Switching career (question)
https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/
<!-- SC_OFF -->I have prior experience in sales, psychology, marketing, copywriting... You name it. The good old corporate life. Basically legally scamming people already to some moral extent. I don't have a CS degree but know my way around coding and terminals since my dad put linux on everything in our house since I was 11, only god knows why. Anyway, thanks dad Is there a way to get into pentesting, focusing on social engineering? Or it's almost impossible for someone like me (outside the CS enviroment) to get into pentesting? I've been studying the basics of networking and protocols for the past month or two. Social engineering seems very important to me. I wonder if companies are into that, or they just look for pure CS skills. Sorry if this is an obvious question, curious to see what actual pentesters think. <!-- SC_ON --> submitted by /u/Pyrotheman-e (https://www.reddit.com/user/Pyrotheman-e)
[link] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/)
https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/
<!-- SC_OFF -->I have prior experience in sales, psychology, marketing, copywriting... You name it. The good old corporate life. Basically legally scamming people already to some moral extent. I don't have a CS degree but know my way around coding and terminals since my dad put linux on everything in our house since I was 11, only god knows why. Anyway, thanks dad Is there a way to get into pentesting, focusing on social engineering? Or it's almost impossible for someone like me (outside the CS enviroment) to get into pentesting? I've been studying the basics of networking and protocols for the past month or two. Social engineering seems very important to me. I wonder if companies are into that, or they just look for pure CS skills. Sorry if this is an obvious question, curious to see what actual pentesters think. <!-- SC_ON --> submitted by /u/Pyrotheman-e (https://www.reddit.com/user/Pyrotheman-e)
[link] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ppzcp4/switching_career_question/)
Buried in JavaScript: How One Comment Led Me to a Production API Key
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Medium
Buried in JavaScript: How One Comment Led Me to a Production API Key 💻🔑
Free Link 🎈
One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🎯 One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
Hey there!😁
The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal…
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…Continue reading on Medium »
Read more...
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…Continue reading on Medium »
Read more...
Medium
🧪 The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal Server Details
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…
The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium »
Read more...
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium »
Read more...
Medium
🔀 The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
Some vulnerabilities feel small at first glance — almost too simple to matter.
What's a goldmine github project you found?
https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/
submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/)
https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/
submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/)
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
Origination:- Cyber LeelawatContinue reading on Medium »
Read more...
Origination:- Cyber LeelawatContinue reading on Medium »
Read more...
Medium
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
Origination:- Cyber Leelawat
How I Found a $8,560 Password Reset Bug
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium »
Read more...
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium »
Read more...
Medium
How I Found a $8,560 Password Reset Bug
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)
The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal…
https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5
There’s a specific kind of vulnerability that feels almost nostalgic.
Something from the early days of PHP.
Something every pentester…Continue reading on Medium » (https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5
There’s a specific kind of vulnerability that feels almost nostalgic.
Something from the early days of PHP.
Something every pentester…Continue reading on Medium » (https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5)
The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium » (https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium » (https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5)
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5
https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5
Origination:- Cyber LeelawatContinue reading on Medium » (https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5)
How I Found a $8,560 Password Reset Bug
https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5
https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium » (https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5)
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
Introduction
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5
https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5)
Outlawed / Banned from the Fraudulent Bug Bounty World: The Story of Cyber Kalki
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Medium
Outlawed / Banned from the Fraudulent Bug Bounty World: The Story of Cyber Kalki
Outlawed / Banned from the Fraudulent Bug Bounty World: The Story of Cyber Kalki In the fast-paced world of ethical hacking, few names stir controversy like Cyber Kalki. An independent researcher …