Hi Everyone! This write is about a Cross-Site Request Forgery (CSRF) vulnerability in the payment flow that allowed an attacker to trigger…Continue reading on Medium » (https://medium.com/@a13h1/575-csrf-triggering-payment-receipt-emails-without-user-consent-6014dd5a17b0?source=rss------bug_bounty-5)
Blind SSRF that Leads To Port Scaning And Descover The Infrastracture
There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium »
Read more...
There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium »
Read more...
Medium
Blind SSRF that Leads To Port Scaning And Descover The Infrastracture
There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)
Race Conditions — The $15k Bug That Breaks Logic
Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium »
Read more...
Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium »
Read more...
Medium
Race Conditions — The $15k Bug That Breaks Logic
Race conditions are about tricking the server into doing something twice. Really really fast.
The Definitive Guide to Subdomain Enumeration
A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium »
Read more...
A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium »
Read more...
Medium
The Definitive Guide to Subdomain Enumeration
A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…
Blind SSRF that Leads To Port Scaning And Descover The Infrastracture
https://medium.com/@tomahawk0ctf/blind-ssrf-that-leads-to-port-scaning-and-descover-the-infrastracture-1b1f1ef05453?source=rss------bug_bounty-5
https://medium.com/@tomahawk0ctf/blind-ssrf-that-leads-to-port-scaning-and-descover-the-infrastracture-1b1f1ef05453?source=rss------bug_bounty-5
There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium » (https://medium.com/@tomahawk0ctf/blind-ssrf-that-leads-to-port-scaning-and-descover-the-infrastracture-1b1f1ef05453?source=rss------bug_bounty-5)
Race Conditions — The $15k Bug That Breaks Logic
https://medium.com/@cyber-ninjaaa/race-conditions-the-15k-bug-that-breaks-logic-bed2f325bc04?source=rss------bug_bounty-5
https://medium.com/@cyber-ninjaaa/race-conditions-the-15k-bug-that-breaks-logic-bed2f325bc04?source=rss------bug_bounty-5
Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium » (https://medium.com/@cyber-ninjaaa/race-conditions-the-15k-bug-that-breaks-logic-bed2f325bc04?source=rss------bug_bounty-5)
The Definitive Guide to Subdomain Enumeration
https://medium.com/@tanvir.infosec/the-definitive-guide-to-subdomain-enumeration-e2c04476ef27?source=rss------bug_bounty-5
https://medium.com/@tanvir.infosec/the-definitive-guide-to-subdomain-enumeration-e2c04476ef27?source=rss------bug_bounty-5
A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium » (https://medium.com/@tanvir.infosec/the-definitive-guide-to-subdomain-enumeration-e2c04476ef27?source=rss------bug_bounty-5)
SAML Username Collision Leading to Full ATO
I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…Continue reading on Medium »
Read more...
I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…Continue reading on Medium »
Read more...
Medium
SAML Username Collision Leading to Full ATO
I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…
Private Polls? Not Really — Exploiting Access Control and Logic Flaws
بسْمِ اللَّهِ الرَّحْمٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى النَّبِيِّ الْمُجَاهِدِ الشَّهِيدِ…اللَّهُمَّ انصُرْ أَهْلَ غَزَّةَ…Continue reading on Medium »
Read more...
بسْمِ اللَّهِ الرَّحْمٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى النَّبِيِّ الْمُجَاهِدِ الشَّهِيدِ…اللَّهُمَّ انصُرْ أَهْلَ غَزَّةَ…Continue reading on Medium »
Read more...
Medium
Private Polls? Not Really — Exploiting Access Control and Logic Flaws
بسْمِ اللَّهِ الرَّحْمٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى النَّبِيِّ الْمُجَاهِدِ الشَّهِيدِ…اللَّهُمَّ انصُرْ أَهْلَ غَزَّةَ…
CSRF Account Takeover: Rejected by the Security Team, Rewarded by the Security Director ($$$)
Hi guys,Continue reading on Medium »
Read more...
Hi guys,Continue reading on Medium »
Read more...
Medium
CSRF Account Takeover: Rejected by the Security Team, Rewarded by the Security Director ($$$)
Hi guys,
Reporting a Low-Severity YouTube Logic Issue to Google Taught Me a Lot
There’s a strange moment every beginner in cybersecurity remembers.Continue reading on Medium »
Read more...
There’s a strange moment every beginner in cybersecurity remembers.Continue reading on Medium »
Read more...
Medium
Reporting a Low-Severity YouTube Logic Issue to Google Taught Me a Lot
There’s a strange moment every beginner in cybersecurity remembers.
SAML Username Collision Leading to Full ATO
https://medium.com/@m0n3m/saml-username-collision-leading-to-full-ato-b1f3595e1cc8?source=rss------bug_bounty-5
https://medium.com/@m0n3m/saml-username-collision-leading-to-full-ato-b1f3595e1cc8?source=rss------bug_bounty-5
I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…Continue reading on Medium » (https://medium.com/@m0n3m/saml-username-collision-leading-to-full-ato-b1f3595e1cc8?source=rss------bug_bounty-5)
Private Polls? Not Really — Exploiting Access Control and Logic Flaws
https://medium.com/@yosefmostef99/private-polls-not-really-exploiting-access-control-and-logic-flaws-943ff0bb5cc4?source=rss------bug_bounty-5
https://medium.com/@yosefmostef99/private-polls-not-really-exploiting-access-control-and-logic-flaws-943ff0bb5cc4?source=rss------bug_bounty-5