How often do you actually get root access or get into an internal network?
https://www.reddit.com/r/Pentesting/comments/1rblo1g/how_often_do_you_actually_get_root_access_or_get/
<!-- SC_OFF -->Currently taking the eJPTv2 course, and I started learning pivoting and routing into internal devices (after you get the initial access from the public-facing server). That made me wonder, how often do pentesters actually get into a webserver and start pivoting? I feel like (based on what I see/hear in bug bounties) most pentest reports are about XSS, information disclosure vulnerabilities, data leak stuff, and so on, without it ever resulting into actual user-level access and PE. <!-- SC_ON --> submitted by /u/AWS_0 (https://www.reddit.com/user/AWS_0)
[link] (https://www.reddit.com/r/Pentesting/comments/1rblo1g/how_often_do_you_actually_get_root_access_or_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/1rblo1g/how_often_do_you_actually_get_root_access_or_get/)
https://www.reddit.com/r/Pentesting/comments/1rblo1g/how_often_do_you_actually_get_root_access_or_get/
<!-- SC_OFF -->Currently taking the eJPTv2 course, and I started learning pivoting and routing into internal devices (after you get the initial access from the public-facing server). That made me wonder, how often do pentesters actually get into a webserver and start pivoting? I feel like (based on what I see/hear in bug bounties) most pentest reports are about XSS, information disclosure vulnerabilities, data leak stuff, and so on, without it ever resulting into actual user-level access and PE. <!-- SC_ON --> submitted by /u/AWS_0 (https://www.reddit.com/user/AWS_0)
[link] (https://www.reddit.com/r/Pentesting/comments/1rblo1g/how_often_do_you_actually_get_root_access_or_get/) [comments] (https://www.reddit.com/r/Pentesting/comments/1rblo1g/how_often_do_you_actually_get_root_access_or_get/)
Advice Needed
https://www.reddit.com/r/Pentesting/comments/1rblymv/advice_needed/
<!-- SC_OFF -->Hey guys, I’ve just accepted a 6-month internship as a pentester at a quant company. For context, I recently passed the PNPT and I’m currently working through the HTB Academy CPTS modules while preparing for the OSCP. I’ve also been doing HTB boxes regularly. Recently, I tried doing some CVE hunting on an open-source CMS, and honestly I felt a bit lost. Do you have any tips on how I can better prepare for the internship and improve in general? Especially in terms of building more confidence and methodology with real-world testing and research. <!-- SC_ON --> submitted by /u/Dramatic_Fix5116 (https://www.reddit.com/user/Dramatic_Fix5116)
[link] (https://www.reddit.com/r/Pentesting/comments/1rblymv/advice_needed/) [comments] (https://www.reddit.com/r/Pentesting/comments/1rblymv/advice_needed/)
https://www.reddit.com/r/Pentesting/comments/1rblymv/advice_needed/
<!-- SC_OFF -->Hey guys, I’ve just accepted a 6-month internship as a pentester at a quant company. For context, I recently passed the PNPT and I’m currently working through the HTB Academy CPTS modules while preparing for the OSCP. I’ve also been doing HTB boxes regularly. Recently, I tried doing some CVE hunting on an open-source CMS, and honestly I felt a bit lost. Do you have any tips on how I can better prepare for the internship and improve in general? Especially in terms of building more confidence and methodology with real-world testing and research. <!-- SC_ON --> submitted by /u/Dramatic_Fix5116 (https://www.reddit.com/user/Dramatic_Fix5116)
[link] (https://www.reddit.com/r/Pentesting/comments/1rblymv/advice_needed/) [comments] (https://www.reddit.com/r/Pentesting/comments/1rblymv/advice_needed/)
How a Small Validation Bypass Enabled Invisible Identities
https://medium.com/@eng.mahmoudbughunter/how-a-small-validation-bypass-enabled-invisible-identities-cc600577b98d?source=rss------bug_bounty-5
https://medium.com/@eng.mahmoudbughunter/how-a-small-validation-bypass-enabled-invisible-identities-cc600577b98d?source=rss------bug_bounty-5
الحمد لله والصلاة والسلام على رسول الله وعلى آله وصحبه أما بعدContinue reading on Medium » (https://medium.com/@eng.mahmoudbughunter/how-a-small-validation-bypass-enabled-invisible-identities-cc600577b98d?source=rss------bug_bounty-5)
Chaining Bugs for Critical Impact: From Missing Rate Limit to Persistent ATO
https://medium.com/@k4r33m/chaining-bugs-for-critical-impact-from-missing-rate-limit-to-persistent-ato-7b856bfe20d7?source=rss------bug_bounty-5
When testing the authentication workflow of domain.tld, what started as a standard brute-force vulnerability quickly escalated into a…Continue reading on Medium » (https://medium.com/@k4r33m/chaining-bugs-for-critical-impact-from-missing-rate-limit-to-persistent-ato-7b856bfe20d7?source=rss------bug_bounty-5)
https://medium.com/@k4r33m/chaining-bugs-for-critical-impact-from-missing-rate-limit-to-persistent-ato-7b856bfe20d7?source=rss------bug_bounty-5
When testing the authentication workflow of domain.tld, what started as a standard brute-force vulnerability quickly escalated into a…Continue reading on Medium » (https://medium.com/@k4r33m/chaining-bugs-for-critical-impact-from-missing-rate-limit-to-persistent-ato-7b856bfe20d7?source=rss------bug_bounty-5)
Escalating a Duplicate Finding to a CVSS 10.0: Chaining Logic and Session Flaws for Persistent ATO
In bug bounty and penetration testing, a “duplicate” finding is often viewed as a dead end.Continue reading on Medium »
Read more...
In bug bounty and penetration testing, a “duplicate” finding is often viewed as a dead end.Continue reading on Medium »
Read more...
Medium
Escalating a Duplicate Finding to a CVSS 10.0: Chaining Logic and Session Flaws for Persistent ATO
In bug bounty and penetration testing, a “duplicate” finding is often viewed as a dead end. However, a duplicate bug is essentially a known…
Double Compromise: Unearthing Unauthenticated SSRF and Weaponized XSS on Legacy Oracle…
When assessing enterprise perimeters, legacy subdomains often hide complex architectural flaws. During a recent engagement targeting a…Continue reading on Medium »
Read more...
When assessing enterprise perimeters, legacy subdomains often hide complex architectural flaws. During a recent engagement targeting a…Continue reading on Medium »
Read more...
Medium
Double Compromise: Unearthing Unauthenticated SSRF and Weaponized XSS on Legacy Oracle Infrastructure
When assessing enterprise perimeters, legacy subdomains often hide complex architectural flaws. During a recent engagement targeting a…
Mining Wayback URLs for High-Impact Vulnerability Discovery
Hi everyone, let me start with a simple question.Continue reading on Medium »
Read more...
Hi everyone, let me start with a simple question.Continue reading on Medium »
Read more...
Medium
Mining Wayback URLs for High-Impact Vulnerability Discovery
Hi everyone, let me start with a simple question.
Full Organization Account Takeover (ATO) by Changing One Parameter
Sometimes, hacking is not about complex payloads.Continue reading on Medium »
Read more...
Sometimes, hacking is not about complex payloads.Continue reading on Medium »
Read more...
Medium
Full Organization Account Takeover (ATO) by Changing One Parameter
Sometimes, hacking is not about complex payloads.
How I Found a Business Logic Vulnerability in SaaS applicationThat Allowed Unlimited Trial…
Hey everyone, I’m Sreejith, a security researcher.Continue reading on Medium »
Read more...
Hey everyone, I’m Sreejith, a security researcher.Continue reading on Medium »
Read more...
Medium
How I Found a Business Logic Vulnerability in SaaS applicationThat Allowed Unlimited Trial…
Hey everyone, I’m Sreejith, a security researcher. In this writeup I’ll walk you through how I discovered a business logic vulnerability in…
Double Compromise: Unearthing Unauthenticated SSRF and Weaponized XSS on Legacy Oracle…
https://medium.com/@k4r33m/double-compromise-unearthing-unauthenticated-ssrf-and-weaponized-xss-on-legacy-oracle-d41ed9f7f7b8?source=rss------bug_bounty-5
When assessing enterprise perimeters, legacy subdomains often hide complex architectural flaws. During a recent engagement targeting a…Continue reading on Medium » (https://medium.com/@k4r33m/double-compromise-unearthing-unauthenticated-ssrf-and-weaponized-xss-on-legacy-oracle-d41ed9f7f7b8?source=rss------bug_bounty-5)
https://medium.com/@k4r33m/double-compromise-unearthing-unauthenticated-ssrf-and-weaponized-xss-on-legacy-oracle-d41ed9f7f7b8?source=rss------bug_bounty-5
When assessing enterprise perimeters, legacy subdomains often hide complex architectural flaws. During a recent engagement targeting a…Continue reading on Medium » (https://medium.com/@k4r33m/double-compromise-unearthing-unauthenticated-ssrf-and-weaponized-xss-on-legacy-oracle-d41ed9f7f7b8?source=rss------bug_bounty-5)
Mining Wayback URLs for High-Impact Vulnerability Discovery
https://medium.com/@nitinsgavane/mining-wayback-urls-for-high-impact-vulnerability-discovery-dfa6ebbe63aa?source=rss------bug_bounty-5
https://medium.com/@nitinsgavane/mining-wayback-urls-for-high-impact-vulnerability-discovery-dfa6ebbe63aa?source=rss------bug_bounty-5
Hi everyone, let me start with a simple question.Continue reading on Medium » (https://medium.com/@nitinsgavane/mining-wayback-urls-for-high-impact-vulnerability-discovery-dfa6ebbe63aa?source=rss------bug_bounty-5)
Full Organization Account Takeover (ATO) by Changing One Parameter
https://medium.com/@2os5/full-organization-account-takeover-ato-by-changing-one-parameter-9f67472d3138?source=rss------bug_bounty-5
https://medium.com/@2os5/full-organization-account-takeover-ato-by-changing-one-parameter-9f67472d3138?source=rss------bug_bounty-5
Sometimes, hacking is not about complex payloads.Continue reading on Medium » (https://medium.com/@2os5/full-organization-account-takeover-ato-by-changing-one-parameter-9f67472d3138?source=rss------bug_bounty-5)
How I Found a Business Logic Vulnerability in SaaS applicationThat Allowed Unlimited Trial…
https://medium.com/@sreejihkn43073/how-i-found-a-business-logic-vulnerability-in-saas-applicationthat-allowed-unlimited-trial-3f680a38f372?source=rss------bug_bounty-5
https://medium.com/@sreejihkn43073/how-i-found-a-business-logic-vulnerability-in-saas-applicationthat-allowed-unlimited-trial-3f680a38f372?source=rss------bug_bounty-5
Hey everyone, I’m Sreejith, a security researcher.Continue reading on Medium » (https://medium.com/@sreejihkn43073/how-i-found-a-business-logic-vulnerability-in-saas-applicationthat-allowed-unlimited-trial-3f680a38f372?source=rss------bug_bounty-5)