Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Could XSS Be the Hidden Key to Account Takeover

What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
GraphQL Gatecrash: When an Introspection Query Opened the Whole Backend ️

Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
$560 Bounty: How Twitter’s Android App Leaked User Location

A Silent Broadcast That Let Any App Spy on You Without AskingContinue reading on InfoSec Write-ups »
Read more...
Could XSS Be the Hidden Key to Account Takeover

What if I told you that a simple Cross-Site Scripting (XSS) vulnerability could be the golden ticket to a full Account Takeover (ATO)? No…Continue reading on InfoSec Write-ups »
Read more...
Account Takeover with OAuth Misconfiguration.

Hello folks,Continue reading on Medium »
Read more...
Cache-Busting Bonanza: How I Bypassed Rate Limits Using HTTP Weirdness

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Inspired by The Amateur, I built Enchat – a secure, encrypted terminal chat tool
https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/

<!-- SC_OFF -->After watching The Amateur, I started thinking more about truly private communication: direct, encrypted, and serverless. So I built Enchat. A lightweight terminal-to-terminal chat app that’s designed for privacy-first, ephemeral conversations. Enchat Github: https://github.com/sudodevdante/enchat Why it’s secure and private: • End-to-end encryption using Fernet (AES 128-bit under the hood) • No servers, no storage, no logs — ever • All messages vanish on exit • No user accounts, no metadata • Runs over Tor or proxychains for full anonymity • Works offline over LAN too (if needed) It’s like netcat but encrypted and made for situations where you don’t want anyone listening in.. not your ISP, not a server, not even a compromised machine in between. Would love to hear thoughts from the community especially if you care about minimal tooling, privacy, and control <!-- SC_ON --> submitted by /u/Weary_Sundae_2634 (https://www.reddit.com/user/Weary_Sundae_2634)
[link] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l7pxz1/inspired_by_the_amateur_i_built_enchat_a_secure/)
Found Critical Vulnerability: Unauthorized Access to Customer Support Emails and Data via…

I won’t be able to disclose the Proof of Concept (POC) or even the name of the company involved, as the organization has not granted…Continue reading on Medium »
Read more...
️ 5 Essential Nmap Commands Every Beginner Bug Bounty Hunter Must Know

A complete beginner’s guide to using Nmap for ethical hacking and reconContinue reading on Medium »
Read more...
If you’re into purple teaming, this article is for you. Let’s explore how red teams attack — and how blue teams can detect or stop them…Continue reading on Medium » (https://medium.com/@paritoshblogs/red-team-tactics-and-their-detection-counterparts-a-purple-team-guide-a20c18ea4402?source=rss------bug_bounty-5)
Upload2Own: How SQL Injection and File Upload Flaws Lead to Remote Code Execution

A story of persistence, subdomain hunting, and how one file upload gave me RCE on two sites.Continue reading on Medium »
Read more...
From RXSS to ATO: Bypassing WAF with a Simple POST Trick

🛡️ Vulnerability Summary:Continue reading on Medium »
Read more...
Critical Google Security Flaw Exposes Millions of Users’ Phone Numbers Through Brute-Force Attack

This comprehensive analysis examines one of the most significant cybersecurity vulnerabilities discovered in 2025.Continue reading on Medium »
Read more...
How I Made $4,260 Bypassing a Simple Username Bug

How a Single Space in a Username Field Unlocked a Samsung Bug BountyContinue reading on Medium »
Read more...
Debug Logs to Admin Panel Access

How I Accessed the Admin Panel in a Private Program on IntigritiContinue reading on LegionHunters »
Read more...
Bug Bounty for Beginners: The Real Talk Guide (No BS Edition)

A French DBA’s Guide to Actually Starting Bug Bounty Hunting Without Losing Your MindContinue reading on Medium »
Read more...