#OSCP
https://github.com/OlivierLaflamme/Cheatsheet-God
https://github.com/rewardone/OSCPRepo
https://github.com/mantvydasb/RedTeam-Tactics-and-Techniques
https://github.com/ihack4falafel/OSCP
https://github.com/skavngr/rapidscan
https://github.com/0x4D31/awesome-oscp
https://github.com/frizb/Windows-Privilege-Escalation
https://github.com/AnasAboureada/Penetration-Testing-Study-Notes
https://github.com/six2dez/OSCP-Human-Guide
#bugbounty
https://github.com/OlivierLaflamme/Cheatsheet-God
https://github.com/rewardone/OSCPRepo
https://github.com/mantvydasb/RedTeam-Tactics-and-Techniques
https://github.com/ihack4falafel/OSCP
https://github.com/skavngr/rapidscan
https://github.com/0x4D31/awesome-oscp
https://github.com/frizb/Windows-Privilege-Escalation
https://github.com/AnasAboureada/Penetration-Testing-Study-Notes
https://github.com/six2dez/OSCP-Human-Guide
#bugbounty
GitHub
GitHub - OlivierLaflamme/Cheatsheet-God: Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet - OlivierLaflamme/Cheatsheet-God
SAML Security Testing Tutorial:
1 - https://t.co/0B4RizvLaB
2 - https://t.co/l5g0mK2kOr
3 - https://t.co/W0vjBsY1lu
Surface: https://t.co/8C1k5cchAl
Examples:
- https://t.co/jzthqg8tmC
- https://t.co/lRLQzOLhLU
- https://t.co/FOcni3Lqzp
1 - https://t.co/0B4RizvLaB
2 - https://t.co/l5g0mK2kOr
3 - https://t.co/W0vjBsY1lu
Surface: https://t.co/8C1k5cchAl
Examples:
- https://t.co/jzthqg8tmC
- https://t.co/lRLQzOLhLU
- https://t.co/FOcni3Lqzp
epi052.gitlab.io
How to Hunt Bugs in SAML; a Methodology - Part I -
The first in a series of three posts about a methodology for hunting bugs in SAML. This post covers background information about SAML, laying the groundwork to understand SAML vulnerabilities and attacks.
IDOR on API endpoints.
https://link.medium.com/slMkuL4Yn5
GraphQL — Common vulnerabilities & how to exploit them
https://link.medium.com/nz0Qt5S8p5
XSS WAF & Character limitation bypass like a boss
https://link.medium.com/J37WN7her5
Bypassing CSRF Protection
https://link.medium.com/FUhzdNker5
#bugbounty,#bugbountytips
https://link.medium.com/slMkuL4Yn5
GraphQL — Common vulnerabilities & how to exploit them
https://link.medium.com/nz0Qt5S8p5
XSS WAF & Character limitation bypass like a boss
https://link.medium.com/J37WN7her5
Bypassing CSRF Protection
https://link.medium.com/FUhzdNker5
#bugbounty,#bugbountytips
Medium
IDOR on API endpoints.
Hey guys,
I’m here to share my recent finding on a website which pulls me to pen down my first post. I can not disclose the name of the…
I’m here to share my recent finding on a website which pulls me to pen down my first post. I can not disclose the name of the…
RCE reports
1. https://hackerone.com/reports/591295
2.https://hackerone.com/reports/470520
3.https://hackerone.com/reports/181879
4.https://hackerone.com/reports/351014
5.https://hackerone.com/reports/658013
6.https://hackerone.com/reports/403417
7.https://hackerone.com/reports/631956
1. https://hackerone.com/reports/591295
2.https://hackerone.com/reports/470520
3.https://hackerone.com/reports/181879
4.https://hackerone.com/reports/351014
5.https://hackerone.com/reports/658013
6.https://hackerone.com/reports/403417
7.https://hackerone.com/reports/631956
HackerOne
X / xAI disclosed on HackerOne: Potential pre-auth RCE on Twitter VPN
Thanks Twitter Security Team again :) The details can be found here!
* [Attacking SSL VPN - Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case...
* [Attacking SSL VPN - Part 3: The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case...