Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How can you start bug hunting in 2025, even in the middle of the year?Continue reading on Medium » (https://medium.com/@Tenebris_Venator/how-i-would-start-bug-bounty-in-mid-2025-3cdbd3f726fb?source=rss------bug_bounty-5)
Web Application Penetration Testing

Comprehensive Web Application Testing GuideContinue reading on Medium »
Read more...
Github - chillyilly/SPFShadow: utility to find subdomains with permissive or nonexistant SPF records.
https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/

<!-- SC_OFF -->This is a great way to bypass email filters. Has worked on current engagements <!-- SC_ON --> submitted by /u/cooldadhacking (https://www.reddit.com/user/cooldadhacking)
[link] (https://github.com/chillyilly/spfshadow) [comments] (https://www.reddit.com/r/redteamsec/comments/1l9087z/github_chillyillyspfshadow_utility_to_find/)
Advanced HTTP Request Smuggling (HRS) Exploitation Guide

By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness »
Read more...
By Shah kaif | “Two headers. One request. Your rules.” | LinkedInContinue reading on System Weakness » (https://systemweakness.com/advanced-http-request-smuggling-hrs-exploitation-guide-53ceadd5ac19?source=rss------bug_bounty-5)
What’s the most overlooked vulnerability in modern web apps today?
https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/

<!-- SC_OFF -->Curious to hear what others think is flying under the radar in 2025. I’m seeing some wild stuff lately that doesn't show up in standard scans. <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8plcm/whats_the_most_overlooked_vulnerability_in_modern/)
Is the industry still underestimating low-code/no-code app vulnerabilities?
https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/

<!-- SC_OFF -->These platforms are everywhere now. But are we even testing them properly? <!-- SC_ON --> submitted by /u/Competitive_Rip7137 (https://www.reddit.com/user/Competitive_Rip7137)
[link] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/) [comments] (https://www.reddit.com/r/Pentesting/comments/1l8pm3n/is_the_industry_still_underestimating/)
Bypassing Authentication: A Critical Flaw in Basecamp’s

How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
How I hacked Karnataka NIC portal with a simple SQL injection

Exploiting a Blind SQL injection vulnerability in karresults.nic.inContinue reading on InfoSec Write-ups »
Read more...
Broken Object Level Authorization (BOLA): Complete Guide — Part 1

📌 What is BOLA and Why It’s the #1 API Risk You Shouldn’t IgnoreContinue reading on Medium »
Read more...
Broken Object Level Authorization (BOLA): Complete Guide — Part 2

🔍 Part 2: Where BOLA Hides — Common Vulnerable SpotsContinue reading on Medium »
Read more...
Bypassing Authentication: A Critical Flaw in Basecamp’s

How Attackers Can Hijack Accounts Using Outdated Passwords and 2FA Backup CodesContinue reading on InfoSec Write-ups »
Read more...
OAuth2verdrive: How Broken Token Exchange Let Me Log in as Any User

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
A classic file based IDOR on NIELIT portal

Hello and welcome to all! This is Adithya M S, a novice web hacker passionate about digging deep into how website endpoints work and how their parameters may be tampered with. Disclaimer: The content provided in this article is for educational and informational purposes only. Always ensure you have proper authorization before conducting security assessments. Use this information responsibly. Neither me nor the publication may be held liable for any harm, damage or legal trouble caused by acting on the information contained in this blog post. Please exercise discretion. In this blog, I shall share my experience of exploiting a file based IDOR in the NIELIT website. If you have NOT heard of the term IDOR before, it stands for Insecure Direct Object Reference and occurs when a web server takes internal references to resources (such as files, other records) as parameters/inputs in paths or queries (in web requests) and handles them in an insecure way to respond with the corresponding resource. There are many nice articles on the web to get some more clarity on IDOR. Here is one such reference. Insecure direct object references (IDOR) | Web Security Academy Now let’s get started. NIELIT is an Indian government institute that focuses on developing human resources and related activities in the field of Information, Electronics, and Communications Technology. NIELIT also conducts an entrance examination every year to select students for its various programs. My brother applied for this exam and thus I was able to login by getting his credentials and see the various sections of the website available to logged in users. One of the sections is to review the filled application form. Part of this page also contains links to view 3 documentsApplication Form review page partApplication form review page Now we click on one of these links to view the uploaded documents fileDocument at the URL https://nltchd.info/nielituniv25/Uploads/canddocx/71399_documents.pdf Now 71399 is the registration number of my brother. The same appears in the URL to view his uploaded documents https://nltchd.info/nielituniv25/Uploads/canddocx/71399_documents.pdf. What if we change this number to say 71405 ?Document at the URL https://nltchd.info/nielituniv25/Uploads/canddocx/71405_documents.pdf Wow!!, we get the documents of the user with registration number 71405 The same technique holds for the photo and signature files. Their names follow the same pattern and contain the candidate registration number. Anyone can access everybody else’s documents !! What an IDOR ?? I hope you guys had fun reading this blog and Happy hacking !! Please follow me and give me some claps 👏 if you liked this post. Please comment on this post to give me any feedback that you may have and let me know how to get this bug resolved. Thank you again for reading my article !! A classic file based IDOR on NIELIT portal was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
How a Simple RECON Earned Me ₹XX,000

Security bugs aren’t always flashy. Sometimes, you don’t need to pop a shell or find an RCE to make an impact. Sometimes… all you need is a little curiosity and a lot of recon.This is the story of how I stumbled upon an exposed origin IP at XYZ, India’s largest stock brokerage, and how that led to an unexpected ₹XX,000 bounty — all without writing a single exploit. It started with a late-night recon session… Like most bug bounty hunters, I was doing my usual late-night stroll across a domain — XYZ’s public-facing assets. WAF? Cloudflare. Endpoints? Mostly locked. But I had a hunch. Out came Shodan, my favorite search engine for all the things you shouldn’t see. One quick dork later:Ssl.cert.subject.CN:"domain.com" 200 And boom — I landed on an IP: 11.1.111.11 An Amazon EC2 instance quietly serving traffic… and not a trace of Cloudflare in sight.🧠 “Wait… is this really accessible?” I typed in: https://11.1.111.11/login It loaded. No 403. No timeout. Just a clean login page staring right back at me. I double-checked with tools: no WAF, no CDN headers, and the cert? Signed for domain.com. Bingo.https://medium.com/media/87df765490ce9e17249ba194985938b1/href🤔 But is it a bypass? Here’s where it got interesting. XYZ uses Cloudflare for protection — rate limiting, WAF, DDoS, the works. But this subdomain — sub.domain.com— wasn’t behind it. At first glance, that might seem like a non-issue. Maybe internal, maybe forgotten. But to an attacker? It’s an open door. Direct origin access means you can:Bypass rate limitsFuzz without detectionBrute force at full throttleEven launch DDoS attacks — because there’s no shield in place And it all stems from one thing: security misconfiguration.📬 The response that made me smile I reported it privately through ComOlho, their bug bounty platform. Soon after, XYZ got back:“Hey Swarnim, we discussed this internally… it’s not behind Cloudflare for some internal reasons. But because of your report, we’re now discussing whether to fix it. Please repost publicly — we’ll process your bounty.” I wasn’t expecting a big payout — just happy they took it seriously. But then… ₹XX,000 dropped into my account. No exploit. No shell. Just impact.💡 What I learnedBug bounties aren’t about breaking things — they’re about finding things that are broken.Even “boring” bugs matter — origin IP exposure can change the threat model completely.If it feels too quiet… dig deeper — sometimes the loudest vulnerabilities whisper.🚀 To all bug hunters out there… Don’t chase just the CVEs. Don’t underestimate the power of recon, curiosity, and context. This was one IP. One misconfiguration. And it paid off — literally and figuratively. Thanks, XYZ. And shoutout to platforms like ComOlho for making security collaborative and rewarding. Time to go hunting again. 🔍💻 If you liked this story, give it a 👏 and share it with fellow hackers. Stay safe. Stay curious. — Swarnim BandekarConnect with me: Swarnim Bandekar Linkedin: https://www.linkedin.com/in/swarnimbandekar/ 💰 How a Simple RECON Earned Me ₹XX,000 was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...