SNsamineni nikhilinnikhilsamineni.hashnode.dev·3d ago · 7 min readI Observed a Session Management Behavior After Password Reset — What I Learned About CWE-613Introduction While learning Web Application Security and Bug Bounty, I wanted to understand how applications handle existing authenticated sessions when a user changes or resets their password. I test00
SNsamineni nikhilinnikhilsamineni.hashnode.dev·Sep 15 · 10 min readSocial Engineering & Phishing Attack — A Hands-on Cybersecurity LabIntroduction When we talk about cybersecurity, we usually think about hackers attacking computers, servers, or networks. But there is another important target: people. An attacker does not always need00
SNsamineni nikhilinnikhilsamineni.hashnode.dev·Sep 14 · 5 min readHTTPS Downgrade Attack Using Bettercap Introduction ARP Spoofing and Man-in-the-Middle Attack Using Bettercap I recently did a practical cybersecurity lab using Kali Linux, Windows 10, EVE-NG, and Bettercap. I had learned about ARP spoofin00