Appsec Engineer looking for Pentesting advice
https://www.reddit.com/r/Pentesting/comments/zlexot/appsec_engineer_looking_for_pentesting_advice/
<!-- SC_OFF -->Hey all, I am a fairly new appsec engineer, been in the job for a few months now. However, like with most cyber roles, I do more than just appsec engineering. One of my additional responsibilities will be to pen test all the smaller hotfixes of our apps, and I will admit, I am no pen testing genius. I have quite a bit of experience with TryHackMe and HTB, but that is about it when it comes to Red Teaming. That being said, I have tried following the OWASP Testing Framework and applying it to a test environment at my work. Let's just say, I have gotten very overwhelmed with everything when trying to apply stuff in a real world situation. Does anyone have any tips on moving from a CTF environment to a real world situation? Also, do you think there are better ways to test a smaller hotfix than go through the OWASP Testing Framework? I know I can pick and choose my tests that pertain to the situation, but curious to see if there are other thoughts. Thanks! <!-- SC_ON --> submitted by /u/lilryder1994 (https://www.reddit.com/user/lilryder1994)
[link] (https://www.reddit.com/r/Pentesting/comments/zlexot/appsec_engineer_looking_for_pentesting_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/zlexot/appsec_engineer_looking_for_pentesting_advice/)
https://www.reddit.com/r/Pentesting/comments/zlexot/appsec_engineer_looking_for_pentesting_advice/
<!-- SC_OFF -->Hey all, I am a fairly new appsec engineer, been in the job for a few months now. However, like with most cyber roles, I do more than just appsec engineering. One of my additional responsibilities will be to pen test all the smaller hotfixes of our apps, and I will admit, I am no pen testing genius. I have quite a bit of experience with TryHackMe and HTB, but that is about it when it comes to Red Teaming. That being said, I have tried following the OWASP Testing Framework and applying it to a test environment at my work. Let's just say, I have gotten very overwhelmed with everything when trying to apply stuff in a real world situation. Does anyone have any tips on moving from a CTF environment to a real world situation? Also, do you think there are better ways to test a smaller hotfix than go through the OWASP Testing Framework? I know I can pick and choose my tests that pertain to the situation, but curious to see if there are other thoughts. Thanks! <!-- SC_ON --> submitted by /u/lilryder1994 (https://www.reddit.com/user/lilryder1994)
[link] (https://www.reddit.com/r/Pentesting/comments/zlexot/appsec_engineer_looking_for_pentesting_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/zlexot/appsec_engineer_looking_for_pentesting_advice/)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
“My first medium blog"
-You can find many interesting things ahead-
Continue reading on Medium »
“My first medium blog"
-You can find many interesting things ahead-
Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
A Beginner’s Guide to IP Addresses
https://cdn-images-1.medium.com/max/1280/0*HpfL4nk7DmnK2H3r.jpg
TL;DR- An overview on networking standards, types of networks, and identifying all sorts of IP address.
Continue reading on The Gray Area »
A Beginner’s Guide to IP Addresses
https://cdn-images-1.medium.com/max/1280/0*HpfL4nk7DmnK2H3r.jpg
TL;DR- An overview on networking standards, types of networks, and identifying all sorts of IP address.
Continue reading on The Gray Area »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
History of the Metasploit Framework
https://cdn-images-1.medium.com/max/728/1*lJhWVqh1C1k04jRCKa_ppg.jpeg
In this article, I will be talking about the history of the metasploit tool and what product types it has. The Metasploit Framework is a…
Continue reading on Block Magnates »
History of the Metasploit Framework
https://cdn-images-1.medium.com/max/728/1*lJhWVqh1C1k04jRCKa_ppg.jpeg
In this article, I will be talking about the history of the metasploit tool and what product types it has. The Metasploit Framework is a…
Continue reading on Block Magnates »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HackTheBox:Precious
https://cdn-images-1.medium.com/max/1400/1*LDZvITtbct_XPuW0-ahVQg.png
This was an mazing and easy linux box by HackTheBox.To gain initial access on the box we first need to exploit a command injection…
Continue reading on Medium »
HackTheBox:Precious
https://cdn-images-1.medium.com/max/1400/1*LDZvITtbct_XPuW0-ahVQg.png
This was an mazing and easy linux box by HackTheBox.To gain initial access on the box we first need to exploit a command injection…
Continue reading on Medium »
Privilege escalation leads to deleting other user’s account and company Workspace [Access Control]
https://medium.com/@h4ck3rp4tik/privilege-escalation-leads-to-deleting-other-users-account-and-company-workspace-access-control-7b709eb88ef?source=rss------bug_bounty-5
https://medium.com/@h4ck3rp4tik/privilege-escalation-leads-to-deleting-other-users-account-and-company-workspace-access-control-7b709eb88ef?source=rss------bug_bounty-5
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Researchers Uncover 22 Security Concerns Surrounding Google One VPN
https://external-preview.redd.it/F7ond8Ku4pQlHwQYqwAKKHIZ6W45a5-bbhC-ejsdGq0.jpg?width=640&crop=smart&auto=webp&s=a5838fcced7b0ff029b7df0f466ff86980d1fbcb submitted by /u/Successful-Minute-10
[link] [comments]
Researchers Uncover 22 Security Concerns Surrounding Google One VPN
https://external-preview.redd.it/F7ond8Ku4pQlHwQYqwAKKHIZ6W45a5-bbhC-ejsdGq0.jpg?width=640&crop=smart&auto=webp&s=a5838fcced7b0ff029b7df0f466ff86980d1fbcb submitted by /u/Successful-Minute-10
[link] [comments]
Privilege escalation leads to deleting other user’s account and company Workspace [Access Control]
Dear Folks!Continue reading on Medium »
Read more...
Dear Folks!Continue reading on Medium »
Read more...
How To Handle A Bug Bounty Program Internally
https://bugbaseindia.medium.com/how-to-handle-a-bug-bounty-program-internally-993e5a23b579?source=rss------bug_bounty-5
https://bugbaseindia.medium.com/how-to-handle-a-bug-bounty-program-internally-993e5a23b579?source=rss------bug_bounty-5