Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
🧪 Shift-Left Testing: Keyfiyyət Nəyə Gözlənilir?Continue reading on Medium » (https://medium.com/@rashid.alakbarov/shift-left-testing-a9293d520eaa?source=rss------bug_bounty-5)
Missing Rate Limit on Several Endpoints $1300

Hello, hunters!Continue reading on InfoSec Write-ups »
Read more...
$1000 Bounty: Account Takeover via Host Header Injection in Password Reset Flow

Free Article Link: Click for free!Continue reading on InfoSec Write-ups »
Read more...
How Hackers Exploit CORS Misconfigurations

🔐 How Hackers Exploit CORS MisconfigurationsContinue reading on InfoSec Write-ups »
Read more...
$2000 Bounty: Stored XSS in GitLab

Exploiting a stored XSS in GitLab’s repository viewer for $2000Continue reading on InfoSec Write-ups »
Read more...
Beyond Alert Boxes: Exploiting DOM XSS for Full Account Takeover

Hello Hunters, as you all know, XSS is one of the most common web vulnerabilities, often underestimated but capable of causing severe…Continue reading on InfoSec Write-ups »
Read more...
How Hackers Exploit CORS Misconfigurations

🔐 How Hackers Exploit CORS MisconfigurationsContinue reading on InfoSec Write-ups »
Read more...
$2000 Bounty: Stored XSS in GitLab

Exploiting a stored XSS in GitLab’s repository viewer for $2000Continue reading on InfoSec Write-ups »
Read more...
Query Confusion: How HTTP Parameter Pollution Made the App Spill Secrets

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Mastering Runtime Hooking with Frida — Real-World Challenges (Part 3)

Hey folks, welcome back! This is Chetan Kashyap, and I’m excited to bring you Part 3 of my ongoing series on runtime hooking using Frida…Continue reading on Medium »
Read more...
Undeleted Secrets: Uncovering an IDOR Vulnerability in “Recently Deleted” Items

During a security assessment of a web application, I identified a critical Insecure Direct Object Reference (IDOR) vulnerability within…Continue reading on Medium »
Read more...
OAuth Integration Hijack via Predictable state Parameter

Hey there! I’m Kariem Gamal, a bug hunter and penetration test. Today, I’d like to share my recent discovery of an OAuth misconfiguration…Continue reading on Medium »
Read more...
Looking for an open-source Agent that can use nmap/metasploit MCP servers
https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/

<!-- SC_OFF -->Do you know any ethical hacker agent project open-source that leverages nmap and metasplout MCP servers in order to have a fully functioning ethical hacker? <!-- SC_ON --> submitted by /u/filopedraz (https://www.reddit.com/user/filopedraz)
[link] (https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kg06zu/looking_for_an_opensource_agent_that_can_use/)
How I Found Critical Flaws in a Medical SOAP API

My €400 Bug Bounty StoryContinue reading on ILLUMINATION »
Read more...
A list of checklists for bug hunters and penetration testers

Learn new things in your bug bounty and penetration testing journey using these resourcesContinue reading on Medium »
Read more...