<!-- SC_OFF -->Hello all, If you do bug bounty hunting or pentests you surely came across many hosts served from an NGINX server, in this lab (published to OWASP) I combined over 20 misconfigurations found in real world bug disclosures and both classic and novel security research, with an extensive blog where I explained everything you need to level up your NGINX hunting game. Feel free to check it out, give it a star on Github if you like it, and suggest any ideas you want me to add/fix... https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/ Happy hunting! <!-- SC_ON --> submitted by /u/OilOverall4190 (https://www.reddit.com/user/OilOverall4190)
[link] (https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vnu9aw/lab_damn_vulnerable_nginx_proxy_dvnp/)
[link] (https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vnu9aw/lab_damn_vulnerable_nginx_proxy_dvnp/)
How to Find Your First Bug Bounty Vulnerability in 2026 (The Beginner Method That Actually Pays)
Everyone's searching CVE-2026-50522, Here's the step-by-step IDOR method beginners actually use to find paid bugs, by b0dj0x.Continue reading on Medium »
Read more...
Everyone's searching CVE-2026-50522, Here's the step-by-step IDOR method beginners actually use to find paid bugs, by b0dj0x.Continue reading on Medium »
Read more...
Medium
How to Find Your First Bug Bounty Vulnerability in 2026 (The Beginner Method That Actually Pays) | CVE-2026–50522
Everyone's searching CVE-2026-50522, Here's the step-by-step IDOR method beginners actually use to find paid bugs, by b0dj0x.
️⚡ Ash Keeps Searching the Tall Grass, While Python Prepares for the Next Gym Battle
Ash had learned something important about Pokémon battles.Continue reading on Medium »
Read more...
Ash had learned something important about Pokémon battles.Continue reading on Medium »
Read more...
How Expired Domains Become Weapons for Scams and Malware
Alternative title: The Hidden Cybercrime Economy Behind Expired DomainsContinue reading on Medium »
Read more...
Alternative title: The Hidden Cybercrime Economy Behind Expired DomainsContinue reading on Medium »
Read more...
Medium
How Expired Domains Become Weapons for Scams and Malware
Alternative title: The Hidden Cybercrime Economy Behind Expired Domains
I Changed ₹500 to ₹1 — How I Found a Payment Logic Bug in a QR Code
The QR Code Looked Normal. The Payment Logic Wasn’t.Continue reading on Medium »
Read more...
The QR Code Looked Normal. The Payment Logic Wasn’t.Continue reading on Medium »
Read more...
Medium
I Changed ₹500 to ₹1 — How I Found a Payment Logic Bug in a QR Code
The QR Code Looked Normal. The Payment Logic Wasn’t.
Shadow AI: The Breach Nobody Approved, Signed Off On, or Even Saw Coming
https://medium.com/@t3nv1/shadow-ai-the-breach-nobody-approved-signed-off-on-or-even-saw-coming-e97737fe30eb?source=rss------bug_bounty-5
https://medium.com/@t3nv1/shadow-ai-the-breach-nobody-approved-signed-off-on-or-even-saw-coming-e97737fe30eb?source=rss------bug_bounty-5
A developer at a mid-sized fintech company pasted a chunk of proprietary source code into a free AI chatbot last spring, just to get a…Continue reading on Medium » (https://medium.com/@t3nv1/shadow-ai-the-breach-nobody-approved-signed-off-on-or-even-saw-coming-e97737fe30eb?source=rss------bug_bounty-5)
Hello everyone,Continue reading on Medium » (https://medium.com/@the_phreak/bug-hunting-1-f9721f0ca753?source=rss------bug_bounty-5)
Got My First $$ Bug Bounty
https://infosecwriteups.com/got-my-first-bug-bounty-9d3d017b4342?source=rss------bug_bounty-5
https://infosecwriteups.com/got-my-first-bug-bounty-9d3d017b4342?source=rss------bug_bounty-5
I finally got my first bug bounty.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/got-my-first-bug-bounty-9d3d017b4342?source=rss------bug_bounty-5)
How I Systematically Find SQL Injection Bugs in Bug Bounty Programs (Step-by-Step Method)
https://medium.com/@b0dj0x/how-i-systematically-find-sql-injection-bugs-in-bug-bounty-programs-step-by-step-method-0bbaf03c4722?source=rss------bug_bounty-5
https://medium.com/@b0dj0x/how-i-systematically-find-sql-injection-bugs-in-bug-bounty-programs-step-by-step-method-0bbaf03c4722?source=rss------bug_bounty-5
SQLi is decades old and still one of the highest-paying bug classes in 2026 — here’s the exact recon-to-report process that actually finds…Continue reading on Medium » (https://medium.com/@b0dj0x/how-i-systematically-find-sql-injection-bugs-in-bug-bounty-programs-step-by-step-method-0bbaf03c4722?source=rss------bug_bounty-5)
Dorks that could get you a good bounty in 2026
https://medium.com/@thenewdate24/dorks-that-could-get-you-a-good-bounty-in-2026-a8cde06f18ed?source=rss------bug_bounty-5
https://medium.com/@thenewdate24/dorks-that-could-get-you-a-good-bounty-in-2026-a8cde06f18ed?source=rss------bug_bounty-5
Google can index far more than publicly intended webpages. During an authorized bug bounty assessment, search operators can help…Continue reading on Medium » (https://medium.com/@thenewdate24/dorks-that-could-get-you-a-good-bounty-in-2026-a8cde06f18ed?source=rss------bug_bounty-5)
How a Simple API Misconfiguration Leaked PII of 100,000+ Users
A Quick Word on MeContinue reading on Medium »
Read more...
A Quick Word on MeContinue reading on Medium »
Read more...
Medium
How a Simple API Misconfiguration Leaked PII of 100,000+ Users
A Quick Word on Me