Skip to content
Latest
BTR.sys Shows Why Trusted Security Drivers Need Behavioral MonitoringWeedHack Shows SEO Poisoning Is Malware Delivery InfrastructureAI Agent Incidents Need Task-Scoped Incident ResponseSDLC Supply-Chain Attacks Show Why Developer Tools Need Runtime ControlsRussian Auth-Flow Phishing Shows MFA Can Be Bypassed Without ExploitsFake AI Tools Show Brand Trust Has Become Malware DeliveryStopAndProtect Shows Why WordPress Sites Are Attack InfrastructureMacSync Stealer Shows Why Behavioral Pivots Beat Rotating DomainsPurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk ControlGitLab GraphQL Flaw Shows Why DevSecOps Platforms Need Emergency Patch RunbooksForminator RCE Shows Why WordPress Plugin Risk Needs Runtime ControlsC2Looper Shows Why GitHub-Based C2 Belongs in Ransomware TriageVMware vCenter Exploitation Shows Why Patching Is Not Incident ClosureRansomware’s Long Tail Means Defenders Need Faster Triage

Category Archive

Bug Bounty

8 reports · All intelligence

Bug bounty and vulnerability research — write-ups, methodology, and findings from real-world testing.

Bug Bounty
TBHM Live Training with Jhaddix
Bug Bounty·

TBHM Live Training with Jhaddix

Attending The Bug Hunters Methodology Live training by Jason Haddix was a great experience. I think my goal with writing this post is really to paint a picture of my overall personal experience being new to Bug Bounty Hunting, coming from the Blue Teaming side of things, and to j

Bug Bounty
Endpoints vs Routes: What every API hacker needs to know
Bug Bounty·

Endpoints vs Routes: What every API hacker needs to know

READ ARTICLE DANA EPP’S BLOG API Hacking Fundamentals February 13, 2024 I recently had an interesting conversation on Twitter/X that got me thinking about API endpoints vs routes. It all started with this tweet: The conversation progressed into whether this was one vulnerability

Bug Bounty
Detecting API endpoints and source code with JS Miner
Bug Bounty·

Detecting API endpoints and source code with JS Miner

Read Article DANA EPP’S BLOG Security (de)engineering for fun and profit Let’s be honest. Most APIs are naked without some sort of web app frontend calling it. These days, those apps are usually written in some sort of framework based on Javascript. With a bit of work, we can do

Bug Bounty
Book.HackTricks
Bug Bounty·

Book.HackTricks

To the Book! Disclaimer This book, ‘HackTricks,’ is intended for educational and informational purposes only. The content within this book is provided on an ‘as is’ basis, and the authors and publishers make no representations or warranties of any kind, express or implied, about

Bug Bounty
Virtual Host Enumeration for Uncovering Hidden Subdomains
Bug Bounty·

Virtual Host Enumeration for Uncovering Hidden Subdomains

Read Article Nairuz Abulhul – Nov 28, 2023 | Published in R3d Buck3T | 8 min read When performing external penetration testing or bug bounty hunting, we explore the targeted system from various angles to collect as much information as possible to identify potential attack vectors

Bug Bounty
SQLmap Cheat Sheet
Bug Bounty·

SQLmap Cheat Sheet

Link to Sheet

Bug Bounty
Announcing cvemap from ProjectDiscovery
Bug Bounty·

Announcing cvemap from ProjectDiscovery

Read Article Project Discovery Tool ManagerGitHub pdtm is a simple and easy-to-use golang based tool for managing open source projects from ProjectDiscovery. Security professionals are constantly on guard against cyber threats, especially given the rising number and sophisticatio

Bug Bounty
From Akamai to F5 to NTLM… with love.
Bug Bounty·

From Akamai to F5 to NTLM… with love.

Read Article Discovery Note: This paper will be covering 1 smuggle gadget out of about 10 that I use in my testing, however this paper will show how this gadget, originally found by @albinowax, can be modified to pin one provider against another in a brutal fashion as you will re

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.