# Lessons from 3–4 Years in CybersecurityContinue reading on Medium » (https://medium.com/@abdulbarhacker/the-quiet-bugs-that-dont-look-like-bugs-c38c7db08364?source=rss------bug_bounty-5)
Recon Fatigue Is Real — Until This One URL Paid My Rent
https://infosecwriteups.com/recon-fatigue-is-real-until-this-one-url-paid-my-rent-8768a51dc50e?source=rss------bug_bounty-5
https://infosecwriteups.com/recon-fatigue-is-real-until-this-one-url-paid-my-rent-8768a51dc50e?source=rss------bug_bounty-5
Hey there!😁Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/recon-fatigue-is-real-until-this-one-url-paid-my-rent-8768a51dc50e?source=rss------bug_bounty-5)
CVE-2025–67418: When Default Credentials Become a Remote Root Button
https://medium.com/@arpit03sharma2003/cve-2025-67418-when-default-credentials-become-a-remote-root-button-03be5ee4b927?source=rss------bug_bounty-5
How Improper Access Control in ClipBucket Led to Full Administrative CompromiseContinue reading on Medium » (https://medium.com/@arpit03sharma2003/cve-2025-67418-when-default-credentials-become-a-remote-root-button-03be5ee4b927?source=rss------bug_bounty-5)
https://medium.com/@arpit03sharma2003/cve-2025-67418-when-default-credentials-become-a-remote-root-button-03be5ee4b927?source=rss------bug_bounty-5
How Improper Access Control in ClipBucket Led to Full Administrative CompromiseContinue reading on Medium » (https://medium.com/@arpit03sharma2003/cve-2025-67418-when-default-credentials-become-a-remote-root-button-03be5ee4b927?source=rss------bug_bounty-5)
Information disclosure, but not in the way you might expect
https://medium.com/@rajveer_0101/information-disclosure-but-not-in-the-way-you-might-expect-a914479e06cc?source=rss------bug_bounty-5
https://medium.com/@rajveer_0101/information-disclosure-but-not-in-the-way-you-might-expect-a914479e06cc?source=rss------bug_bounty-5
“This write-up highlights the importance of not overlooking any response and how it can sometimes earn you a bounty.”Continue reading on Medium » (https://medium.com/@rajveer_0101/information-disclosure-but-not-in-the-way-you-might-expect-a914479e06cc?source=rss------bug_bounty-5)
How I Found an Unauthenticated XXE That Allowed Arbitrary File Read in NASA
Recently, I uncovered a critical (P1) XXE vulnerability that allowed to read arbitrary files on the server.Continue reading on Medium »
Read more...
Recently, I uncovered a critical (P1) XXE vulnerability that allowed to read arbitrary files on the server.Continue reading on Medium »
Read more...
Medium
How I Found an Unauthenticated XXE That Allowed Arbitrary File Read in NASA
Recently, I uncovered a critical (P1) XXE vulnerability that allowed to read arbitrary files on the server.
Full stack development
https://www.reddit.com/r/Pentesting/comments/1pqk16c/full_stack_development/
<!-- SC_OFF -->Would learning and build a full stack project make me a better ethical hacker? <!-- SC_ON --> submitted by /u/Fizzedine (https://www.reddit.com/user/Fizzedine)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqk16c/full_stack_development/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqk16c/full_stack_development/)
https://www.reddit.com/r/Pentesting/comments/1pqk16c/full_stack_development/
<!-- SC_OFF -->Would learning and build a full stack project make me a better ethical hacker? <!-- SC_ON --> submitted by /u/Fizzedine (https://www.reddit.com/user/Fizzedine)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqk16c/full_stack_development/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqk16c/full_stack_development/)
ATmega32U4 on Mac
https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/
<!-- SC_OFF -->I've been creating some scripts for an ATmega32U4 for keystroke injection on Windows and Mac for work. The only problem is that on Mac, it tries to do the keyboard setup process because it is not an approved vendor keyboard. Is there a way to update the firmware so that when I plug it in the VID and PID display as an approved / apple keyboard? <!-- SC_ON --> submitted by /u/West_Atmosphere_9601 (https://www.reddit.com/user/West_Atmosphere_9601)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/)
https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/
<!-- SC_OFF -->I've been creating some scripts for an ATmega32U4 for keystroke injection on Windows and Mac for work. The only problem is that on Mac, it tries to do the keyboard setup process because it is not an approved vendor keyboard. Is there a way to update the firmware so that when I plug it in the VID and PID display as an approved / apple keyboard? <!-- SC_ON --> submitted by /u/West_Atmosphere_9601 (https://www.reddit.com/user/West_Atmosphere_9601)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqp2c6/atmega32u4_on_mac/)
GitHub - l4rm4nd/IKESS: A Python3 Script for Auditing IKE VPN Servers
https://www.reddit.com/r/Pentesting/comments/1pqrk37/github_l4rm4ndikess_a_python3_script_for_auditing/
https://www.reddit.com/r/Pentesting/comments/1pqrk37/github_l4rm4ndikess_a_python3_script_for_auditing/
OSCP in 3 years?
https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/
<!-- SC_OFF -->For context, I'm starting my first semester of CS after switching from mechanical engineering next semester. I'm committed to collecting certifications and getting experience before graduation (which will be in 2.5-3 years). My "end goal" is OSCP. If I can graduate with OSCP, I'll be satisfied. I'm new to this field, and I'd like to know how much time is needed to get OSCP from scratch. I'm almost starting from scratch (I started THM 2-3 weeks ago, and started studying for Security+ recently). Is 3 years too ambitious? Or am I being dramatic? I want a general idea of how long it'll take to get to OSCP level. Looking work my way up with certifications in the following order: CompTIA Security+ eJPTv2 PJPT PNPT CEH OSCP+ Some of them will be either fully paid or partially paid by external entities. Is this feasible? Or am I setting myself up for failure/burnout? I feel bitter about "losing" the progress I made in engineering, so I'm determined to work hard and make up for it. <!-- SC_ON --> submitted by /u/AWS_0 (https://www.reddit.com/user/AWS_0)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/)
https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/
<!-- SC_OFF -->For context, I'm starting my first semester of CS after switching from mechanical engineering next semester. I'm committed to collecting certifications and getting experience before graduation (which will be in 2.5-3 years). My "end goal" is OSCP. If I can graduate with OSCP, I'll be satisfied. I'm new to this field, and I'd like to know how much time is needed to get OSCP from scratch. I'm almost starting from scratch (I started THM 2-3 weeks ago, and started studying for Security+ recently). Is 3 years too ambitious? Or am I being dramatic? I want a general idea of how long it'll take to get to OSCP level. Looking work my way up with certifications in the following order: CompTIA Security+ eJPTv2 PJPT PNPT CEH OSCP+ Some of them will be either fully paid or partially paid by external entities. Is this feasible? Or am I setting myself up for failure/burnout? I feel bitter about "losing" the progress I made in engineering, so I'm determined to work hard and make up for it. <!-- SC_ON --> submitted by /u/AWS_0 (https://www.reddit.com/user/AWS_0)
[link] (https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqt3yf/oscp_in_3_years/)
submitted by /u/sk1nT7 (https://www.reddit.com/user/sk1nT7)
[link] (https://github.com/l4rm4nd/IKESS) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqrk37/github_l4rm4ndikess_a_python3_script_for_auditing/)
[link] (https://github.com/l4rm4nd/IKESS) [comments] (https://www.reddit.com/r/Pentesting/comments/1pqrk37/github_l4rm4ndikess_a_python3_script_for_auditing/)
Analysis of Sensitive Information Vulnerability in Public XML Files
Case Study: WordPress MisconfigurationContinue reading on Medium »
Read more...
Case Study: WordPress MisconfigurationContinue reading on Medium »
Read more...
Medium
Analysis of Sensitive Information Vulnerability in Public XML Files
Case Study: WordPress Misconfiguration
Improper SVG Handling in AI Generated Output
بسم الله الرحمن الرحيمContinue reading on Medium »
Read more...
بسم الله الرحمن الرحيمContinue reading on Medium »
Read more...
Medium
Improper SVG Handling in AI Generated Output
بسم الله الرحمن الرحيم
How I Found an Unauthenticated XXE That Allowed Arbitrary File Read in NASA
https://medium.com/@thomscoder/how-i-found-an-unauthenticated-xxe-that-allowed-arbitrary-file-read-in-nasa-bfffe24dc24e?source=rss------bug_bounty-5
https://medium.com/@thomscoder/how-i-found-an-unauthenticated-xxe-that-allowed-arbitrary-file-read-in-nasa-bfffe24dc24e?source=rss------bug_bounty-5
Recently, I uncovered a critical (P1) XXE vulnerability that allowed to read arbitrary files on the server.Continue reading on Medium » (https://medium.com/@thomscoder/how-i-found-an-unauthenticated-xxe-that-allowed-arbitrary-file-read-in-nasa-bfffe24dc24e?source=rss------bug_bounty-5)
Unauthorized access to any presentation at Dropbox
https://medium.com/@0xRaccoon/unauthorized-access-to-any-presentation-at-dropbox-604af454547d?source=rss------bug_bounty-5
https://medium.com/@0xRaccoon/unauthorized-access-to-any-presentation-at-dropbox-604af454547d?source=rss------bug_bounty-5