!-- SC_ON --> submitted by /u/Abject-Offer3045 (https://www.reddit.com/user/Abject-Offer3045)
[link] (https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/)
Finally built the Pentest Report Maker I wish I had as a freelancer. It’s free to try.
https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/
<!-- SC_OFF -->Hey everyone, Like many of you, I’ve spent years wrestling with broken Word templates, fixing indentation for the 100th time, and manually copy-pasting the same remediation advice for IDORs and XSS. It’s the worst part of the job. I’d rather be hacking than formatting. A few months ago, I decided to build the tool I wish I had: Atomik.sh It’s a dedicated pentest reporting platform (not just a document generator). You feed it findings (manually or from Burp/Nessus), and it spits out a clean, standardized PDF/DOCX. Core Features: No Word Styles: It handles the formatting automatically. Findings Library: Save your common write-ups (CVEs/CWEs) so you never write the same description twice. AI Assist: Uses AI to draft Executive Summaries or fix grammar in your PoCs (you have full edit control). Multi-User: Teams can collaborate on the same report. The Ask: I’m not here to sell you a subscription today. I frankly just need senior pentesters to tear this apart and tell me what sucks. Does the workflow actually save time compared to your current templates? Is the AI output useful or hallucinated garbage? What critical feature is missing? For this Subreddit: The "Community" tier is free forever (watermarked exports). However, if you want to test a clean, production-ready export, I don't want you to pay. DM me your email after you sign up, and I will manually add a "Hustle Pack" (5 clean export credits - $100 worth) to your account for free for the first 10 pentesters! I built this to solve a real pain point, and I need brutal honesty to make it indispensable. Link: https://atomik.sh (https://atomik.sh/) <!-- SC_ON --> submitted by /u/iriof23 (https://www.reddit.com/user/iriof23)
[link] (https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/)
https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/
<!-- SC_OFF -->Hey everyone, Like many of you, I’ve spent years wrestling with broken Word templates, fixing indentation for the 100th time, and manually copy-pasting the same remediation advice for IDORs and XSS. It’s the worst part of the job. I’d rather be hacking than formatting. A few months ago, I decided to build the tool I wish I had: Atomik.sh It’s a dedicated pentest reporting platform (not just a document generator). You feed it findings (manually or from Burp/Nessus), and it spits out a clean, standardized PDF/DOCX. Core Features: No Word Styles: It handles the formatting automatically. Findings Library: Save your common write-ups (CVEs/CWEs) so you never write the same description twice. AI Assist: Uses AI to draft Executive Summaries or fix grammar in your PoCs (you have full edit control). Multi-User: Teams can collaborate on the same report. The Ask: I’m not here to sell you a subscription today. I frankly just need senior pentesters to tear this apart and tell me what sucks. Does the workflow actually save time compared to your current templates? Is the AI output useful or hallucinated garbage? What critical feature is missing? For this Subreddit: The "Community" tier is free forever (watermarked exports). However, if you want to test a clean, production-ready export, I don't want you to pay. DM me your email after you sign up, and I will manually add a "Hustle Pack" (5 clean export credits - $100 worth) to your account for free for the first 10 pentesters! I built this to solve a real pain point, and I need brutal honesty to make it indispensable. Link: https://atomik.sh (https://atomik.sh/) <!-- SC_ON --> submitted by /u/iriof23 (https://www.reddit.com/user/iriof23)
[link] (https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/)
They Called It Luck — So NASA Did It Again
https://medium.com/@ninadgowda777/they-called-it-luck-so-nasa-did-it-again-0146179622a5?source=rss------bug_bounty-5
https://medium.com/@ninadgowda777/they-called-it-luck-so-nasa-did-it-again-0146179622a5?source=rss------bug_bounty-5
by Ninad GowdaContinue reading on Medium » (https://medium.com/@ninadgowda777/they-called-it-luck-so-nasa-did-it-again-0146179622a5?source=rss------bug_bounty-5)
Password Reset Poisoning: Receiving the Same Reset Link in My Inbox
A short walkthrough on how experimenting with request structures led to observing a password reset poisoning behavior.Continue reading on Medium »
Read more...
A short walkthrough on how experimenting with request structures led to observing a password reset poisoning behavior.Continue reading on Medium »
Read more...
Medium
Password Reset Poisoning: Receiving the Same Reset Link in My Inbox
A short walkthrough on how experimenting with request structures led to observing a password reset poisoning behavior.