One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🎯 One “Harmless” Parameter, Full Account Takeover — My Favorite Bug Bounty Find
Hey there!😁
The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal…
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…Continue reading on Medium »
Read more...
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…Continue reading on Medium »
Read more...
Medium
🧪 The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal Server Details
There’s a specific kind of vulnerability that feels almost nostalgic. Something from the early days of PHP. Something every pentester…
The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium »
Read more...
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium »
Read more...
Medium
🔀 The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
Some vulnerabilities feel small at first glance — almost too simple to matter.
What's a goldmine github project you found?
https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/
submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/)
https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/
submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqfq1x/whats_a_goldmine_github_project_you_found/)
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
Origination:- Cyber LeelawatContinue reading on Medium »
Read more...
Origination:- Cyber LeelawatContinue reading on Medium »
Read more...
Medium
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
Origination:- Cyber Leelawat
How I Found a $8,560 Password Reset Bug
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium »
Read more...
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium »
Read more...
Medium
How I Found a $8,560 Password Reset Bug
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)
The phpinfo() Page That Shouldn’t Have Been There — And How It Exposed NykaaMan’s Internal…
https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5
There’s a specific kind of vulnerability that feels almost nostalgic.
Something from the early days of PHP.
Something every pentester…Continue reading on Medium » (https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5
There’s a specific kind of vulnerability that feels almost nostalgic.
Something from the early days of PHP.
Something every pentester…Continue reading on Medium » (https://medium.com/@anshubind89/the-phpinfo-page-that-shouldnt-have-been-there-and-how-it-exposed-nykaaman-s-internal-ee5f6e568159?source=rss------bug_bounty-5)
The Open Redirect That Could Turn a Trusted URL Into a Weapon — A Bug Hunting Story
https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium » (https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5)
https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5
Some vulnerabilities feel small at first glance — almost too simple to matter.Continue reading on Medium » (https://medium.com/@anshubind89/the-open-redirect-that-could-turn-a-trusted-url-into-a-weapon-a-bug-hunting-story-c01e47e5ab3a?source=rss------bug_bounty-5)
CVE-2025–20393 (Cisco AsyncOS Zero-Day)
https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5
https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5
Origination:- Cyber LeelawatContinue reading on Medium » (https://cyberleelawat.medium.com/cve-2025-20393-cisco-asyncos-zero-day-72b35798cdf9?source=rss------bug_bounty-5)
How I Found a $8,560 Password Reset Bug
https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5
https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5
How a Hidden API Endpoint Allowed an $8,560 Authentication Bypass and Full Account Takeover (A Bug Bounty Case Study)Continue reading on Medium » (https://medium.com/@codii/how-i-found-a-8-560-password-reset-bug-23a5845421c9?source=rss------bug_bounty-5)
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
Introduction
How i Found Easy ₹5,000 IDOR | Bug Bounty Writeup | P3
https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5
https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@rajankumarbarik143/how-i-found-easy-5-000-idor-bug-bounty-writeup-p3-27348656c4cd?source=rss------bug_bounty-5)
Outlawed / Banned from the Fraudulent Bug Bounty World: The Story of Cyber Kalki
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Medium
Outlawed / Banned from the Fraudulent Bug Bounty World: The Story of Cyber Kalki
Outlawed / Banned from the Fraudulent Bug Bounty World: The Story of Cyber Kalki In the fast-paced world of ethical hacking, few names stir controversy like Cyber Kalki. An independent researcher …
# The Quiet Bugs That Don’t Look Like Bugs
# Lessons from 3–4 Years in CybersecurityContinue reading on Medium »
Read more...
# Lessons from 3–4 Years in CybersecurityContinue reading on Medium »
Read more...
Medium
# The Quiet Bugs That Don’t Look Like Bugs
# Lessons from 3–4 Years in Cybersecurity
Recon Fatigue Is Real — Until This One URL Paid My Rent
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Medium
🔍💸 Recon Fatigue Is Real — Until This One URL Paid My Rent
Hey there!😁