Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Ethical Hacking Assignment - getting root from an IP/Site
https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/

<!-- SC_OFF -->Hi, I am a 4th semester of computer sciences right now and I'm working on my final project, which is getting root access of a site/ip using kali linux, we've attempted to use gobuster and metasploit, however, both methods are considered brute forcing and it simply isn't effective based on our deadline which is in a few days. The system we're trying to take root over uses linux so eternalbblue wouldn't work as well. Any tips on what method we should use. The goal here is to use kali to get the root access of server3.pentest.id (http://server3.pentest.id/) (this is a fake site that my lecturer gave us}. Also we found the vulnerable ports that are open already, there are 2 to be exact. So i guess we need to utilize those open ports. <!-- SC_ON --> submitted by /u/Seraphims-Monody (https://www.reddit.com/user/Seraphims-Monody)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxknz5/ethical_hacking_assignment_getting_root_from_an/)
Cracking JWTs: A Bug Bounty Hunting Guide [Part 1]

JWT Authentication Bypass via Unverified and Flawed Signature VerificationContinue reading on InfoSec Write-ups »
Read more...
How I Bypassed a Famous Regional Newspaper’s Subscription Plan By Http Response Manipulation

My article is open to everyone; non-member readers can click this link to read the full text.Continue reading on OSINT Team »
Read more...
Windows Defender E5 auto remediation problem
https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/

<!-- SC_OFF -->During a pentest, the windows test account was found by Defender and later disabled. It seems it also added the account to 2 windows user policy settings - "Deny access to this computer from the network" and "Deny logon through Remote Desktop Services" on each item that was accessed. I don't see any group policy that has this setting added and the local policy has it but is greyed out and I am unable to remove it. Any ideas? Just need to remove it so we can continue testing or if real-world, get the user back to normal access again. <!-- SC_ON --> submitted by /u/Successful_Way_3663 (https://www.reddit.com/user/Successful_Way_3663)
[link] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxj48o/windows_defender_e5_auto_remediation_problem/)
Mastering PHP Wrappers: Concepts, Use Cases, and Security Risks

By ZoningxtrContinue reading on Medium »
Read more...
One month ago, I was looking for bugs in a prop firm platform (I’ve been trading for 3 years and have worked with many of them).
 This…Continue reading on Medium » (https://medium.com/@nimashahbazi524/how-a-simple-payment-exploit-could-take-down-a-prop-firm-and-no-one-cared-026509b54002?source=rss------bug_bounty-5)
Spidering in Security
https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5

Spidering, in the context of cybersecurity, is the process of automatically crawling a website to collect information about its structure…Continue reading on Medium » (https://medium.com/@natarajanck2/spidering-in-security-104900f56836?source=rss------bug_bounty-5)
Is it possible to be a red teamer with superior degree?
https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/

<!-- SC_OFF -->Im finishing a higher degree of web applications development, but ive noticed that I like too much the cibersecurity area. So I did some research, and red teamer seems to fit the best with what im interested in. But the thing is, do i have real spectations to find a job there without a university degree? I could do my best to get the needed certifications (if my budget allows it), but would it be enough? And if it actually is, could i make it to the top? Im just genuinely asking from ignorance, so i will appreciate constructive answers. <!-- SC_ON --> submitted by /u/Informal-Command-714 (https://www.reddit.com/user/Informal-Command-714)
[link] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/) [comments] (https://www.reddit.com/r/redteamsec/comments/1kxh5p8/is_it_possible_to_be_a_red_teamer_with_superior/)
HackingHub Lab: Scam Artists — API Hacking & Reverse Proxy Basics.NahamSec

👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium »
Read more...
👋 Hey hackers! I’m Rohit Pawar, aka ethicalrohit, and in this quick post, I’m introducing a lab walkthrough that every beginner bug…Continue reading on Medium » (https://medium.com/@ethicalrohit/hackinghub-lab-scam-artists-api-hacking-reverse-proxy-basics-nahamsec-b9b6ffd9cf90?source=rss------bug_bounty-5)
<!-- SC_OFF -->Hey everyone, our blog post this month post discusses pentest reports and how the various audiences that consume them sometimes misinterpret what they mean. We cover why findings in a report are not a sign of failure, why "clean" reports aren't always good news, and why it may not be necessary to fix every single identified vulnerability. The post concludes with a few takeaways about how the information in a pentest report helps inform the reader about the report subject's security posture. <!-- SC_ON --> submitted by /u/IncludeSec (https://www.reddit.com/user/IncludeSec)
[link] (https://blog.includesecurity.com/2025/05/misinterpreted-what-penetration-test-reports-actually-mean/) [comments] (https://www.reddit.com/r/Pentesting/comments/1kxow9n/misinterpreted_what_penetration_test_reports/)
Android Pentesting Setup Up Burpsuite Intercept

This document provides a step-by-step guide on how to set up Burp Suite to intercept and analyze traffic from a mobile device.Continue reading on Medium »
Read more...