Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
SQL Vulnerability in WordPress Automatic Plugin (CVE-2024–27956)

OverviewContinue reading on Medium »
Read more...
How I Bypassed 2FA and Earned My First Bounty $$$

Hacker Summary:Continue reading on Medium »
Read more...
Day 15 of 30 Days — 30 Vulnerabilities | ClickJacking

Day 15: Mastering ClickJacking Vulnerability — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
What to check after automated scan
https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/

<!-- SC_OFF -->Hi, We’re currently using automated scanning tools for our web application, which effectively catch the usual vulnerabilities. I’m curious to know what additional checks or manual assessments you typically perform after the automated scans. For instance, do you focus on areas like error handling, access control, or something else? Any insights on key areas that might be overlooked by automated tools would be greatly appreciated! <!-- SC_ON --> submitted by /u/TheITSecGuy (https://www.reddit.com/user/TheITSecGuy)
[link] (https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/)
HTML Injection in Mobile App Support Ticket Form on target.tech

Overview: I was invited to a private bug bounty program hosted on YesWeHack. After reviewing the program’s rules, during this testing…Continue reading on Medium »
Read more...
Needing bug bounty results for a 6-month internship - does it make sense ?
https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/

<!-- SC_OFF -->Hi there, it's been a year since I decided to switch careers and focus on pentesting. I recently started looking for an internship in my area (Belgium) and found an interesting company. I saw they were seeking an intern for 6 months, but after some emails, I quickly hit a wall. They asked me for bug bounty history and ultimately chose someone else who had already had some success in bug bounties. Should an intern already be able to manage bug hunting independently? This situation left me a bit lost. I’ve spent a lot of time learning and practicing almost all types of web vulnerabilities, and I completed all the PortSwigger labs. I thought that would be an adequate level of knowledge to get an internship in the field. As I want to work at that company, I spent the weekend working on some programs listed on HackerOne, and I'll probably continue until I have at least one "credit" to put on my resume. But what are your thoughts on this? Should an intern already have that level of experience? What level do you expect when hiring an intern in pentesting? Thanks! <!-- SC_ON --> submitted by /u/Snoo_11846 (https://www.reddit.com/user/Snoo_11846)
[link] (https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/)
Advanced Techniques and Emerging Trends in Web Cache Poisoning

Exploring the Mechanics, Risks, and Defense Strategies Against Web Cache Poisoning Attacks. Web cache poisoning is a sophisticated attack…Continue reading on Medium »
Read more...
Day 15: Mastering ClickJacking Vulnerability — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium » (https://it4chis3c.medium.com/day-15-of-30-days-30-vulnerabilities-clickjacking-592505aff54d?source=rss------bug_bounty-5)
Overview: I was invited to a private bug bounty program hosted on YesWeHack. After reviewing the program’s rules, during this testing…Continue reading on Medium » (https://medium.com/@shobitsharma/html-injection-in-mobile-app-support-ticket-form-on-target-tech-f45d2de510af?source=rss------bug_bounty-5)