Bringing Out of Scope, In Scope
https://meispi.medium.com/bringing-out-of-scope-in-scope-dc19ee17dd6?source=rss------bug_bounty-5
We are all aware of the CSRF on Login form being out of scope in almost all of the bug bounty programs. This post is about chaining this…Continue reading on Medium » (https://meispi.medium.com/bringing-out-of-scope-in-scope-dc19ee17dd6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://meispi.medium.com/bringing-out-of-scope-in-scope-dc19ee17dd6?source=rss------bug_bounty-5
We are all aware of the CSRF on Login form being out of scope in almost all of the bug bounty programs. This post is about chaining this…Continue reading on Medium » (https://meispi.medium.com/bringing-out-of-scope-in-scope-dc19ee17dd6?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bringing Out of Scope, In Scope
We are all aware of the CSRF on Login form being out of scope in almost all of the bug bounty programs. This post is about chaining this…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
PentestBro : Port Scanning, Banner Grabbing & Web Enumeration Into One Tool
Experimental tool for Windows. PentestBro combines subdomain scans, whois, port scanning, banner grabbing and web enumeration into one tool. Uses subdomain list of SecLists. Uses nmap service probes for banner grabbing. Uses list of paths for web enumeration. Example scan of “www.ccc.de“ Scanned subdomain, IPs and ports Grabbed banner for each IP and port whois […]
The post PentestBro : Port Scanning, Banner Grabbing & Web Enumeration Into One Tool appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
PentestBro : Port Scanning, Banner Grabbing & Web Enumeration Into One Tool
Experimental tool for Windows. PentestBro combines subdomain scans, whois, port scanning, banner grabbing and web enumeration into one tool. Uses subdomain list of SecLists. Uses nmap service probes for banner grabbing. Uses list of paths for web enumeration. Example scan of “www.ccc.de“ Scanned subdomain, IPs and ports Grabbed banner for each IP and port whois […]
The post PentestBro : Port Scanning, Banner Grabbing & Web Enumeration Into One Tool appeared first on Kali Linux Tutorials.
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
PentestBro : Port Scanning, Banner Grabbing & Web Enumeration Into One Tool
Experimental tool for Windows. PentestBro combines subdomain scans, whois, port scanning, banner grabbing and web enumeration into one tool.
Bug Bounty on Medium
How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR.
https://cdn-images-1.medium.com/max/1185/1*PRKIv9mGEbo5ickHdOW7YA.png
Hey friends,
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR.
https://cdn-images-1.medium.com/max/1185/1*PRKIv9mGEbo5ickHdOW7YA.png
Hey friends,
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR.
Hey friends,
Hacking Articles Tips Tricks Videos Tutorials pinned «Bug Bounty on Medium How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR. https://cdn-images-1.medium.com/max/1185/1*PRKIv9mGEbo5ickHdOW7YA.png Hey friends, Continue reading on InfoSec Write-ups » ___________________________…»
How to find that BadAss IDOR
Hey there, my name is karan sharma. And i’m back with a story of IDOR and why i think you should know about it.Continue reading on Medium »
Read more...
Hey there, my name is karan sharma. And i’m back with a story of IDOR and why i think you should know about it.Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR.
https://cdn-images-1.medium.com/max/1185/1*PRKIv9mGEbo5ickHdOW7YA.png
Hey friends,
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR.
https://cdn-images-1.medium.com/max/1185/1*PRKIv9mGEbo5ickHdOW7YA.png
Hey friends,
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How I hacked into India’s top matrimonial website and earned amazon gift card worth 10K INR.
Hey friends,
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Internet पर आपकी इन गलतियों से आपको कोई भी कर सकता है । Hacked With these mistakes on the internet…
https://cdn-images-1.medium.com/max/1282/0*lQJOqtLIli4WaRem.jpg
आज के टाइम सभी internet use करते है और रोज़ तरह तरह की web sites को visite करते है लेकिन बोहोत लोगो को http ओर https के difference का पता…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Internet पर आपकी इन गलतियों से आपको कोई भी कर सकता है । Hacked With these mistakes on the internet…
https://cdn-images-1.medium.com/max/1282/0*lQJOqtLIli4WaRem.jpg
आज के टाइम सभी internet use करते है और रोज़ तरह तरह की web sites को visite करते है लेकिन बोहोत लोगो को http ओर https के difference का पता…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Internet पर आपकी इन गलतियों से आपको कोई भी कर सकता है । Hacked With these mistakes on the internet, anyone can hack you.
आज के टाइम सभी internet use करते है और रोज़ तरह तरह की web sites को visite करते है लेकिन बोहोत लोगो को http ओर https के difference का पता…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Command execution: OWASP top vulnerability
https://cdn-images-1.medium.com/max/2600/1*JYgwaEFfqJre6bhC7u-Qiw.jpeg
what is command execution?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Command execution: OWASP top vulnerability
https://cdn-images-1.medium.com/max/2600/1*JYgwaEFfqJre6bhC7u-Qiw.jpeg
what is command execution?
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Command execution: OWASP top vulnerability
what is command execution?
Media is too big
VIEW IN TELEGRAM
5. SSH Socks5 Proxy Tunneling with Dynamic Ports.mp4
Watch Full Course :- https://t.me/joinchat/Sye7C3tuRFfA10yN
Watch Full Course :- https://t.me/joinchat/Sye7C3tuRFfA10yN
🔰 Todays findings 🔰
New QNAP NAS Flaws Exploited In Recent Ransomware Attacks - Patch It!
https://thehackernews.com/2021/04/new-qnap-nas-flaws-exploited-in-recent.html
Google Released Chrome 90 With The Fixes Of Zero-Day Flaw – Update Your Chrome Immediately
https://gbhackers.com/google-released-chrome-90-with-the-fixes-of-zero-day-flaw-update-your-chrome-immediately/
S3 Account Search
https://github.com/WeAreCloudar/s3-account-search
Designing sockfuzzer, a network syscall fuzzer for XNU
https://googleprojectzero.blogspot.com/2021/04/designing-sockfuzzer-network-syscall.html
Duo Two-factor Authentication Bypass
https://sensepost.com/blog/2021/duo-two-factor-authentication-bypass/
___________________________
@hacking_Attack
@Hacking_Video
New QNAP NAS Flaws Exploited In Recent Ransomware Attacks - Patch It!
https://thehackernews.com/2021/04/new-qnap-nas-flaws-exploited-in-recent.html
Google Released Chrome 90 With The Fixes Of Zero-Day Flaw – Update Your Chrome Immediately
https://gbhackers.com/google-released-chrome-90-with-the-fixes-of-zero-day-flaw-update-your-chrome-immediately/
S3 Account Search
https://github.com/WeAreCloudar/s3-account-search
Designing sockfuzzer, a network syscall fuzzer for XNU
https://googleprojectzero.blogspot.com/2021/04/designing-sockfuzzer-network-syscall.html
Duo Two-factor Authentication Bypass
https://sensepost.com/blog/2021/duo-two-factor-authentication-bypass/
___________________________
@hacking_Attack
@Hacking_Video
🔰 Todays findings 🔰
Shopify Account Takeover $22500 Bug Bounty
https://youtu.be/YnKcRN6SBKI
CSRF Testing Guide For Bug Bounty Hunters
https://thexssrat.medium.com/csrf-tesguide-for-bug-bounty-hunters-d14db3462695
Passwordstate Password Manager Update Hijacked to Install Backdoor on Thousands of PCs
https://thehackernews.com/2021/04/passwordstate-password-manager-update.html
QR Codes Popularity May Abused to Deliver Malware and Banking Heists
https://gbhackers.com/qr-codes-popularity-may-abused-to-deliver-malware/
Detecting Jakarta Expression Language injections with CodeQL
https://infosecwriteups.com/detecting-jakarta-expression-language-injections-with-codeql-41c25d45cdb3
My Experience With BugBountyHunt3r — Hands on Bug Bounty Hunting Learning Platform
https://smhtahsin33.medium.com/my-experience-with-bugbountyhunt3r-hands-on-bug-bounty-hunting-learning-platform-9da52a50502d
CocoaPods RCE exploit exposed keys to repo used by three million mobile apps
https://portswigger.net/daily-swig/cocoapods-rce-exploit-exposed-keys-to-repo-used-by-three-million-mobile-apps
___________________________
@hacking_Attack
@Hacking_Video
Shopify Account Takeover $22500 Bug Bounty
https://youtu.be/YnKcRN6SBKI
CSRF Testing Guide For Bug Bounty Hunters
https://thexssrat.medium.com/csrf-tesguide-for-bug-bounty-hunters-d14db3462695
Passwordstate Password Manager Update Hijacked to Install Backdoor on Thousands of PCs
https://thehackernews.com/2021/04/passwordstate-password-manager-update.html
QR Codes Popularity May Abused to Deliver Malware and Banking Heists
https://gbhackers.com/qr-codes-popularity-may-abused-to-deliver-malware/
Detecting Jakarta Expression Language injections with CodeQL
https://infosecwriteups.com/detecting-jakarta-expression-language-injections-with-codeql-41c25d45cdb3
My Experience With BugBountyHunt3r — Hands on Bug Bounty Hunting Learning Platform
https://smhtahsin33.medium.com/my-experience-with-bugbountyhunt3r-hands-on-bug-bounty-hunting-learning-platform-9da52a50502d
CocoaPods RCE exploit exposed keys to repo used by three million mobile apps
https://portswigger.net/daily-swig/cocoapods-rce-exploit-exposed-keys-to-repo-used-by-three-million-mobile-apps
___________________________
@hacking_Attack
@Hacking_Video
🔰 Todays findings 🔰
RCE via Internal Access to Adminer Database Management (Critical)
https://ahmdhalabi.medium.com/rce-via-internal-access-to-adminer-database-management-critical-d3dc2a1d392a
Hacking GraphQL for Fun and Profit — Part 2— Methodology and Examples
https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-2-methodology-and-examples-5992093bcc24
Critical RCE Bug Found in Homebrew Package Manager for macOS and Linux
https://thehackernews.com/2021/04/critical-rce-bug-found-in-homebrew.html
Ransomware Strain Qlocker Targeting QNAP NAS Flaws – Patch It!
https://cybersecuritynews.com/ransomware-strain-qlocker/
___________________________
@hacking_Attack
@Hacking_Video
RCE via Internal Access to Adminer Database Management (Critical)
https://ahmdhalabi.medium.com/rce-via-internal-access-to-adminer-database-management-critical-d3dc2a1d392a
Hacking GraphQL for Fun and Profit — Part 2— Methodology and Examples
https://busk3r.medium.com/hacking-graphql-for-fun-and-profit-part-2-methodology-and-examples-5992093bcc24
Critical RCE Bug Found in Homebrew Package Manager for macOS and Linux
https://thehackernews.com/2021/04/critical-rce-bug-found-in-homebrew.html
Ransomware Strain Qlocker Targeting QNAP NAS Flaws – Patch It!
https://cybersecuritynews.com/ransomware-strain-qlocker/
___________________________
@hacking_Attack
@Hacking_Video
Medium
RCE via Internal Access to Adminer Database Management (Critical)
How I was able to access an internal Database Management leading to Remote Code Execution.