⚙️ 01. — Username and Password Enumeration via Different Responses
Difficulty: 🟢 ApprenticeContinue reading on Medium »
Read more...
Difficulty: 🟢 ApprenticeContinue reading on Medium »
Read more...
Medium
⚙️ 01. — Username and Password Enumeration via Different Responses
Difficulty: 🟢 Apprentice
BlackField | HTB | Hard | OSCP Preparation
https://medium.com/@SilentExploit/blackfield-htb-hard-oscp-preparation-20d804a3d1de?source=rss------bug_bounty-5
https://medium.com/@SilentExploit/blackfield-htb-hard-oscp-preparation-20d804a3d1de?source=rss------bug_bounty-5
Firstly, export the machine’s IP as a variable. This means we don’t have to keep typing the IP of the target.Continue reading on Medium » (https://medium.com/@SilentExploit/blackfield-htb-hard-oscp-preparation-20d804a3d1de?source=rss------bug_bounty-5)
From Manual Testing to Automation: Burp Suite + OpenCode Setup
https://medium.com/@m1scher/from-manual-testing-to-automation-burp-suite-opencode-setup-69e4612499cb?source=rss------bug_bounty-5
https://medium.com/@m1scher/from-manual-testing-to-automation-burp-suite-opencode-setup-69e4612499cb?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@m1scher/from-manual-testing-to-automation-burp-suite-opencode-setup-69e4612499cb?source=rss------bug_bounty-5)
The “Incognito” Triage Fail: How Human Bias and Technical Ignorance Sabotage Real-World Security
https://medium.com/@Xiac0heckmate/the-incognito-triage-fail-how-human-bias-and-technical-ignorance-sabotage-real-world-security-e2cf19fc52c6?source=rss------bug_bounty-5
https://medium.com/@Xiac0heckmate/the-incognito-triage-fail-how-human-bias-and-technical-ignorance-sabotage-real-world-security-e2cf19fc52c6?source=rss------bug_bounty-5
What happens when a security researcher finds a vulnerability that affects 75% of global internet users, but the analyst tries to…Continue reading on Medium » (https://medium.com/@Xiac0heckmate/the-incognito-triage-fail-how-human-bias-and-technical-ignorance-sabotage-real-world-security-e2cf19fc52c6?source=rss------bug_bounty-5)
I Stopped Chasing Tools And Started Finding Vulnerabilities
https://medium.com/illumination/i-stopped-chasing-tools-and-started-finding-vulnerabilities-427a82375076?source=rss------bug_bounty-5
https://medium.com/illumination/i-stopped-chasing-tools-and-started-finding-vulnerabilities-427a82375076?source=rss------bug_bounty-5
My scanner collection was impressive. My finding record was embarrassing.Continue reading on ILLUMINATION » (https://medium.com/illumination/i-stopped-chasing-tools-and-started-finding-vulnerabilities-427a82375076?source=rss------bug_bounty-5)
Easiest Zero-click Account Takeover you’ll ever find
https://medium.com/@prayerskhristi/easiest-zero-click-account-takeover-youll-ever-find-5911b4ae3114?source=rss------bug_bounty-5
https://medium.com/@prayerskhristi/easiest-zero-click-account-takeover-youll-ever-find-5911b4ae3114?source=rss------bug_bounty-5
“And the forgot password link was sent to attacker’s mail, instead of victim’s mail” 😈
Oops, maybe we just went too ahead.Continue reading on Medium » (https://medium.com/@prayerskhristi/easiest-zero-click-account-takeover-youll-ever-find-5911b4ae3114?source=rss------bug_bounty-5)
Oops, maybe we just went too ahead.Continue reading on Medium » (https://medium.com/@prayerskhristi/easiest-zero-click-account-takeover-youll-ever-find-5911b4ae3114?source=rss------bug_bounty-5)
How Hackers Use Nmap to Find Hidden Vulnerabilities
Bug bounty Continue reading on Medium »
Read more...
Bug bounty Continue reading on Medium »
Read more...
Medium
How Hackers Use Nmap to Find Hidden Vulnerabilities
Bug bounty
⚙️ 03. — Password Reset Broken Logic
Difficulty: 🟢 ApprenticeContinue reading on Medium »
Read more...
Difficulty: 🟢 ApprenticeContinue reading on Medium »
Read more...
Medium
⚙️ 03. — Password Reset Broken Logic
Difficulty: 🟢 Apprentice
⚙️ 04. — Username Enumeration via Subtly Different Responses
Difficulty: 🟡 PractitionerContinue reading on Medium »
Read more...
Difficulty: 🟡 PractitionerContinue reading on Medium »
Read more...
Medium
⚙️ 04. — Username Enumeration via Subtly Different Responses
Difficulty: 🟡 Practitioner
I Changed One Number. Then I Found Everything.
How a single predictable parameter unraveled into IDOR, SQL injection, multi-school data exposure, and admin credential leakage — all from…Continue reading on Medium »
Read more...
How a single predictable parameter unraveled into IDOR, SQL injection, multi-school data exposure, and admin credential leakage — all from…Continue reading on Medium »
Read more...
Medium
I Changed One Number. Then I Found Everything.
How a single predictable parameter unraveled into IDOR, SQL injection, multi-school data exposure, and admin credential leakage — all from…
⚙️ 05. — Username Enumeration via Response Timing
Difficulty: 🟡 PractitionerContinue reading on Medium »
Read more...
Difficulty: 🟡 PractitionerContinue reading on Medium »
Read more...
Medium
⚙️ 05. — Username Enumeration via Response Timing
Difficulty: 🟡 Practitioner