Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
404 to Root: How a Forgotten Subdomain Led to Server Takeover ‍☠️

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
$2,500 Bounty: DOM-Based XSS via postMessage on Upserve’s Login Page

How a Loose Origin Check Opened the Door to Credential Theft on a Production Login PageContinue reading on InfoSec Write-ups »
Read more...
Demystifying Cookies: The Complete Guide for Bug Bounty Hunters

Everything you need to know about cookies to expand your attack surface and find real bugs.Continue reading on InfoSec Write-ups »
Read more...
They Missed This One Tiny Parameter — I Made $500 Instantly

Free Article LinkContinue reading on InfoSec Write-ups »
Read more...
The Misconfigured Magnet: How Public Buckets Exposed Millions of User Files

Hey there😁Continue reading on InfoSec Write-ups »
Read more...
Feroxbuster: The Rust-Powered Recon Weapon You’ve Been Missing

By Chintala Tarka RamContinue reading on Medium »
Read more...
How a Loose Origin Check Opened the Door to Credential Theft on a Production Login PageContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/2-500-bounty-dom-based-xss-via-postmessage-on-upserves-login-page-dc899778ed31?source=rss------bug_bounty-5)
Understanding Server Side Request Forgery (SSRF) with a Simple Real-Life Example

Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…Continue reading on Medium »
Read more...
Understanding Server Side Request Forgery (SSRF) with a Simple Real-Life Example
https://medium.com/@natarajanck2/understanding-server-side-request-forgery-ssrf-with-a-simple-real-life-example-a14650bd5317?source=rss------bug_bounty-5

Server-Side Request Forgery (SSRF) is a security vulnerability that allows an attacker to make a server perform unintended requests on…Continue reading on Medium » (https://medium.com/@natarajanck2/understanding-server-side-request-forgery-ssrf-with-a-simple-real-life-example-a14650bd5317?source=rss------bug_bounty-5)
Zerolend: Technical Analysis of the Risks and Failures Undermining Its DeFi Protocol

Zerolend aims to be a decentralized lending protocol, offering speed and flexibility for borrowing or lending crypto assets. However, a…Continue reading on Medium »
Read more...
How I Bypassed My University’s OTP System and Got Admin-Level Access (Ethical Hack)

“Curiosity is the most powerful exploit.”Continue reading on Medium »
Read more...
$5,000 | Authorization Bypass via Parameter Parsing Mismatch (Django — Flask)

SummaryContinue reading on Medium »
Read more...
Bug Bounty

“Step-by-step notes from my bug bounty journey — tools, techniques, and tips.”Continue reading on Medium »
Read more...
Should I Move On? Looking for Insights from Cybersecurity Professionals
https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/

<!-- SC_OFF -->Hi everyone, I’m currently working in the cybersecurity domain with around 2 years of experience. However, I feel that my current skill level is not quite up to par with industry standards. The company I work for has very few projects, and unfortunately, it’s been difficult for me to grow or upskill due to the lack of real-world exposure. I’ve been considering starting a job search to move to a company where I can work on actual projects and be around more experienced professionals to accelerate my learning. For those of you working as pentesters or in similar roles — do you think it's a good idea to shift companies at this stage? Would moving to a more dynamic environment help me grow faster? Any advice or suggestions would be really appreciated! Thanks in advance! <!-- SC_ON --> submitted by /u/NenuDhevudini (https://www.reddit.com/user/NenuDhevudini)
[link] (https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/) [comments] (https://www.reddit.com/r/Pentesting/comments/1krydqf/should_i_move_on_looking_for_insights_from/)