<!-- SC_OFF -->Killer price for a good quality cert, praised by many and the next one im tackling. <!-- SC_ON --> submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://i.redd.it/40zn2v4etz7g1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppvsus/pnpt_on_sale/)
[link] (https://i.redd.it/40zn2v4etz7g1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppvsus/pnpt_on_sale/)
Unpopular opinion: Gemini is actually good at pentesting
https://www.reddit.com/r/Pentesting/comments/1ppxbyx/unpopular_opinion_gemini_is_actually_good_at/
<!-- SC_OFF -->I am a junior pentester, I've worked at the cybersecurity field for couple of years doing all sorts of things, but actually pentesting for 3 months. For the past couple of months I've used ChatGPT, Though something was off, besides always telling me "I can't help you with that... bla bla", He just didn't help at all, only making things more confusing. I switched to Gemini about a month ago, and it’s been a total game-changer. It’s helped me spot bugs I honestly would’ve walked right past. It’s become a huge part of my workflow, not just for generating solid payloads on the fly (Yes I do tempt to sometimes take the easy way and copy paste payloads), but for actually breaking down new technologies I haven't seen before. It rarely hits me with those 'I can’t help' blocks, so I can actually focus on the work instead of fighting the AI. I feel it has become a partner of mine while researching. That's it, just wanted to share my thoughts. <!-- SC_ON --> submitted by /u/AdFlashy6158 (https://www.reddit.com/user/AdFlashy6158)
[link] (https://www.reddit.com/r/Pentesting/comments/1ppxbyx/unpopular_opinion_gemini_is_actually_good_at/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppxbyx/unpopular_opinion_gemini_is_actually_good_at/)
https://www.reddit.com/r/Pentesting/comments/1ppxbyx/unpopular_opinion_gemini_is_actually_good_at/
<!-- SC_OFF -->I am a junior pentester, I've worked at the cybersecurity field for couple of years doing all sorts of things, but actually pentesting for 3 months. For the past couple of months I've used ChatGPT, Though something was off, besides always telling me "I can't help you with that... bla bla", He just didn't help at all, only making things more confusing. I switched to Gemini about a month ago, and it’s been a total game-changer. It’s helped me spot bugs I honestly would’ve walked right past. It’s become a huge part of my workflow, not just for generating solid payloads on the fly (Yes I do tempt to sometimes take the easy way and copy paste payloads), but for actually breaking down new technologies I haven't seen before. It rarely hits me with those 'I can’t help' blocks, so I can actually focus on the work instead of fighting the AI. I feel it has become a partner of mine while researching. That's it, just wanted to share my thoughts. <!-- SC_ON --> submitted by /u/AdFlashy6158 (https://www.reddit.com/user/AdFlashy6158)
[link] (https://www.reddit.com/r/Pentesting/comments/1ppxbyx/unpopular_opinion_gemini_is_actually_good_at/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppxbyx/unpopular_opinion_gemini_is_actually_good_at/)
Switching career (question)
https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/
<!-- SC_OFF -->I have prior experience in sales, psychology, marketing, copywriting... You name it. The good old corporate life. Basically legally scamming people already to some moral extent. I don't have a CS degree but know my way around coding and terminals since my dad put linux on everything in our house since I was 11, only god knows why. Anyway, thanks dad Is there a way to get into pentesting, focusing on social engineering? Or it's almost impossible for someone like me (outside the CS enviroment) to get into pentesting? I've been studying the basics of networking and protocols for the past month or two. Social engineering seems very important to me. I wonder if companies are into that, or they just look for pure CS skills. Sorry if this is an obvious question, curious to see what actual pentesters think. <!-- SC_ON --> submitted by /u/Pyrotheman-e (https://www.reddit.com/user/Pyrotheman-e)
[link] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/)
https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/
<!-- SC_OFF -->I have prior experience in sales, psychology, marketing, copywriting... You name it. The good old corporate life. Basically legally scamming people already to some moral extent. I don't have a CS degree but know my way around coding and terminals since my dad put linux on everything in our house since I was 11, only god knows why. Anyway, thanks dad Is there a way to get into pentesting, focusing on social engineering? Or it's almost impossible for someone like me (outside the CS enviroment) to get into pentesting? I've been studying the basics of networking and protocols for the past month or two. Social engineering seems very important to me. I wonder if companies are into that, or they just look for pure CS skills. Sorry if this is an obvious question, curious to see what actual pentesters think. <!-- SC_ON --> submitted by /u/Pyrotheman-e (https://www.reddit.com/user/Pyrotheman-e)
[link] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/)
Buried in JavaScript: How One Comment Led Me to a Production API Key
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Buried in JavaScript: How One Comment Led Me to a Production API Key 💻🔑
Free Link 🎈
One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🎯 One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
Hey there!😁
The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal…
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…Continue reading on Medium »
Read more...
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…Continue reading on Medium »
Read more...
Medium
🧪 The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal Server Details
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…
The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium »
Read more...
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium »
Read more...
Medium
🔀 The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
Some vulnerabilities feel small at first glance — almost too simple to matter.
What's a goldmine github project you found?
https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/
submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/)
https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/
submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/)
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
Origination:- Cyber LeelawatContinue reading on Medium »
Read more...
Origination:- Cyber LeelawatContinue reading on Medium »
Read more...
Medium
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
Origination:- Cyber Leelawat
How I Found a $8,560 Password Reset Bug
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium »
Read more...
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium »
Read more...
Medium
How I Found a $8,560 Password Reset Bug
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)
The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal…
https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5
There’s a specific kind of vulnerability that feels almost nostalgic.
Something from the early days of PHP.
Something every pentester…Continue reading on Medium » (https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5
There’s a specific kind of vulnerability that feels almost nostalgic.
Something from the early days of PHP.
Something every pentester…Continue reading on Medium » (https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5)
The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium » (https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium » (https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5)
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5
https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5
Origination:- Cyber LeelawatContinue reading on Medium » (https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5)
How I Found a $8,560 Password Reset Bug
https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5
https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium » (https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5)
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
Introduction
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5
https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5