PinnedInentersoftsecuritybysecureITmania·May 31, 2020Weird “Subdomain Take Over” pattern of Amazon S3Even though you have an idea on the subdomain takeover via AWS S3. In this write-up, I will show the non-typical way of S3 subdomain
secureITmania·Apr 22Bug Bounty $$$ Write-up: OTP BypassHow an Eagle-Eyed Observation Led to a Critical Account Takeover
secureITmania·May 29, 2024S3 bucket enumeration simplified.A web-based tool to scan the S3 bucket misconfiguration.A response icon1A response icon1
secureITmania·Apr 28, 2024Never use the GET method for Sensitive Actions in Web App: Ft. CSRFThe Limitation of Cookie’s “SameSite: Lax” SecurityA response icon1A response icon1
secureITmania·Oct 15, 2023Why Appropriate Content-Type Header Matters In REST API Security: Ft. JSON XSSLet's Explore the Content-Type Header Role in API Security
secureITmania·Sep 30, 2023The Art of Identifying X$$ & WAF Bypass Fuzzing TechniqueA smart way to hunt Cross-Site Scripting vulnerability
secureITmania·Jul 11, 2023Learn and Earn with the Most Common Unsecured Methods of OTP Bypass Techniques: Unpacking the…Discover the ultimate guide for bug bounty hunters to detect sneaky OTP validation vulnerabilities!
secureITmania·Jun 2, 2023The Importance of Checking User-Agent Header Dependency in Penetration TestingNever ever give a chance to leave a bug to automated scanners.
secureITmania·Jul 1, 2022Secure docker instance with basic AuthenticationNginx reverse proxy with Basic Authentication
secureITmania·Nov 12, 2021Never leave this tip while you hunting Broken Access ControlA special Bug-Bounty tip for Bug hunters and Pen-testers