REDSECLABS

09
Sep
REDSECLABS XSS Challenge Solution – Writeup

REDSECLABS XSS Challenge Solution – Writeup

On 30th August 2024, we released REDSECLABS XSS Challenge for the Infosec and bug bounty community, the challenge was to
6 min read
07
Sep
5 Essential Questions to Ask Your Penetration Testing Service Company

5 Essential Questions to Ask Your Penetration Testing Service Company

Introduction It’s a time when cyber threats are increasing in complexity and frequency, penetration testing has become an integral
5 min read
07
Sep
Introduction to Penetration Testing Costs - A Detailed Guide

Introduction to Penetration Testing Costs - A Detailed Guide

Pentesting (Penetration Testing) is a vital part of an organization’s cybersecurity strategy. This involves simulating cyber attacks on your
7 min read
20
May
Inside the MSP Wire Fraud Playbook: How Hackers Hijack Payments

Inside the MSP Wire Fraud Playbook: How Hackers Hijack Payments

Date/Time Event 15th March 2024 Attacker logged in to the Global account 15th March 2024 Attacker elevated privileges of
6 min read
05
May
Browser Vulnerabilities: Microsoft Edge, Safari and DuckDuckGo Address Bar Spoofing vulnerabilities

Browser Vulnerabilities: Microsoft Edge, Safari and DuckDuckGo Address Bar Spoofing vulnerabilities

RedSecLabs security researchers Rafay Baloch and Muhammad Samaak discovered address bar spoofing vulnerabilities in widely used mobile browsers such as
2 min read
25
Mar
Web Hacking Arsenal Book Available For Pre-Order

Web Hacking Arsenal Book Available For Pre-Order

For most of 2023, I devoted my time to writing my book, scheduled for publication in August 2024, titled as
3 min read
06
Mar
Case Study: Credit Card Stealer Backdoor

Case Study: Credit Card Stealer Backdoor

REDSECLABS was contracted to perform a backdoor analysis for a customer operating a large e-commerce platform, following complaints from customers
4 min read
28
Jan
Critical Security Flaws in Pure VPN: Code Execution and IP Address Disclosure

Critical Security Flaws in Pure VPN: Code Execution and IP Address Disclosure

Introduction In this blog post, we shed light on two critical vulnerabilities discovered within PureVPN. One involves an alarming IP
4 min read