One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium » (https://medium.com/@yasser_/when-an-invitation-isnt-really-an-invitation-a-real-world-bug-finding-5d1469a877f0?source=rss------bug_bounty-5)
When an Invitation Isn’t Really an Invitation , A real world bug Finding
One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium »
Read more...
One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.Continue reading on Medium »
Read more...
Medium
When an Invitation Isn’t Really an Invitation , A real world bug Finding
One thing I really enjoy about bug bounty hunting is that some of the most interesting bugs don’t come from complicated payloads.
Dark-Moon v1.4.0
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
Read more...
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
Read more...
DOM XSS Deep Dive: Sources, Sinks, and Backwards Tracing
Hello, I am Nitin.Continue reading on Medium »
Read more...
Hello, I am Nitin.Continue reading on Medium »
Read more...
Medium
DOM XSS Deep Dive: Sources, Sinks, and Backwards Tracing
Hello, I am Nitin.
How Did I Find a Subdomain Takeover in a HackerOne Program?
How a forgotten DNS record led me to an unclaimed Heroku applicationContinue reading on Medium »
Read more...
How a forgotten DNS record led me to an unclaimed Heroku applicationContinue reading on Medium »
Read more...
Medium
How Did I Find a Subdomain Takeover in a HackerOne Program?
How a forgotten DNS record led me to an unclaimed Heroku application
LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium »
Read more...
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium »
Read more...
Medium
🔥 LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…
The Victim Paid. The Attacker Used Their Subscription.
Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Medium
The Victim Paid. The Attacker Used Their Subscription.
Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.
The AI Bug Bounty Delusion: Why LLMs and Scanners Won’t Make You a Hacker
If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…Continue reading on Medium »
Read more...
If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…Continue reading on Medium »
Read more...
Medium
The AI Bug Bounty Delusion: Why LLMs and Scanners Won’t Make You a Hacker
If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…
Shuffle v2.3.0-rc1
https://kitploit.com/en/posts/github-shuffle-shuffle-v230-rc1
Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and hybrid resource sharing for SOC teams.
https://kitploit.com/en/posts/github-shuffle-shuffle-v230-rc1
Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and hybrid resource sharing for SOC teams.
Dark-Moon v1.4.0
https://kitploit.com/en/posts/github-ascit31-dark-moon-v140
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
https://kitploit.com/en/posts/github-ascit31-dark-moon-v140
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
opencti v7.260907.0
https://kitploit.com/en/posts/github-opencti-platform-opencti-72609070
Open Cyber Threat Intelligence Platform
https://kitploit.com/en/posts/github-opencti-platform-opencti-72609070
Open Cyber Threat Intelligence Platform
I Wasn’t Hunting an Email Bug. I Just Changed One Word.
Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Medium
I Wasn’t Hunting an Email Bug. I Just Changed One Word (ATO).
Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.
Advanced Vulnerabilities Part 2: Cross-Chain, Signatures & Upgradeable Pitfalls
Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min readContinue reading on Medium »
Read more...
Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min readContinue reading on Medium »
Read more...
Medium
Advanced Vulnerabilities Part 2: Cross-Chain, Signatures & Upgradeable Pitfalls
Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min read
How I Could Have Shut Down Every Restaurant in Europe With One Click
I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.Continue reading on Medium »
Read more...
I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.Continue reading on Medium »
Read more...
Medium
How I Could Have Shut Down Every Restaurant in Europe With One Click
I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.
DOM XSS Deep Dive: Sources, Sinks, and Backwards Tracing
https://kd-200.medium.com/dom-xss-deep-dive-sources-sinks-and-backwards-tracing-9253fdb8975c?source=rss------bug_bounty-5
https://kd-200.medium.com/dom-xss-deep-dive-sources-sinks-and-backwards-tracing-9253fdb8975c?source=rss------bug_bounty-5
Hello, I am Nitin.Continue reading on Medium » (https://kd-200.medium.com/dom-xss-deep-dive-sources-sinks-and-backwards-tracing-9253fdb8975c?source=rss------bug_bounty-5)
How Did I Find a Subdomain Takeover in a HackerOne Program?
https://medium.com/@jakalalokesh07/how-did-i-find-a-subdomain-takeover-in-a-hackerone-program-2f2ba3b3adf6?source=rss------bug_bounty-5
https://medium.com/@jakalalokesh07/how-did-i-find-a-subdomain-takeover-in-a-hackerone-program-2f2ba3b3adf6?source=rss------bug_bounty-5