XSS, Flash Cross-Domain Policy, and CSRF Vulnerabilities Discovered on a Single Website
Hello everyone, my name is Koroush, (aka whiteOwl). In this write-up, I will be discussing the methods I used to bypass the site’s input…Continue reading on Medium »
Read more...
Hello everyone, my name is Koroush, (aka whiteOwl). In this write-up, I will be discussing the methods I used to bypass the site’s input…Continue reading on Medium »
Read more...
XSS, Flash Cross-Domain Policy, and CSRF Vulnerabilities Discovered on a Single Website
https://medium.com/@koroush.pub/xss-flash-cross-domain-policy-and-csrf-vulnerabilities-discovered-on-a-single-website-4948dff4ec11?source=rss------bug_bounty-5
https://medium.com/@koroush.pub/xss-flash-cross-domain-policy-and-csrf-vulnerabilities-discovered-on-a-single-website-4948dff4ec11?source=rss------bug_bounty-5
Hello everyone, my name is Koroush, (aka whiteOwl).
In this write-up, I will be discussing the methods I used to bypass the site’s input…Continue reading on Medium » (https://medium.com/@koroush.pub/xss-flash-cross-domain-policy-and-csrf-vulnerabilities-discovered-on-a-single-website-4948dff4ec11?source=rss------bug_bounty-5)
In this write-up, I will be discussing the methods I used to bypass the site’s input…Continue reading on Medium » (https://medium.com/@koroush.pub/xss-flash-cross-domain-policy-and-csrf-vulnerabilities-discovered-on-a-single-website-4948dff4ec11?source=rss------bug_bounty-5)
Fintech bank app won’t respond to a really bad exploit
https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/
<!-- SC_OFF -->I found a bug in an iOS app of a financial institution! This bug is actually hilariously bad. Basically if you have a phone number you have that person credentials. No 2FA. It's literally driving me mad how this even happens. I'm talking this will give you SSN of the user EVERYTHING! This company I added Software engineers on Linkedln. Nothing ignored. I don't really know my next steps. I've done bug bounty a long time ago. This was stumbled on accident, and it's been over 2 weeks it's still works. This is pretty big "fintech bank" apps. What do I do should I just leave it, or disclose it publicly and watch the company burn to the ground like it should. <!-- SC_ON --> submitted by /u/Ehh8me (https://www.reddit.com/user/Ehh8me)
[link] (https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/)
https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/
<!-- SC_OFF -->I found a bug in an iOS app of a financial institution! This bug is actually hilariously bad. Basically if you have a phone number you have that person credentials. No 2FA. It's literally driving me mad how this even happens. I'm talking this will give you SSN of the user EVERYTHING! This company I added Software engineers on Linkedln. Nothing ignored. I don't really know my next steps. I've done bug bounty a long time ago. This was stumbled on accident, and it's been over 2 weeks it's still works. This is pretty big "fintech bank" apps. What do I do should I just leave it, or disclose it publicly and watch the company burn to the ground like it should. <!-- SC_ON --> submitted by /u/Ehh8me (https://www.reddit.com/user/Ehh8me)
[link] (https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/) [comments] (https://www.reddit.com/r/Pentesting/comments/10n9z1t/fintech_bank_app_wont_respond_to_a_really_bad/)
Security jobs for junior positions
https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/
<!-- SC_OFF -->Hi everybody, I'm trying to find some open roles in security positions. I'm not starting from the scratch, I will get a master degree in cybersecurity in 3 months, I've experience with coding, open source on Github, bug bounty, CTFs, 2 CVEs, eJPT... The problem is that 99% of the roles companies are looking for are for highly skilled / experienced people (senior, staff, VC, manager etc..). Where I can find junior positions? Are there companies looking for those roles? Thanks. (advices from experts are welcome :-) ) <!-- SC_ON --> submitted by /u/edoardottt (https://www.reddit.com/user/edoardottt)
[link] (https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/) [comments] (https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/)
https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/
<!-- SC_OFF -->Hi everybody, I'm trying to find some open roles in security positions. I'm not starting from the scratch, I will get a master degree in cybersecurity in 3 months, I've experience with coding, open source on Github, bug bounty, CTFs, 2 CVEs, eJPT... The problem is that 99% of the roles companies are looking for are for highly skilled / experienced people (senior, staff, VC, manager etc..). Where I can find junior positions? Are there companies looking for those roles? Thanks. (advices from experts are welcome :-) ) <!-- SC_ON --> submitted by /u/edoardottt (https://www.reddit.com/user/edoardottt)
[link] (https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/) [comments] (https://www.reddit.com/r/Pentesting/comments/10nawtm/security_jobs_for_junior_positions/)
Ödül Avcılığı — 403 Forbidden Bypass
https://medium.com/@el-cezeri/%C3%B6d%C3%BCl-avc%C4%B1l%C4%B1%C4%9F%C4%B1-403-forbidden-bypass-f8904345678?source=rss------bug_bounty-5
https://medium.com/@el-cezeri/%C3%B6d%C3%BCl-avc%C4%B1l%C4%B1%C4%9F%C4%B1-403-forbidden-bypass-f8904345678?source=rss------bug_bounty-5
Merhaba arkadaşlar , bu yazımızda 403 kısıtlamasını aşmak için ne tür teknikler uygulayabiliriz ? Ve 403bypass aracını kullanarak hızlı…Continue reading on Medium » (https://medium.com/@el-cezeri/%C3%B6d%C3%BCl-avc%C4%B1l%C4%B1%C4%9F%C4%B1-403-forbidden-bypass-f8904345678?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe DNS In Detail Walkthrough
https://cdn-images-1.medium.com/max/663/1*ZlvtJsY2sqIjIx2k-2WMFA.png
One of the rooms found in the Pre Security ==>> How The Web Works path is DNS in Detail in which Learn how DNS works and how it helps you…
Continue reading on InfoSec Write-ups »
TryHackMe DNS In Detail Walkthrough
https://cdn-images-1.medium.com/max/663/1*ZlvtJsY2sqIjIx2k-2WMFA.png
One of the rooms found in the Pre Security ==>> How The Web Works path is DNS in Detail in which Learn how DNS works and how it helps you…
Continue reading on InfoSec Write-ups »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Stay Ahead of the Curve: The Top Cybersecurity Skills in Demand for 2023
Cybersecurity is an ever-evolving field, and staying ahead of the curve is essential for professionals in this field. As we move into 2023…
Continue reading on Medium »
Stay Ahead of the Curve: The Top Cybersecurity Skills in Demand for 2023
Cybersecurity is an ever-evolving field, and staying ahead of the curve is essential for professionals in this field. As we move into 2023…
Continue reading on Medium »
Security jobs for junior positions
https://www.reddit.com/r/redteamsec/comments/10naw90/security_jobs_for_junior_positions/
<!-- SC_OFF -->Hi everybody, I'm trying to find some open roles in security positions. I'm not starting from the scratch, I will get a master degree in cybersecurity in 3 months, I've experience with coding, open source on Github, bug bounty, CTFs, 2 CVEs, eJPT... The problem is that 99% of the roles companies are looking for are for highly skilled / experienced people (senior, staff, VC, manager etc..). Where I can find junior positions? Are there companies looking for those roles? Thanks. (advices from experts are welcome :-) ) <!-- SC_ON --> submitted by /u/edoardottt (https://www.reddit.com/user/edoardottt)
[link] (https://www.reddit.com/r/redteamsec/comments/10naw90/security_jobs_for_junior_positions/) [comments] (https://www.reddit.com/r/redteamsec/comments/10naw90/security_jobs_for_junior_positions/)
https://www.reddit.com/r/redteamsec/comments/10naw90/security_jobs_for_junior_positions/
<!-- SC_OFF -->Hi everybody, I'm trying to find some open roles in security positions. I'm not starting from the scratch, I will get a master degree in cybersecurity in 3 months, I've experience with coding, open source on Github, bug bounty, CTFs, 2 CVEs, eJPT... The problem is that 99% of the roles companies are looking for are for highly skilled / experienced people (senior, staff, VC, manager etc..). Where I can find junior positions? Are there companies looking for those roles? Thanks. (advices from experts are welcome :-) ) <!-- SC_ON --> submitted by /u/edoardottt (https://www.reddit.com/user/edoardottt)
[link] (https://www.reddit.com/r/redteamsec/comments/10naw90/security_jobs_for_junior_positions/) [comments] (https://www.reddit.com/r/redteamsec/comments/10naw90/security_jobs_for_junior_positions/)
Ödül Avcılığı — 403 Forbidden Bypass
Merhaba arkadaşlar , bu yazımızda 403 kısıtlamasını aşmak için ne tür teknikler uygulayabiliriz ? Ve 403bypass aracını kullanarak hızlı…Continue reading on Medium »
Read more...
Merhaba arkadaşlar , bu yazımızda 403 kısıtlamasını aşmak için ne tür teknikler uygulayabiliriz ? Ve 403bypass aracını kullanarak hızlı…Continue reading on Medium »
Read more...
Securing your Infrastructure using Crowdsourced Security
Bug Bounty hunting is a crowdsourced cyber security model that helps companies utilize the power of the crowd to secure their…Continue reading on Shahmeer Amir »
Read more...
Bug Bounty hunting is a crowdsourced cyber security model that helps companies utilize the power of the crowd to secure their…Continue reading on Shahmeer Amir »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
I’m a newbie
I tried to download tor for my windows 11 and my settings didn’t allow it, probably cos it’s not a trusted file ect. Could someone point me in the right direction ?
submitted by /u/Fogholadebitch
[link] [comments]
I’m a newbie
I tried to download tor for my windows 11 and my settings didn’t allow it, probably cos it’s not a trusted file ect. Could someone point me in the right direction ?
submitted by /u/Fogholadebitch
[link] [comments]
Hide Evidences in Hacked System
https://medium.com/@cyber.sec.mumbai.000/hide-evidences-in-hacked-system-95c52bbce010?source=rss------bug_bounty-5
https://medium.com/@cyber.sec.mumbai.000/hide-evidences-in-hacked-system-95c52bbce010?source=rss------bug_bounty-5