Out today: @SynackRedTeam member @naglinagli shares his thoughts on Mass Assignment exploitation / privilege escalation vulnerabilities. Read the blog: https://t.co/ZzaxZeov6i
New Write-up on InfoSec Write-ups publication : "Leveraging Burp Suite extension for finding HTTP request smuggling." #bugbounty#bugbountywriteup#bugbountytips https://t.co/RAy1JrcAID
Here is a quick summary for penetration testers of what you want to consider when analysing the log output of an iOS app:
https://t.co/mLOQUzpRcH
Happy Hacking ⛏
When Fuzzing For Directories Follow these wordlists.
1. dirsearch
2. directory-list-2.3-medium
3. httparchive_directories
4. Raft
5. RobotsDisallowed
Then go for technology-specific chances are high with these wordlists
[1/2]
#bugbounty#bugbountytips
I think @MobiKwik Security team accepted the breach but @MobiKwik didn't. And now everyone has proofs. I've also checked the breached data.
In digital world, no-one can be secure. Accept it!!!
#MobikwikDataLeak#MobikwikDataBreach
Finally, our legal team will be pursuing strict action against this so-called researcher who is trying to malign our brand reputation for ulterior motives. n/n
-Team MobiKwik
Tools designed to automate phishing attacks that are intended to bypass 2FA
evilginx2: https://t.co/9haUXdvpV1
Modlishka: https://t.co/mHNvbvYzF7
KoiPhish: https://t.co/JTA9T4r5yF
ReelPhish https://t.co/FXtzjwgCYG
CredSniper:https://t.co/mFTPZYg8xY
muraena:https://t.co/e5Cl66DsFv