alg:none and Friends — A JWT Hacking Field Guide
https://kd-200.medium.com/alg-none-and-friends-a-jwt-hacking-field-guide-4864f2e1c673?source=rss------bug_bounty-5
https://kd-200.medium.com/alg-none-and-friends-a-jwt-hacking-field-guide-4864f2e1c673?source=rss------bug_bounty-5
What’s up everyone! Nitin here 👋Continue reading on Medium » (https://kd-200.medium.com/alg-none-and-friends-a-jwt-hacking-field-guide-4864f2e1c673?source=rss------bug_bounty-5)
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium »
Read more...
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium »
Read more...
Medium
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…
PEASS-ng v20260829-c348cd6e
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Read more...
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Read more...
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty
https://medium.com/@t4nv1/how-an-unsanitized-pdf-export-engine-led-to-local-file-inclusion-and-a-14-000-bounty-971c19603d94?source=rss------bug_bounty-5
https://medium.com/@t4nv1/how-an-unsanitized-pdf-export-engine-led-to-local-file-inclusion-and-a-14-000-bounty-971c19603d94?source=rss------bug_bounty-5
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium » (https://medium.com/@t4nv1/how-an-unsanitized-pdf-export-engine-led-to-local-file-inclusion-and-a-14-000-bounty-971c19603d94?source=rss------bug_bounty-5)
One parameter & Two IDORs
بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
Medium
One parameter & Two IDORs
بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلم
From Zero Credentials to Super Admin: An SSO Authentication Bypass on AT&T
The Door Was Already OpenContinue reading on Medium »
Read more...
The Door Was Already OpenContinue reading on Medium »
Read more...
Medium
From Zero Credentials to Super Admin: An SSO Authentication Bypass on AT&T
The Door Was Already Open
The Dark Reality of Mod APKs on Android | Hidden Security Risks
Modified Android applications — commonly called Mod APKs — are everywhere.Continue reading on Medium »
Read more...
Modified Android applications — commonly called Mod APKs — are everywhere.Continue reading on Medium »
Read more...
Medium
🚨 The Dark Reality of Mod APKs on Android | Hidden Security Risks
Modified Android applications — commonly called Mod APKs — are everywhere.
The Bid Button Was Disabled — So I Sent the Bid Anyway
How a client-side payment check on a livestream auction platform turned into a High-severity business logic bug (CVSS 8.5) — found on a…Continue reading on Medium »
Read more...
How a client-side payment check on a livestream auction platform turned into a High-severity business logic bug (CVSS 8.5) — found on a…Continue reading on Medium »
Read more...
Medium
The Bid Button Was Disabled — So I Sent the Bid Anyway
How a client-side payment check on a livestream auction platform turned into a High-severity business logic bug (CVSS 8.5) — found on a…
Buyer Verification Gate Not Enforced Server-Side: Unverified Buyer Wins Live Auction (High)
Target: Private bug bounty program — livestream auction platform (anonymized) Severity: High Vulnerability class: Improper Authorization /…Continue reading on Medium »
Read more...
Target: Private bug bounty program — livestream auction platform (anonymized) Severity: High Vulnerability class: Improper Authorization /…Continue reading on Medium »
Read more...
Medium
Buyer Verification Gate Not Enforced Server-Side: Unverified Buyer Wins Live Auction (High)
Target: Private bug bounty program — livestream auction platform (anonymized) Severity: High Vulnerability class: Improper Authorization /…
opencanary
https://kitploit.com/en/tools/github/thinkst/opencanary
Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and configurable alerting.
https://kitploit.com/en/tools/github/thinkst/opencanary
Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and configurable alerting.
PEASS-ng v20260829-c348cd6e
https://kitploit.com/en/posts/github-peass-ng-peass-ng-20260829-c348cd6e
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
https://kitploit.com/en/posts/github-peass-ng-peass-ng-20260829-c348cd6e
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Microsoft-Sentinel-SecOps
https://kitploit.com/en/tools/github/eshlomo1/microsoft-sentinel-secops
SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud environments.
https://kitploit.com/en/tools/github/eshlomo1/microsoft-sentinel-secops
SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud environments.
SecureForce
https://kitploit.com/en/tools/github/hackops-academy/secureforce
A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing
https://kitploit.com/en/tools/github/hackops-academy/secureforce
A simplified but capable penetration testing framework with exploit library, payload creation, and interactive console for authorized security testing
zttp
https://kitploit.com/en/tools/gitlab/nihal799/zttp
Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to production infrastructure.
https://kitploit.com/en/tools/gitlab/nihal799/zttp
Zero-trust SSH bastion proxy with Vault-backed key management, RBAC policy enforcement, full session recording, and admin TUI for auditable access to production infrastructure.
بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium » (https://medium.com/@omerasraan/one-parameter-two-idors-d26c76620e32?source=rss------bug_bounty-5)