Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
XSS in Hidden Input Without User Interaction

IntroductionContinue reading on Medium »
Read more...
Hacking APIs: Exploiting Shadow APIs and Forgotten Endpoints

Most companies focus on protecting their main APIs. But attackers know that the real gold often hides in places security teams forget: old…Continue reading on Medium »
Read more...
Cracking JWTs: A Bug Bounty Hunting Guide [Part 6]

JWT Authentication Bypass via Algorithm ConfusionContinue reading on InfoSec Write-ups »
Read more...
Most companies focus on protecting their main APIs. But attackers know that the real gold often hides in places security teams forget: old…Continue reading on Medium » (https://iaraoz.medium.com/hacking-apis-exploiting-shadow-apis-and-forgotten-endpoints-9930c78e7c2d?source=rss------bug_bounty-5)
Bypass Cerrificate Pinning for thick Client applicatio n
https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/

<!-- SC_OFF -->Anyone here had experience with thick client application pentesting and could actually bypass cerrificate pinning ? I am using proxifier and Burp and the application fails whener I try to forward and intercept requests. I can see traffic happening using wireshark. Any suggestions ? <!-- SC_ON --> submitted by /u/ceasar911 (https://www.reddit.com/user/ceasar911)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7h78a/bypass_cerrificate_pinning_for_thick_client/)
GraphQL Role Escalation and Data Exposure

.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
.بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium » (https://medium.com/@omerasraan/graphql-role-escalation-and-data-exposure-4cc340431289?source=rss------bug_bounty-5)
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack

From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH »
Read more...