How I Earned a 4-Digit Bounty: Complete Account Takeover via Insecure Session Cookie
https://adityasunny06.medium.com/how-i-earned-a-4-digit-bounty-complete-account-takeover-via-insecure-session-cookie-75d1992c9367?source=rss------bug_bounty-5
https://adityasunny06.medium.com/how-i-earned-a-4-digit-bounty-complete-account-takeover-via-insecure-session-cookie-75d1992c9367?source=rss------bug_bounty-5
TL;DR: A missing `Secure` flag on a session cookie led to a complete account takeover vulnerability on a popular AI-powered SaaS platform…Continue reading on Medium » (https://adityasunny06.medium.com/how-i-earned-a-4-digit-bounty-complete-account-takeover-via-insecure-session-cookie-75d1992c9367?source=rss------bug_bounty-5)
CRTP - how did you study?
https://www.reddit.com/r/redteamsec/comments/1qowexe/crtp_how_did_you_study/
<!-- SC_OFF -->I’m currently preparing for the CRTP certification and I’d really appreciate some advice from people who already went through it. A bit of background: I already have OSCP, so I’m comfortable with hands-on learning and lab-driven study. I’m not sure about the best approach for CRTP: • Is it better to go through all the video lessons first and then do the labs? • Or does it make more sense to alternate between video lessons and labs (study a section → do the related lab → move on)? One important thing about me: I really struggle with long video lessons — I get distracted very easily. Slides + practice work much better for me than passive watching but I’m not sure is enough. Any advice, study plans, or lessons learned from your CRTP journey would be super appreciated <!-- SC_ON --> submitted by /u/th3d4rkp4ss3ng3r (https://www.reddit.com/user/th3d4rkp4ss3ng3r)
[link] (https://www.alteredsecurity.com/crtp-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1qowexe/crtp_how_did_you_study/)
https://www.reddit.com/r/redteamsec/comments/1qowexe/crtp_how_did_you_study/
<!-- SC_OFF -->I’m currently preparing for the CRTP certification and I’d really appreciate some advice from people who already went through it. A bit of background: I already have OSCP, so I’m comfortable with hands-on learning and lab-driven study. I’m not sure about the best approach for CRTP: • Is it better to go through all the video lessons first and then do the labs? • Or does it make more sense to alternate between video lessons and labs (study a section → do the related lab → move on)? One important thing about me: I really struggle with long video lessons — I get distracted very easily. Slides + practice work much better for me than passive watching but I’m not sure is enough. Any advice, study plans, or lessons learned from your CRTP journey would be super appreciated <!-- SC_ON --> submitted by /u/th3d4rkp4ss3ng3r (https://www.reddit.com/user/th3d4rkp4ss3ng3r)
[link] (https://www.alteredsecurity.com/crtp-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1qowexe/crtp_how_did_you_study/)
GitHub - dereeqw/BlackBerryC2: Encrypted command‑and‑control (C2) research framework for cybersecurity education, red team labs, and secure client‑server communication experiments.
https://www.reddit.com/r/redteamsec/comments/1qp35jc/github_dereeqwblackberryc2_encrypted/
<!-- SC_OFF -->BlackBerryC2 v1.7 – Encrypted C2 Framework (Compiled) Encrypted Command & Control framework using AES-GCM + RSA-2048. Features: End-to-end encryption (AES-GCM + RSA-2048) TLS / HTTP / HTTPS proxy daemon & GUI Recursive file transfers with compression Anti-scan protection & IP blocking 🔗 GitHub (compiled version): https://github.com/dereeqw/BlackBerryC2 Built for security research and penetration testing. NetSpy – Encrypted C2 Framework (Source Code) Open-source C2 framework written in Python 3.3+, compatible with any system that supports Python. 🔗 GitHub (source code): https://github.com/dereeqw/NetSpy <!-- SC_ON --> submitted by /u/Key-Reserve-5645 (https://www.reddit.com/user/Key-Reserve-5645)
[link] (https://github.com/dereeqw/BlackBerryC2) [comments] (https://www.reddit.com/r/redteamsec/comments/1qp35jc/github_dereeqwblackberryc2_encrypted/)
https://www.reddit.com/r/redteamsec/comments/1qp35jc/github_dereeqwblackberryc2_encrypted/
<!-- SC_OFF -->BlackBerryC2 v1.7 – Encrypted C2 Framework (Compiled) Encrypted Command & Control framework using AES-GCM + RSA-2048. Features: End-to-end encryption (AES-GCM + RSA-2048) TLS / HTTP / HTTPS proxy daemon & GUI Recursive file transfers with compression Anti-scan protection & IP blocking 🔗 GitHub (compiled version): https://github.com/dereeqw/BlackBerryC2 Built for security research and penetration testing. NetSpy – Encrypted C2 Framework (Source Code) Open-source C2 framework written in Python 3.3+, compatible with any system that supports Python. 🔗 GitHub (source code): https://github.com/dereeqw/NetSpy <!-- SC_ON --> submitted by /u/Key-Reserve-5645 (https://www.reddit.com/user/Key-Reserve-5645)
[link] (https://github.com/dereeqw/BlackBerryC2) [comments] (https://www.reddit.com/r/redteamsec/comments/1qp35jc/github_dereeqwblackberryc2_encrypted/)
Thread-Hijack Supply Chain Phishing: Analysis of EvilProxy Campaign
https://www.reddit.com/r/redteamsec/comments/1qpa5wk/threadhijack_supply_chain_phishing_analysis_of/
<!-- SC_OFF -->TL;DR Initial access: Likely compromise of a contractor mailbox already involved in the thread, enabling conversation hijacking inside a real C-suite approval flow. Attack chain: SCA phishing email → 7x forwards → phishing link → Cloudflare Turnstile antibot page → Turnstile-protected phishing page → EvilProxy AiTM for Microsoft credential theft. Evasion: Multi-step redirects + Turnstile mean the final phishing content is only exposed during real execution, not simple URL or static checks. Detection: Behavioral detonation is required to see the full chain and confirm intent; static analysis alone is unlikely to flag it reliably. <!-- SC_ON --> submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/enterprise-email-thread-phishing/?utm_source=reddit) [comments] (https://www.reddit.com/r/redteamsec/comments/1qpa5wk/threadhijack_supply_chain_phishing_analysis_of/)
https://www.reddit.com/r/redteamsec/comments/1qpa5wk/threadhijack_supply_chain_phishing_analysis_of/
<!-- SC_OFF -->TL;DR Initial access: Likely compromise of a contractor mailbox already involved in the thread, enabling conversation hijacking inside a real C-suite approval flow. Attack chain: SCA phishing email → 7x forwards → phishing link → Cloudflare Turnstile antibot page → Turnstile-protected phishing page → EvilProxy AiTM for Microsoft credential theft. Evasion: Multi-step redirects + Turnstile mean the final phishing content is only exposed during real execution, not simple URL or static checks. Detection: Behavioral detonation is required to see the full chain and confirm intent; static analysis alone is unlikely to flag it reliably. <!-- SC_ON --> submitted by /u/malwaredetector (https://www.reddit.com/user/malwaredetector)
[link] (https://any.run/cybersecurity-blog/enterprise-email-thread-phishing/?utm_source=reddit) [comments] (https://www.reddit.com/r/redteamsec/comments/1qpa5wk/threadhijack_supply_chain_phishing_analysis_of/)
What still shows up in Windows memory after basic execution
https://www.reddit.com/r/redteamsec/comments/1qpesfw/what_still_shows_up_in_windows_memory_after_basic/
<!-- SC_OFF -->I’ve been spending some time looking at Windows memory from the other side and trying to sanity check what actually shows up after basic execution and post compromise activity. The goal wasn’t deep malware analysis or evasion research, more just understanding what artefacts are realistically visible in memory if a defender pulls a dump and starts poking around. I went through process listings, command line history, parent child relationships and a few other common areas to see what stands out quickly versus what ends up being noisy or not that useful early on. A couple of things surprised me, mainly how much context is still there even without doing anything fancy, and how easy it is to get distracted by data that looks interesting but doesn’t really move the investigation forward. This was done in a small lab rather than a hardened environment, but I’m curious how others approach this from a red team perspective. Are there particular behaviours or artefacts you deliberately try to avoid leaving behind, or do you mostly assume memory is burned once it’s captured anyway? Happy to hear how others think about this. <!-- SC_ON --> submitted by /u/Glass-Ant-6041 (https://www.reddit.com/user/Glass-Ant-6041)
[link] (https://youtu.be/BDk4YlyMRKw?si=-pK__AiJRpKBIIQN) [comments] (https://www.reddit.com/r/redteamsec/comments/1qpesfw/what_still_shows_up_in_windows_memory_after_basic/)
https://www.reddit.com/r/redteamsec/comments/1qpesfw/what_still_shows_up_in_windows_memory_after_basic/
<!-- SC_OFF -->I’ve been spending some time looking at Windows memory from the other side and trying to sanity check what actually shows up after basic execution and post compromise activity. The goal wasn’t deep malware analysis or evasion research, more just understanding what artefacts are realistically visible in memory if a defender pulls a dump and starts poking around. I went through process listings, command line history, parent child relationships and a few other common areas to see what stands out quickly versus what ends up being noisy or not that useful early on. A couple of things surprised me, mainly how much context is still there even without doing anything fancy, and how easy it is to get distracted by data that looks interesting but doesn’t really move the investigation forward. This was done in a small lab rather than a hardened environment, but I’m curious how others approach this from a red team perspective. Are there particular behaviours or artefacts you deliberately try to avoid leaving behind, or do you mostly assume memory is burned once it’s captured anyway? Happy to hear how others think about this. <!-- SC_ON --> submitted by /u/Glass-Ant-6041 (https://www.reddit.com/user/Glass-Ant-6041)
[link] (https://youtu.be/BDk4YlyMRKw?si=-pK__AiJRpKBIIQN) [comments] (https://www.reddit.com/r/redteamsec/comments/1qpesfw/what_still_shows_up_in_windows_memory_after_basic/)
Is Evilginx still good?
https://www.reddit.com/r/redteamsec/comments/1qph9zw/is_evilginx_still_good/
<!-- SC_OFF -->I’ve gone through most of the usual hardening steps: such as Cloudflare/Turnstile, removing obvious IOCs, disabling the Easter egg, and using my own wildcard cert — and I’m still having trouble getting consistent results. At this point, I can’t tell if the issue is the fact that I might need the pro version, if my phishlets are incorrect, or if most sites have simply rolled out much stronger protections overall. The only platform where I’ve had somewhat success with O365; but usually it has been hit-or-miss at best. Any insight? <!-- SC_ON --> submitted by /u/Littlemike0712 (https://www.reddit.com/user/Littlemike0712)
[link] (https://github.com/kgretzky/evilginx2) [comments] (https://www.reddit.com/r/redteamsec/comments/1qph9zw/is_evilginx_still_good/)
https://www.reddit.com/r/redteamsec/comments/1qph9zw/is_evilginx_still_good/
<!-- SC_OFF -->I’ve gone through most of the usual hardening steps: such as Cloudflare/Turnstile, removing obvious IOCs, disabling the Easter egg, and using my own wildcard cert — and I’m still having trouble getting consistent results. At this point, I can’t tell if the issue is the fact that I might need the pro version, if my phishlets are incorrect, or if most sites have simply rolled out much stronger protections overall. The only platform where I’ve had somewhat success with O365; but usually it has been hit-or-miss at best. Any insight? <!-- SC_ON --> submitted by /u/Littlemike0712 (https://www.reddit.com/user/Littlemike0712)
[link] (https://github.com/kgretzky/evilginx2) [comments] (https://www.reddit.com/r/redteamsec/comments/1qph9zw/is_evilginx_still_good/)
<!-- SC_OFF -->Hello! I created this repository with great enthusiasm, covering a wide range of topics on cybersecurity and bug hunting! Visit it and tell me what you think. If you find it useful, give me a star! I’ve just pushed a massive update to the Hacking-Cheatsheets repository. We are moving beyond network pentesting into full-scale Web Application Security. I have organized a complete methodology for Bug Hunting, covering everything from Recon to Advanced Exploitation. 🔥 New Categories Include: ✅ Automation: Nuclei, ffuf, Subfinder, Katana & more. ✅ Payloads: Quick references for XSS, SQLi, SSTI, and LFI. ✅ Advanced Techniques: WAF Bypass, HTTP Request Smuggling, Prototype Pollution & Race Conditions. ✅ Vulnerabilities: In-depth guides for IDOR, SSRF, and API Security. Whether you are hunting on HackerOne or doing a pentest, having these commands ready is a game-changer. 👇 Check it out and please drop a ⭐ STAR on the repo if you find it useful! https://github.com/Ilias1988/Hacking-Cheatsheets <!-- SC_ON --> submitted by /u/Elliot-1988 (https://www.reddit.com/user/Elliot-1988)
[link] (https://www.reddit.com/gallery/1qpa1jd) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpa1jd/bug_bounty_tutorial/)
[link] (https://www.reddit.com/gallery/1qpa1jd) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpa1jd/bug_bounty_tutorial/)
Architecting a Portable Red Team Engine
https://www.reddit.com/r/Pentesting/comments/1qpkbnp/architecting_a_portable_red_team_engine/
submitted by /u/0111001101110010 (https://www.reddit.com/user/0111001101110010)
[link] (https://www.neteye-blog.com/2026/01/architecting-a-portable-red-team-engine/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpkbnp/architecting_a_portable_red_team_engine/)
https://www.reddit.com/r/Pentesting/comments/1qpkbnp/architecting_a_portable_red_team_engine/
submitted by /u/0111001101110010 (https://www.reddit.com/user/0111001101110010)
[link] (https://www.neteye-blog.com/2026/01/architecting-a-portable-red-team-engine/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpkbnp/architecting_a_portable_red_team_engine/)
Intelbras
https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/
<!-- SC_OFF -->Prologue: I'm probably posting on the wrong subreddit, but hoping for a friendly go to /r/elsewhere (https://www.reddit.com/r/elsewhere) instead. The largest consumer brand for home security, networking, etc in Brazil is Intelbras. I myself have intelbras for my home security. Where it all began My first "hum this is odd" moment was when I noticed that I can view my cameras via the http-webview, and they'll last indefinitely as long as I don't click anything. If I click something, the "session will expire" and I'll get kicked out, but until then, I can watch the cameras until the end of time. Just not modify anything. The second clue was when I turned on a couple of PCs i keep turned off for months at a time, and on both Mac and PC, launching "Intelbras SIM Player" I got the error message "Your access credentials could not be validated.", "If you wish you continue, you will have access to your devices without being able to edit them."* Which seemingly sounds a lot like "You don't have access, but we'll let you view the cameras anyways" My motives Don't really have any. I think I'd have fun with this if it fell within my area of competence, but as it does not, I figure I'd at the very least leave the breadcrumbs for someone else who might care to. *) I have a screenshot, not that it provides anything. Didn't run wireshark or anything similar at the time to capture network traffic. Windows PC eventually got kicked out, the Macbook can still view my cameras without any login. <!-- SC_ON --> submitted by /u/EvilAndStuff492 (https://www.reddit.com/user/EvilAndStuff492)
[link] (https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/)
https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/
<!-- SC_OFF -->Prologue: I'm probably posting on the wrong subreddit, but hoping for a friendly go to /r/elsewhere (https://www.reddit.com/r/elsewhere) instead. The largest consumer brand for home security, networking, etc in Brazil is Intelbras. I myself have intelbras for my home security. Where it all began My first "hum this is odd" moment was when I noticed that I can view my cameras via the http-webview, and they'll last indefinitely as long as I don't click anything. If I click something, the "session will expire" and I'll get kicked out, but until then, I can watch the cameras until the end of time. Just not modify anything. The second clue was when I turned on a couple of PCs i keep turned off for months at a time, and on both Mac and PC, launching "Intelbras SIM Player" I got the error message "Your access credentials could not be validated.", "If you wish you continue, you will have access to your devices without being able to edit them."* Which seemingly sounds a lot like "You don't have access, but we'll let you view the cameras anyways" My motives Don't really have any. I think I'd have fun with this if it fell within my area of competence, but as it does not, I figure I'd at the very least leave the breadcrumbs for someone else who might care to. *) I have a screenshot, not that it provides anything. Didn't run wireshark or anything similar at the time to capture network traffic. Windows PC eventually got kicked out, the Macbook can still view my cameras without any login. <!-- SC_ON --> submitted by /u/EvilAndStuff492 (https://www.reddit.com/user/EvilAndStuff492)
[link] (https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qpke3r/intelbras/)
Help please
https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/
<!-- SC_OFF -->I know this subreddit its not to seek hackers for hire and such but I need desperately some help with one of my accounts on xbox, my account on xbox got hacked I didn't clicked on anything suspicious or answered a weird sms I even had the Microsoft authenticator on another phone that I don't use any more I know thats bad but I didn't know this could go so bad, and the bastard that took my account changed my email, and phone number to his even the recovery email I chatted with web support but it's not use they are telling me that my account doesn't exist anymore but friends can still see my account disconnected obviously a day ago, and also I tried signing with the mail of the hacker and it works it ask me for a password and when I click on I forget password the recovery email now it's a disposable email ending in @ polo something, and I'm at my limit now idk what else to do if anyone could help me or know something please let me know all of my 100 + games I bought with my own money it's gone <!-- SC_ON -->
[link] (https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/)
https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/
<!-- SC_OFF -->I know this subreddit its not to seek hackers for hire and such but I need desperately some help with one of my accounts on xbox, my account on xbox got hacked I didn't clicked on anything suspicious or answered a weird sms I even had the Microsoft authenticator on another phone that I don't use any more I know thats bad but I didn't know this could go so bad, and the bastard that took my account changed my email, and phone number to his even the recovery email I chatted with web support but it's not use they are telling me that my account doesn't exist anymore but friends can still see my account disconnected obviously a day ago, and also I tried signing with the mail of the hacker and it works it ask me for a password and when I click on I forget password the recovery email now it's a disposable email ending in @ polo something, and I'm at my limit now idk what else to do if anyone could help me or know something please let me know all of my 100 + games I bought with my own money it's gone <!-- SC_ON -->
[link] (https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/) [comments] (https://www.reddit.com/r/Pentesting/comments/1qprxrp/help_please/)
New rate limit bypass , other won’t say
https://medium.com/@rajanbala39/new-rate-limit-bypass-other-wont-say-086489470239?source=rss------bug_bounty-5
https://medium.com/@rajanbala39/new-rate-limit-bypass-other-wont-say-086489470239?source=rss------bug_bounty-5
Description:Continue reading on Medium » (https://medium.com/@rajanbala39/new-rate-limit-bypass-other-wont-say-086489470239?source=rss------bug_bounty-5)
AddUser-SAMR: Create local users via the SAMR API (C#, Python, Rust, Crystal implementations)
https://www.reddit.com/r/redteamsec/comments/1qq2123/addusersamr_create_local_users_via_the_samr_api_c/
submitted by /u/Rare_Bicycle_5705 (https://www.reddit.com/user/Rare_Bicycle_5705)
[link] (https://github.com/ricardojoserf/AddUser-SAMR) [comments] (https://www.reddit.com/r/redteamsec/comments/1qq2123/addusersamr_create_local_users_via_the_samr_api_c/)
https://www.reddit.com/r/redteamsec/comments/1qq2123/addusersamr_create_local_users_via_the_samr_api_c/
submitted by /u/Rare_Bicycle_5705 (https://www.reddit.com/user/Rare_Bicycle_5705)
[link] (https://github.com/ricardojoserf/AddUser-SAMR) [comments] (https://www.reddit.com/r/redteamsec/comments/1qq2123/addusersamr_create_local_users_via_the_samr_api_c/)
Zero-Day Detection Rule Builder: 12 Tools Every Cybersecurity Pro Should Master
What if I told you most data breaches start with a vulnerability no one’s even seen before? Zero-days don’t wait for patch notes. The…Continue reading on Medium »
Read more...
What if I told you most data breaches start with a vulnerability no one’s even seen before? Zero-days don’t wait for patch notes. The…Continue reading on Medium »
Read more...
Medium
Zero-Day Detection Rule Builder: 12 Tools Every Cybersecurity Pro Should Master
What if I told you most data breaches start with a vulnerability no one’s even seen before? Zero-days don’t wait for patch notes. The…
IDOR: The Easiest High-Severity Bug Most Hunters Still Miss
(Bug Bounty Tutorial Series — Part 1)Continue reading on OSINT Team »
Read more...
(Bug Bounty Tutorial Series — Part 1)Continue reading on OSINT Team »
Read more...
Medium
IDOR: The Easiest High-Severity Bug Most Hunters Still Miss
(Bug Bounty Tutorial Series — Part 1)
XBow and the “AI Takeover”: Why You Can Put Down the Goat Farming Manual
Let’s be real: we’ve all had that 3:00 AM moment. You’re staring at a target, your third empty energy drink is judging you from the desk…Continue reading on Medium »
Read more...
Let’s be real: we’ve all had that 3:00 AM moment. You’re staring at a target, your third empty energy drink is judging you from the desk…Continue reading on Medium »
Read more...
Medium
XBow and the “AI Takeover”: Why You Can Put Down the Goat Farming Manual
Let’s be real: we’ve all had that 3:00 AM moment. You’re staring at a target, your third empty energy drink is judging you from the desk…