Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
From Zero to Free Credits: Abusing a Referral System Like a Lazy Genius

”I wasn’t planning to break anything. I just wanted free stuff.” – A bored bug hunter, probably meContinue reading on LegionHunters »
Read more...
20+ Lesser-Known Linux Commands Every Hacker & Sysadmin Should Master

Introduction: Why Go Beyond the Basics?Continue reading on Medium »
Read more...
How to get into bug bounties — A list of resources V2.0

Hello friends, I’ve seen this question come by often so I’ve decided to try and group all the resources of myself that I have about…Continue reading on Medium »
Read more...
Cracking JWTs: A Bug Bounty Hunting Guide [Part 7] — The Final P1 Boss

JWT Authentication Bypass via Algorithm Confusion Exploit Without Key DisclosureContinue reading on Medium »
Read more...
How can you start bug hunting in 2025, even in the middle of the year?Continue reading on Medium » (https://medium.com/@Tenebris_Venator/how-i-would-start-bug-bounty-in-mid-2025-3cdbd3f726fb?source=rss------bug_bounty-5)
Web Application Penetration Testing

Comprehensive Web Application Testing GuideContinue reading on Medium »
Read more...
Github - chillyilly/SPFShadow: utility to find subdomains with permissive or nonexistant SPF records.
https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/

<!-- SC_OFF -->This is a great way to bypass email filters. Has worked on current engagements <!-- SC_ON --> submitted by /u/cooldadhacking (https://www.reddit.com/user/cooldadhacking)
[link] (https://github.com/chillyilly/spfshadow) [comments] (https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/)
Advanced HTTP Request Smuggling (HRS) Exploitation Guide

By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness »
Read more...
By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness » (https://systemweakness.com/advanced-http-request-smuggling-hrs-exploitation-guide-53ceadd5ac19?source=rss------bug_bounty-5)
What’s the most overlooked vulnerability in modern web apps today?
https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/

<!-- SC_OFF -->Curious to hear what others think is flying under the radar in 2025. I’m seeing some wild stuff lately that doesn't show up in standard scans. <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/)
Is the industry still underestimating low-code/no-code app vulnerabilities?
https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/

<!-- SC_OFF -->These platforms are everywhere now. But are we even testing them properly? <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/)
Bypassing Authentication: A Critical Flaw in Basecamp’s

How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
How I hacked Karnataka NIC portal with a simple SQL injection

Exploiting a Blind SQL injection vulnerability in karresults.nic.inContinue reading on InfoSec Write-ups »
Read more...
Broken Object Level Authorization (BOLA): Complete Guide — Part 1

📌 What is BOLA and Why It’s the #1 API Risk You Shouldn’t IgnoreContinue reading on Medium »
Read more...