Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
OAuth Misuse: How Broken Flows and Open Redirects Lead to Account Hijack

From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH »
Read more...
From Innocent-Looking Redirects to Full Account Takeovers — Inside the Most Overlooked Attack Path in Modern AuthenticationContinue reading on T3CH » (https://medium.com/h7w/oauth-misuse-how-broken-flows-and-open-redirects-lead-to-account-hijack-9f280680aab5?source=rss------bug_bounty-5)
I want a reality check !
https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/

<!-- SC_OFF -->So i'm very new to pensting, i see all those people on youtube claiming you can get a six figure job straight after finishing a 3 month cert, frankly i think this is BS, so i want to know what it actually takes to get a pentesting job, i'm still in uni with 4 years to graduation, i preferably want to use this time to get a pentesting after i get my degree, if it's not realistic then how to accelerate the process and get it as fast as possible. Please be brutally objective with me as i want to hear the unfiltered opinion of professionals, i'm willing to do whatever it takes to make this goal a reality so please help me. <!-- SC_ON --> submitted by /u/Valens_007 (https://www.reddit.com/user/Valens_007)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7od12/i_want_a_reality_check/)
$250 Bounty: How I Tricked the Nextcloud Android App Into Uploading Its Own Sensitive Files

A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root AccessContinue reading on OSINT Team »
Read more...
Grafana CVE-2025–4123 | Open Redirect - XSS - SSRF

A Hands-on practical guide to earning rewards.Continue reading on OSINT Team »
Read more...
A Path Traversal Bypass That Let Attackers Exfiltrate Internal Preferences Without Root AccessContinue reading on OSINT Team » (https://osintteam.blog/250-bounty-how-i-tricked-the-nextcloud-android-app-into-uploading-its-own-sensitive-files-b481703e05cf?source=rss------bug_bounty-5)
Red Team Tactics and Their Detection Counterparts: A Purple Team Guide

If you’re into purple teaming, this article is for you. Let’s explore how red teams attack — and how blue teams can detect or stop them…Continue reading on Medium »
Read more...
$560 Bounty: How Twitter’s Android App Leaked User Location

A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
HTML Injection in Traveler Profiles

Free Article Link: Click for free!Continue reading on InfoSec Write-ups »
Read more...
Could XSS Be the Hidden Key to Account Takeover

What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
GraphQL Gatecrash: When an Introspection Query Opened the Whole Backend ️

Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
$560 Bounty: How Twitter’s Android App Leaked User Location

A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
Could XSS Be the Hidden Key to Account Takeover

What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
Account Takeover with OAuth Misconfiguration.

Hello folks,Continue reading on Medium »
Read more...