Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Need Advice to build up resume
https://www.reddit.com/r/Pentesting/comments/10n5g1z/need_advice_to_build_up_resume/

<!-- SC_OFF -->I want to get into pentesting field and don't know how should I proceed to get there. I play CTFs from Hackthebox, learn from some other materials. But what are the things which I should be doing which can be added up in my resume as Uni Student , when going to apply for a job I can be considered a promising candidate for the job. Certifications are kind of too expensive like OSCP, eJPT Can't get any intership? Or can I ? Cybersecurity Internship (Don't know they are relevant)? <!-- SC_ON --> submitted by /u/Us3r_blue (https://www.reddit.com/user/Us3r_blue)
[link] (https://www.reddit.com/r/Pentesting/comments/10n5g1z/need_advice_to_build_up_resume/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n5g1z/need_advice_to_build_up_resume/)
Dark Reading: Attacks/Breaches
Enterprises Need to Do More to Assure Consumers About Privacy

Organizations care about data privacy, but their priorities appear to be different from what their customers think are important.
XSS, Flash Cross-Domain Policy, and CSRF Vulnerabilities Discovered on a Single Website

Hello everyone, my name is Koroush, (aka whiteOwl).  In this write-up, I will be discussing the methods I used to bypass the site’s input…Continue reading on Medium »
Read more...
Hello everyone, my name is Koroush, (aka whiteOwl). 
In this write-up, I will be discussing the methods I used to bypass the site’s input…Continue reading on Medium » (https://medium.com/@koroush.pub/xss-flash-cross-domain-policy-and-csrf-vulnerabilities-discovered-on-a-single-website-4948dff4ec11?source=rss------bug_bounty-5)
Fintech bank app won’t respond to a really bad exploit
https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/

<!-- SC_OFF -->I found a bug in an iOS app of a financial institution! This bug is actually hilariously bad. Basically if you have a phone number you have that person credentials. No 2FA. It's literally driving me mad how this even happens. I'm talking this will give you SSN of the user EVERYTHING! This company I added Software engineers on Linkedln. Nothing ignored. I don't really know my next steps. I've done bug bounty a long time ago. This was stumbled on accident, and it's been over 2 weeks it's still works. This is pretty big "fintech bank" apps. What do I do should I just leave it, or disclose it publicly and watch the company burn to the ground like it should. <!-- SC_ON --> submitted by /u/Ehh8me (https://www.reddit.com/user/Ehh8me)
[link] (https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/)
Security jobs for junior positions
https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/

<!-- SC_OFF -->Hi everybody, I'm trying to find some open roles in security positions. I'm not starting from the scratch, I will get a master degree in cybersecurity in 3 months, I've experience with coding, open source on Github, bug bounty, CTFs, 2 CVEs, eJPT... The problem is that 99% of the roles companies are looking for are for highly skilled / experienced people (senior, staff, VC, manager etc..). Where I can find junior positions? Are there companies looking for those roles? Thanks. ​ (advices from experts are welcome :-) ) <!-- SC_ON --> submitted by /u/edoardottt (https://www.reddit.com/user/edoardottt)
[link] (https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/) [comments] (https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/)
Merhaba arkadaşlar , bu yazımızda 403 kısıtlamasını aşmak için ne tür teknikler uygulayabiliriz ? Ve 403bypass aracını kullanarak hızlı…Continue reading on Medium » (https://medium.com/@el-cezeri/%C3%B6d%C3%BCl-avc%C4%B1l%C4%B1%C4%9F%C4%B1-403-forbidden-bypass-f8904345678?source=rss------bug_bounty-5)