Hello hackers! I’m back with another writeup. This time, I want to share a recent finding from a HackerOne program (jobs.target.com).Continue reading on Medium » (https://medium.com/@coolorangee3/exploiting-race-condition-to-break-idempotency-corrupt-data-integrity-160cbf0d2b71?source=rss------bug_bounty-5)
Pondering Paths — Linux Luminarium Part 2
https://medium.com/@may.hack/pondering-paths-linux-luminarium-part-2-56236746706c?source=rss------bug_bounty-5
https://medium.com/@may.hack/pondering-paths-linux-luminarium-part-2-56236746706c?source=rss------bug_bounty-5
Part 1 is already available on my profile. Check my profile if you haven’t read it yet.Continue reading on Medium » (https://medium.com/@may.hack/pondering-paths-linux-luminarium-part-2-56236746706c?source=rss------bug_bounty-5)
Security Week: Gitea RCE Under Attack, Critical Web Flaws, and Tag-Name XSS
Five urgent CVEs, three fresh web security research stories, and the bug bounty lessons defenders should carry into next week.Continue reading on InfoSec Write-ups »
Read more...
Five urgent CVEs, three fresh web security research stories, and the bug bounty lessons defenders should carry into next week.Continue reading on InfoSec Write-ups »
Read more...
Medium
Security Week: Gitea RCE Under Attack, Critical Web Flaws, and Tag-Name XSS
Five urgent CVEs, three fresh web security research stories, and the bug bounty lessons defenders should carry into next week.
Security Week: Gitea RCE Under Attack, Critical Web Flaws, and Tag-Name XSS
https://infosecwriteups.com/security-week-gitea-rce-under-attack-critical-web-flaws-and-tag-name-xss-6db2611da923?source=rss------bug_bounty-5
https://infosecwriteups.com/security-week-gitea-rce-under-attack-critical-web-flaws-and-tag-name-xss-6db2611da923?source=rss------bug_bounty-5
Five urgent CVEs, three fresh web security research stories, and the bug bounty lessons defenders should carry into next week.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/security-week-gitea-rce-under-attack-critical-web-flaws-and-tag-name-xss-6db2611da923?source=rss------bug_bounty-5)
agentZ
https://kitploit.com/en/tools/github/accuknox/agentz
Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.
https://kitploit.com/en/tools/github/accuknox/agentz
Zero-trust agentic AI platform. Supports SaaS and OnPrem (airgapped) deployments.
FuzzingBrain-Bench
https://kitploit.com/en/tools/github/fuzzingbrain/fuzzingbrain-bench
A sealed benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java). Each challenge is an answer-free Docker image with in-image grading — no patch, Poc or answer key ships.
https://kitploit.com/en/tools/github/fuzzingbrain/fuzzingbrain-bench
A sealed benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java). Each challenge is an answer-free Docker image with in-image grading — no patch, Poc or answer key ships.
CVE-2014-085
https://kitploit.com/en/tools/github/ehaoxiongdiycw/cve-2014-085
Nuclei template and PoC for exploiting ZooKeeper unauthorized access vulnerability (CVE-2014-085), enabling automated security testing against target IPs.
https://kitploit.com/en/tools/github/ehaoxiongdiycw/cve-2014-085
Nuclei template and PoC for exploiting ZooKeeper unauthorized access vulnerability (CVE-2014-085), enabling automated security testing against target IPs.
WSGoat
https://kitploit.com/en/tools/github/makarov05bm/wsgoat
The vulnerable application that will teach you how to hack WebSockets
https://kitploit.com/en/tools/github/makarov05bm/wsgoat
The vulnerable application that will teach you how to hack WebSockets
nl-kat-coordination
https://kitploit.com/en/tools/github/ssc-ict-innovatie/nl-kat-coordination
Modular network scanning framework that integrates diverse tools and external databases to detect vulnerabilities and configuration errors, producing accessible reports for continuous security monitoring.
https://kitploit.com/en/tools/github/ssc-ict-innovatie/nl-kat-coordination
Modular network scanning framework that integrates diverse tools and external databases to detect vulnerabilities and configuration errors, producing accessible reports for continuous security monitoring.
OWASP-Top-10-AI-Infrastructure-Security-Risks
https://kitploit.com/en/tools/github/owasp/owasp-top-10-ai-infrastructure-security-risks
A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management planes, and supply chain, with mitigation strategies for providers and customers.
https://kitploit.com/en/tools/github/owasp/owasp-top-10-ai-infrastructure-security-risks
A practical framework identifying and prioritizing the top security risks in AI datacenter infrastructure, covering hardware, networking, management planes, and supply chain, with mitigation strategies for providers and customers.
How I found my first critical vulnerability which came from forgetting my own password on the…
I had already written the program off. Three days later I came back, could not remember my password, and the reset flow showed me…Continue reading on Medium »
Read more...
I had already written the program off. Three days later I came back, could not remember my password, and the reset flow showed me…Continue reading on Medium »
Read more...
Medium
How I found my first critical vulnerability which came from forgetting my own password on the target site
I had already written the program off. Three days later I came back, could not remember my password, and the reset flow showed me something…
AIDebug
Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging
Read more...
Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging
Read more...
How I found my first critical vulnerability which came from forgetting my own password on the…
https://medium.com/@sufyan0x01/how-i-found-my-first-critical-vulnerability-which-came-from-forgetting-my-own-password-on-the-a062bd448868?source=rss------bug_bounty-5
I had already written the program off. Three days later I came back, could not remember my password, and the reset flow showed me…Continue reading on Medium » (https://medium.com/@sufyan0x01/how-i-found-my-first-critical-vulnerability-which-came-from-forgetting-my-own-password-on-the-a062bd448868?source=rss------bug_bounty-5)
https://medium.com/@sufyan0x01/how-i-found-my-first-critical-vulnerability-which-came-from-forgetting-my-own-password-on-the-a062bd448868?source=rss------bug_bounty-5
I had already written the program off. Three days later I came back, could not remember my password, and the reset flow showed me…Continue reading on Medium » (https://medium.com/@sufyan0x01/how-i-found-my-first-critical-vulnerability-which-came-from-forgetting-my-own-password-on-the-a062bd448868?source=rss------bug_bounty-5)
CSRF | How to Test — Part 1
Hi how are u ? i am sure u missed me right 😔?Continue reading on Medium »
Read more...
Hi how are u ? i am sure u missed me right 😔?Continue reading on Medium »
Read more...
Medium
CSRF | How to Test 🐞 — Part 1
Hi how are u ? i am sure u missed me right 😔?
llm-agent-testbed
https://kitploit.com/en/tools/github/pie-script/llm-agent-testbed
An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.
https://kitploit.com/en/tools/github/pie-script/llm-agent-testbed
An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.
AIDebug
https://kitploit.com/en/tools/github/anpa1200/aidebug
Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging
https://kitploit.com/en/tools/github/anpa1200/aidebug
Evidence-focused malware reverse engineering with deep PE/.NET inspection, Ghidra reconstruction, AI cross-checks, YARA, and ELF debugging
DNSRPC-BOF
https://kitploit.com/en/tools/github/paradoxis/dnsrpc-bof
Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the ServerLevelPluginDll edge by using MS-DNSP.
https://kitploit.com/en/tools/github/paradoxis/dnsrpc-bof
Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the ServerLevelPluginDll edge by using MS-DNSP.