$$$ I Tried a Simple Registration Endpoint… and Accidentally Found a Critical Admin Account…
No login. No authorization. One API request. And suddenly… I had an administrator account.Continue reading on Medium »
Read more...
No login. No authorization. One API request. And suddenly… I had an administrator account.Continue reading on Medium »
Read more...
Medium
$$$ I Tried a Simple Registration Endpoint… and Accidentally Found a Critical Admin Account Takeover
No login. No authorization. One API request. And suddenly… I had an administrator account.
From an OTP Race Condition to Zero-Interaction Account Takeover
DisclaimerContinue reading on Medium »
Read more...
DisclaimerContinue reading on Medium »
Read more...
Medium
From an OTP Race Condition to Zero-Interaction Account Takeover
Disclaimer
15 Access Control Mistakes Developers Keep Making: Master Real-World Application Security
Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?”Continue reading on Medium »
Read more...
Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?”Continue reading on Medium »
Read more...
Medium
15 Access Control Mistakes Developers Keep Making: Master Real-World Application Security
Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?” You’re not alone. Access control flaws quietly…
Atlas
https://kitploit.com/en/tools/github/portbuster1337/atlas
Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#
https://kitploit.com/en/tools/github/portbuster1337/atlas
Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#
conductai
https://kitploit.com/en/tools/github/sseshachala/conductai
AI agent governance for teams. Runtime firewalls tell you what happened; Conduct Guard controls what can happen — signed policy, verified chain, fail-closed by default. Ships with Router (LLM proxy), 20+ compliance packs, canvas UI, and a playbook engine.
https://kitploit.com/en/tools/github/sseshachala/conductai
AI agent governance for teams. Runtime firewalls tell you what happened; Conduct Guard controls what can happen — signed policy, verified chain, fail-closed by default. Ships with Router (LLM proxy), 20+ compliance packs, canvas UI, and a playbook engine.
$$$ I Tried a Simple Registration Endpoint… and Accidentally Found a Critical Admin Account…
https://alfazhossain0.medium.com/i-tried-a-simple-registration-endpoint-and-accidentally-found-a-critical-admin-account-9af2b90cf4a3?source=rss------bug_bounty-5
https://alfazhossain0.medium.com/i-tried-a-simple-registration-endpoint-and-accidentally-found-a-critical-admin-account-9af2b90cf4a3?source=rss------bug_bounty-5
No login. No authorization. One API request. And suddenly… I had an administrator account.Continue reading on Medium » (https://alfazhossain0.medium.com/i-tried-a-simple-registration-endpoint-and-accidentally-found-a-critical-admin-account-9af2b90cf4a3?source=rss------bug_bounty-5)
From an OTP Race Condition to Zero-Interaction Account Takeover
https://medium.com/@noureldin_shaban/from-an-otp-race-condition-to-zero-interaction-account-takeover-2a95bde82181?source=rss------bug_bounty-5
https://medium.com/@noureldin_shaban/from-an-otp-race-condition-to-zero-interaction-account-takeover-2a95bde82181?source=rss------bug_bounty-5
DisclaimerContinue reading on Medium » (https://medium.com/@noureldin_shaban/from-an-otp-race-condition-to-zero-interaction-account-takeover-2a95bde82181?source=rss------bug_bounty-5)
15 Access Control Mistakes Developers Keep Making: Master Real-World Application Security
https://medium.com/@verylazytech/15-access-control-mistakes-developers-keep-making-master-real-world-application-security-34df61fb9741?source=rss------bug_bounty-5
https://medium.com/@verylazytech/15-access-control-mistakes-developers-keep-making-master-real-world-application-security-34df61fb9741?source=rss------bug_bounty-5
Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?”Continue reading on Medium » (https://medium.com/@verylazytech/15-access-control-mistakes-developers-keep-making-master-real-world-application-security-34df61fb9741?source=rss------bug_bounty-5)
Hacker Club — Solving YesWeHack Dojo #53
https://medium.com/@__fr2/hacker-club-solving-yeswehack-dojo-53-026626278a84?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@__fr2/hacker-club-solving-yeswehack-dojo-53-026626278a84?source=rss------bug_bounty-5)
https://medium.com/@__fr2/hacker-club-solving-yeswehack-dojo-53-026626278a84?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@__fr2/hacker-club-solving-yeswehack-dojo-53-026626278a84?source=rss------bug_bounty-5)
alg:none and Friends — A JWT Hacking Field Guide
What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
Medium
alg:none and Friends — A JWT Hacking Field Guide
What’s up everyone! Nitin here 👋
alg:none and Friends — A JWT Hacking Field Guide
https://kd-200.medium.com/alg-none-and-friends-a-jwt-hacking-field-guide-4864f2e1c673?source=rss------bug_bounty-5
https://kd-200.medium.com/alg-none-and-friends-a-jwt-hacking-field-guide-4864f2e1c673?source=rss------bug_bounty-5
What’s up everyone! Nitin here 👋Continue reading on Medium » (https://kd-200.medium.com/alg-none-and-friends-a-jwt-hacking-field-guide-4864f2e1c673?source=rss------bug_bounty-5)
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium »
Read more...
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium »
Read more...
Medium
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…