⤷ Title: VULNBANK API SECURITY ASSESSMENT
════════════════════════
𐀪 Author: Lh1l0v3
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 11:11:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #software_engineering #software_development #web_development
════════════════════════
𐀪 Author: Lh1l0v3
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 11:11:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #application_security #software_engineering #software_development #web_development
Medium
VULNBANK API SECURITY ASSESSMENT
PART 4 — When Internal Endpoints Become Part of the Public API Surface
⤷ Title: From a Single WAF Bypass to 58,000+ Exposed Media Objects
════════════════════════
𐀪 Author: Tarek ElDemerdash
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 12:51:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #web_application_security #penetration_testing #information_security
════════════════════════
𐀪 Author: Tarek ElDemerdash
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 12:51:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #web_application_security #penetration_testing #information_security
Medium
From a Single WAF Bypass to 58,000+ Exposed Media Objects
A bug bounty case study in chaining overlooked misconfigurations into a full attack surface
⤷ Title: My First Valid Bug: A Broken Object Level Authorization (BOLA) in Customer API
════════════════════════
𐀪 Author: Abobakrmohamed
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 12:20:17 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunter #web_app_pentesting #hacking #find_your_first_bug
════════════════════════
𐀪 Author: Abobakrmohamed
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 12:20:17 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_hunter #web_app_pentesting #hacking #find_your_first_bug
Medium
My First Valid Bug: A Broken Object Level Authorization (BOLA) in Customer API
After months of grinding through labs, courses, and public program testing without a confirmed finding, I finally landed my first valid bug…
⤷ Title: Créer un Point d’Accès Wi-Fi WPA2 Professionnel avec dnsmasq, hostapd, iptables, PMF et PMFC
════════════════════════
𐀪 Author: ATTE-THM
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 13:39:29 GMT
════════════════════════
⌗ Tags: #hacking #dhcp #linux #networking #web_development
════════════════════════
𐀪 Author: ATTE-THM
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 13:39:29 GMT
════════════════════════
⌗ Tags: #hacking #dhcp #linux #networking #web_development
⤷ Title: I Thought I Understood HTTP — Then I Opened Burp Suite
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 13:59:28 GMT
════════════════════════
⌗ Tags: #https #ethical_hacking #web_security #cybersecurity #burpsuite
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 13:59:28 GMT
════════════════════════
⌗ Tags: #https #ethical_hacking #web_security #cybersecurity #burpsuite
Medium
I Thought I Understood HTTP — Then I Opened Burp Suite
A hands-on journey into HTTP requests, responses, headers, cookies, and web application security.
⤷ Title: PortSwigger File Path Traversal Lab Solution, Simple Case
════════════════════════
𐀪 Author: Arham H.B
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:26:43 GMT
════════════════════════
⌗ Tags: #portswigger #portswigger_lab #web_security #cybersecurity #bug_bounty
════════════════════════
𐀪 Author: Arham H.B
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:26:43 GMT
════════════════════════
⌗ Tags: #portswigger #portswigger_lab #web_security #cybersecurity #bug_bounty
Medium
PortSwigger File Path Traversal Lab Solution, Simple Case
Web Security Academy by PortSwigger
⤷ Title: Hammer (THM) — Rate Limits JWT Forgery
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:37:21 GMT
════════════════════════
⌗ Tags: #jwt #tryhackme #web_exploitation #hammer #thm_writeup
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:37:21 GMT
════════════════════════
⌗ Tags: #jwt #tryhackme #web_exploitation #hammer #thm_writeup
Medium
Hammer(THM) — Rate Limits JWT Forgery
Hammer(THM) — Rate Limits JWT Forgery A web exploitation writeup covering directory fuzzing, password-reset brute forcing, rate-limit bypass via IP spoofing, command injection, and JWT key …
⤷ Title: Client-Side Web Security Essentials
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:30:03 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #ethical_hacking #bug_hunter #web_pen_testing
════════════════════════
𐀪 Author: Ph
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 15:30:03 GMT
════════════════════════
⌗ Tags: #web_development #cybersecurity #ethical_hacking #bug_hunter #web_pen_testing
Medium
Client-Side Web Security Essentials
Modern web apps aren’t just “pages in a browser” — they’re interactive systems where the client (browser) and the server continuously…
⤷ Title: picoCTF: No FA
════════════════════════
𐀪 Author: Parthib Dewanjee
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 14:14:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_exploitation #ethical_hacking #picoctf #ctf_writeup
════════════════════════
𐀪 Author: Parthib Dewanjee
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 14:14:19 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_exploitation #ethical_hacking #picoctf #ctf_writeup
Medium
picoCTF: No FA
Challenge Description
⤷ Title: Dorks that could get you a good bounty in 2026
════════════════════════
𐀪 Author: Deepanshu Deep
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #google_dorking #web_security #osint
════════════════════════
𐀪 Author: Deepanshu Deep
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 17:01:43 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #google_dorking #web_security #osint
Medium
Dorks that could get you a good bounty in 2026
Google can index far more than publicly intended webpages. During an authorized bug bounty assessment, search operators can help…