Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How a CSRF Vulnerability Can Be Exploited to Target Email Accounts — A Practical Walkthrough

In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…Continue reading on Medium »
Read more...
How a CSRF Vulnerability Can Be Exploited to Target Email Accounts — A Practical Walkthrough
https://medium.com/@muhammedgalal66/how-a-csrf-vulnerability-can-be-exploited-to-target-email-accounts-a-practical-walkthrough-60e6c2eac31f?source=rss------bug_bounty-5

In this article, I’ll guide you through a practical example of exploiting a Cross-Site Request Forgery (CSRF) vulnerability that allows an…Continue reading on Medium » (https://medium.com/@muhammedgalal66/how-a-csrf-vulnerability-can-be-exploited-to-target-email-accounts-a-practical-walkthrough-60e6c2eac31f?source=rss------bug_bounty-5)
From User to Admin: The Art of Privilege Escalation
https://bootcampsecurity.medium.com/from-user-to-admin-the-art-of-privilege-escalation-b80a4cd1e89b?source=rss------bug_bounty-5

“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?Continue reading on Medium » (https://bootcampsecurity.medium.com/from-user-to-admin-the-art-of-privilege-escalation-b80a4cd1e89b?source=rss------bug_bounty-5)
Dica de enumeração de subdomínios através da homepage de um alvo utilizando nada menos do que somente um terminal linux e o básico de…Continue reading on Medium » (https://medium.com/@sarkis093/enumera%C3%A7%C3%A3o-de-subdom%C3%ADnios-atrav%C3%A9s-da-homepage-971d7aa341bf?source=rss------bug_bounty-5)
From User to Admin: The Art of Privilege Escalation

“What if I told you that the biggest risk in your web app isn’t hacking the login, but what comes after someone gets in?Continue reading on Medium »
Read more...
Enumeração de subdomínios através da homepage

Dica de enumeração de subdomínios através da homepage de um alvo utilizando nada menos do que somente um terminal linux e o básico de…Continue reading on Medium »
Read more...
Critical Authentication Vulnerability in SAP BusinessObjects Business Intelligence Platform (CVE-2024-41730, CVSS 9.8/10)
https://www.reddit.com/r/Pentesting/comments/1guu7ac/critical_authentication_vulnerability_in_sap/
Exploiting Business Logic Flaws in e-commerce platforms

Exploiting business logic flaws involves identifying weaknesses in the platform’s workflows or processes that can be manipulated by…Continue reading on Medium »
Read more...
Common Security Risks in Browser Extensions

In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…Continue reading on Medium »
Read more...
HOW I FOUND A BUG IN NASA

Hello, everyone! I hope you’re doing great. Today, I’m excited to share an incredible story about my recent experience hunting bugs in…Continue reading on Medium »
Read more...
Exploiting business logic flaws involves identifying weaknesses in the platform’s workflows or processes that can be manipulated by…Continue reading on Medium » (https://medium.com/@Pentestforge/exploiting-business-logic-flaws-in-e-commerce-platforms-c3042a240c4a?source=rss------bug_bounty-5)
Common Security Risks in Browser Extensions
https://medium.com/@Parag_Bagul/common-security-risks-in-browser-extensions-e61422499f7c?source=rss------bug_bounty-5

In this blog, we’ll explore some of the most common security vulnerabilities found in browser extensions, with examples of vulnerable code…Continue reading on Medium » (https://medium.com/@Parag_Bagul/common-security-risks-in-browser-extensions-e61422499f7c?source=rss------bug_bounty-5)
Pentesting Advice for Startup
https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/

<!-- SC_OFF -->We're a small startup and about to select a vendor for a pentest. Our quotes are ranging from $1k to $12k. We are looking for a blackbox test on 3 URLs and network vulnerability. Of course, we want to keep costs low, but our colleague is suggesting that we need to use a reputable company that is public facing (has a website) and based in the US or first-world country. We work with small financial institutions, so his rationale is that the stamp on the pentest report will matter (I don't think it does), and also that if you allow a company or person in 3rd world countries that you're exposing yourself to risk if they are able collect the data, and they could share our vulnerabilities with others that can hack us. Suggestions? <!-- SC_ON --> submitted by /u/Brain-Abject (https://www.reddit.com/user/Brain-Abject)
[link] (https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/) [comments] (https://www.reddit.com/r/Pentesting/comments/1gv57ft/pentesting_advice_for_startup/)
How I Uncovered an Unsubscribe Exploit While Checking My Internship Applications

IntroductionContinue reading on Medium »
Read more...
Chinese Hackers Exploit Fortinet VPN Zero-Day to Steal Credentials

WIRE TOR — The Ethical Hacking ServicesContinue reading on Medium »
Read more...