Collects, checks and ranks public HTTP/SOCKS proxies against your own targets, then serves them via ranked exports, pools, a rotating gateway and a local API.
Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/
Web Cache Deception: Understanding the Attack and How to Prevent It
https://medium.com/@MazenElsayed_/web-cache-deception-understanding-the-attack-and-how-to-prevent-it-f9d617af56d3?source=rss------bug_bounty-5
https://medium.com/@MazenElsayed_/web-cache-deception-understanding-the-attack-and-how-to-prevent-it-f9d617af56d3?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@MazenElsayed_/web-cache-deception-understanding-the-attack-and-how-to-prevent-it-f9d617af56d3?source=rss------bug_bounty-5)
Recruit — SSRF → LFI → SQL Injection → Admin Takeover”THM”
https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5
Difficulty: Easy/Medium Category: Web Application Pentesting Techniques: SSRF, Local File Inclusion, SQL Injection, Vulnerability ChainingContinue reading on Medium » (https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5)
https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5
Difficulty: Easy/Medium Category: Web Application Pentesting Techniques: SSRF, Local File Inclusion, SQL Injection, Vulnerability ChainingContinue reading on Medium » (https://medium.com/@ahmed240102345/recruit-ssrf-lfi-sql-injection-admin-takeover-thm-e31a0688b0bc?source=rss------bug_bounty-5)
Support — Cookie Tampering → IDOR → LFI → Command Injection (RCE) “THM”
https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5
Difficulty: Medium Category: Web Application Pentesting Techniques: Credential Brute-Forcing, Insecure Cookie Trust, Local File Inclusion…Continue reading on Medium » (https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5)
https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5
Difficulty: Medium Category: Web Application Pentesting Techniques: Credential Brute-Forcing, Insecure Cookie Trust, Local File Inclusion…Continue reading on Medium » (https://medium.com/@ahmed240102345/support-cookie-tampering-idor-lfi-command-injection-rce-thm-d8bf93bcb5ce?source=rss------bug_bounty-5)
It Returned 404… But the Data Was Still There
https://medium.com/@hamdyosama2995/it-returned-404-but-the-data-was-still-there-6e9bf4dd408d?source=rss------bug_bounty-5
https://medium.com/@hamdyosama2995/it-returned-404-but-the-data-was-still-there-6e9bf4dd408d?source=rss------bug_bounty-5
Hello Hacker👋Continue reading on Medium » (https://medium.com/@hamdyosama2995/it-returned-404-but-the-data-was-still-there-6e9bf4dd408d?source=rss------bug_bounty-5)
OnTheEdge - Extracting Edge plaintext credentials
https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/
<!-- SC_OFF -->I've been working on a small C-based program that looks for credential-related data in running Microsoft Edge processes. The program simply enumerates msedge.exe processes, reads accessible memory regions and looks for specific patterns associated with credential data. The project includes both a standalone EXE and a BOF version for Sliver. Would be interested to know if others can reproduce it on different Edge/Windows versions. <!-- SC_ON --> submitted by /u/KeyDay4761 (https://www.reddit.com/user/KeyDay4761)
[link] (https://github.com/JssNGC/OnTheEdge) [comments] (https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/)
https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/
<!-- SC_OFF -->I've been working on a small C-based program that looks for credential-related data in running Microsoft Edge processes. The program simply enumerates msedge.exe processes, reads accessible memory regions and looks for specific patterns associated with credential data. The project includes both a standalone EXE and a BOF version for Sliver. Would be interested to know if others can reproduce it on different Edge/Windows versions. <!-- SC_ON --> submitted by /u/KeyDay4761 (https://www.reddit.com/user/KeyDay4761)
[link] (https://github.com/JssNGC/OnTheEdge) [comments] (https://www.reddit.com/r/redteamsec/comments/1wo3frp/ontheedge_extracting_edge_plaintext_credentials/)
HimitsuShell: shell scripts invisible to kernel tracing
https://www.reddit.com/r/redteamsec/comments/1woa6r0/himitsushell_shell_scripts_invisible_to_kernel/
submitted by /u/masiroo (https://www.reddit.com/user/masiroo)
[link] (https://github.com/HimitsuShell/HimitsuShell) [comments] (https://www.reddit.com/r/redteamsec/comments/1woa6r0/himitsushell_shell_scripts_invisible_to_kernel/)
https://www.reddit.com/r/redteamsec/comments/1woa6r0/himitsushell_shell_scripts_invisible_to_kernel/
submitted by /u/masiroo (https://www.reddit.com/user/masiroo)
[link] (https://github.com/HimitsuShell/HimitsuShell) [comments] (https://www.reddit.com/r/redteamsec/comments/1woa6r0/himitsushell_shell_scripts_invisible_to_kernel/)
Breaking the Superuser Guardrails of managed-PostgreSQL Providers
https://www.reddit.com/r/redteamsec/comments/1wogfra/breaking_the_superuser_guardrails_of/
submitted by /u/wtfse (https://www.reddit.com/user/wtfse)
[link] (https://mehmetince.net/part-2-6-breaking-the-superuser-guardrails-attacking-security-hardening-extensions-systemic-risks-in-the-managed-postgresql-industry/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wogfra/breaking_the_superuser_guardrails_of/)
https://www.reddit.com/r/redteamsec/comments/1wogfra/breaking_the_superuser_guardrails_of/
submitted by /u/wtfse (https://www.reddit.com/user/wtfse)
[link] (https://mehmetince.net/part-2-6-breaking-the-superuser-guardrails-attacking-security-hardening-extensions-systemic-risks-in-the-managed-postgresql-industry/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wogfra/breaking_the_superuser_guardrails_of/)
Smart Popup by Supsystic (CVE-2026-18322): Analysis and Exploitation
https://www.reddit.com/r/redteamsec/comments/1wovy8l/smart_popup_by_supsystic_cve202618322_analysis/
submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/23/cve-2026-18322-analysis-and-exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wovy8l/smart_popup_by_supsystic_cve202618322_analysis/)
https://www.reddit.com/r/redteamsec/comments/1wovy8l/smart_popup_by_supsystic_cve202618322_analysis/
submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/23/cve-2026-18322-analysis-and-exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wovy8l/smart_popup_by_supsystic_cve202618322_analysis/)
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
https://www.reddit.com/r/redteamsec/comments/1wpwggq/argus_monitor_local_denialofservice_vulnerability/
<!-- SC_OFF -->(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR (https://www.felixcloutier.com/x86/monitor) & MWAIT (https://www.felixcloutier.com/x86/mwait) instructions used by Hyper-V (https://en.wikipedia.org/wiki/Hyper-V) and other kernel components--triggering a HYPERVISOR_ERROR bugcheck. (2) Reaching the IOCTL requires exploiting a TOCTOU (https://en.wikipedia.org/wiki/Time-of-check_to_time-of-use) bug arguably caused by poor documentation of the SeLocateProcessImageName (https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/ntifs/nf-ntifs-selocateprocessimagename) function. (3) Reimplementation of the driver's security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum. See full write-up (https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/), and Github (https://github.com/connorjaydunn/CVE-2026-79417) for PoC. <!-- SC_ON --> submitted by /u/p0xq (https://www.reddit.com/user/p0xq)
[link] (https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wpwggq/argus_monitor_local_denialofservice_vulnerability/)
https://www.reddit.com/r/redteamsec/comments/1wpwggq/argus_monitor_local_denialofservice_vulnerability/
<!-- SC_OFF -->(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR (https://www.felixcloutier.com/x86/monitor) & MWAIT (https://www.felixcloutier.com/x86/mwait) instructions used by Hyper-V (https://en.wikipedia.org/wiki/Hyper-V) and other kernel components--triggering a HYPERVISOR_ERROR bugcheck. (2) Reaching the IOCTL requires exploiting a TOCTOU (https://en.wikipedia.org/wiki/Time-of-check_to_time-of-use) bug arguably caused by poor documentation of the SeLocateProcessImageName (https://learn.microsoft.com/en-us/windows-hardware/drivers/ddi/ntifs/nf-ntifs-selocateprocessimagename) function. (3) Reimplementation of the driver's security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum. See full write-up (https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/), and Github (https://github.com/connorjaydunn/CVE-2026-79417) for PoC. <!-- SC_ON --> submitted by /u/p0xq (https://www.reddit.com/user/p0xq)
[link] (https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wpwggq/argus_monitor_local_denialofservice_vulnerability/)