Начинаем в багбаунти: что такое уязвимости 1-day
Всем привет! С вами Михаил Ключников. Я работаю в Positive Technologies уже 10 лет, где руковожу группой по анализу защищенности ПО. Мы занимаемся п…
Tech news from the best sources
Всем привет! С вами Михаил Ключников. Я работаю в Positive Technologies уже 10 лет, где руковожу группой по анализу защищенности ПО. Мы занимаемся п…
Ultimate IDOR Testing Checklist Phase 1: Setup & Target Identification [ ] Create Test Accounts: Create two accounts (Attacker and Victim) for s…
Your Secrets Need a VDP, Not Just a Bug Bounty Bug bounty programs are valuable -- until they replace disclosure policies. Learn how unreasonable Po…
Been learning web security for a while and kept jumping between different tools for every recon task so I just built my own. It's a Python script wi…
How to Earn $10k+/Year from Bug Bounties tags: security, bugbounty, money, hacking How to Earn $10k+/Year from Bug Bounties: A Practical Roadmap You…
🛠️ Tools & Resources I Use Hack The Box VIP — practice environment for recon techniques YubiKey 5C NFC — hardware key for API token security Fre…
Cloudflare Turnstile stores a token in your browser. I found you can copy it from one browser, paste it into another, and skip the CAPTCHA completel…
Bug Bounty: CORS-to-RCE Chains in WordPress How a single misconfigured Access-Control-Allow-Origin header escalates into full Remote Code Execution…
Using AI to find authorization bugs — and to prove the ones that aren't real Draft flagship post. Safe to publish now (no undisclosed vulnerabilitie…
Привет, друзья! Сегодня хочу поговорить об одной из самых обсуждаемых тем последних лет — использовании AI в пентесте. За последние два года вокруг…
Всем привет от команды DFIR JetCSIRT! Хотим поделиться с вами одним интересным кейсом, эмоции от которого прекрасно описывает обложка... Заказчик за…
There is a music streaming platform, which is supposed to only let registered users to play and download musics from it. On the desktop view of web…
If you spend enough time poking at web applications, you’ll eventually run into a target that handles session management poorly. You’ll intercept a…
Most developers learn a hard lesson at some point in their careers: just because data is encrypted doesn't mean it’s safe from tampering. It’s an ea…
Привет, Хабр! Меня зовут Евгений Кабаргин (aka kiberjen). Я капитан KiberS, команды энтузиастов и профессионалов в области кибербезопасности. Любим…
Пока одни специалисты спорят в комментариях, способны ли нейросети эффективно искать уязвимости, я решил проверить это на практике. Я Nuit, мне 18 л…
An intentionally vulnerable e-commerce platform that teaches you to find, exploit, and understand IDOR vulnerabilities — the way they actually appea…
A Django-based vulnerable lab built to simulate real-world IDOR scenarios — not just textbook examples. If you've spent any time in Bug Bounty hunti…
Hey dev.to community! 👋 I'm Muhammad Abdullah — a CEH-certified Cybersecurity Specialist and SQA Engineer from Pakistan 🇵🇰 How It All Started My jou…
В марте 2026 многие обсуждали ситуацию с доступом к изображениям из ЛС мессенджера MAX по ссылкам, сохранённым через WebArchive. Тогда же многих не…
How to keep bug bounty findings alive in the queue: the HEAD verification matrix A practical pattern for researchers waiting weeks-to-months between…
A technical deep-dive for bug bounty hunters targeting CVE-2026–41940 — reconnaissance, exploitation chains, WAF bypasses, and report writing for ma…