Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How a Common Reporting Feature Can Expose Internal InfrastructureContinue reading on T3CH » (https://medium.com/h7w/ssrf-via-pdf-export-in-analytics-dashboard-54e304b438f9?source=rss------bug_bounty-5)
From Recon to Report — A Beginner-to-Advanced Journey for Finding Real-World Security VulnerabilitiesContinue reading on OSINT Team » (https://osintteam.blog/mastering-the-hunt-the-ultimate-guide-to-modern-bug-bounty-hunting-416357b08abb?source=rss------bug_bounty-5)
$2,000 |critical Samsung Bug Bounty: Bypassing Plan Restrictions via Business Logic Flaw

During testing of Samsung VXT, I discovered a plan escalation vulnerability allowing S Plan users to access Pro Plan features by…Continue reading on Medium »
Read more...
Top Dark Web Forums With .onion Links to Explore in 2025

While the surface web hosts the majority of online conversations, the dark web remains a hidden hub of raw discussions, privacy-first…Continue reading on Medium »
Read more...
How I Found My First Critical Bug: Account Takeover via Email Verification Bypass

Let me share how I found my first critical vulnerability — a simple yet powerful bug that led to full account takeover (ATO) on an…Continue reading on Medium »
Read more...
Need advice learning Linux
https://www.reddit.com/r/Pentesting/comments/1m2tqr3/need_advice_learning_linux/

<!-- SC_OFF -->I've been thinking about getting my CompTIA Network+ certification to pursue a career in Cyber Security/Penetration Testing, but now i'm thinking i should just continue on my pre-existing knowledge of Linux. I'm wondering what's the best way to learn how to use the tools like Aircrack-ng, NMAP, and every tool on the Linux OS, whats the best way to gain hands on real life experience with out having my hand held by tryhackme or hack the box??? <!-- SC_ON --> submitted by /u/DaisyE63 (https://www.reddit.com/user/DaisyE63)
[link] (https://www.reddit.com/r/Pentesting/comments/1m2tqr3/need_advice_learning_linux/) [comments] (https://www.reddit.com/r/Pentesting/comments/1m2tqr3/need_advice_learning_linux/)
De reconocimiento pasivo a investigativo: transformando mi fase de reconocimiento en Bug Bounty

“No es la abundancia de datos lo que te descubre vulnerabilidades, sino la profundidad de tu investigación.”Continue reading on Medium »
Read more...
During testing of Samsung VXT, I discovered a plan escalation vulnerability allowing S Plan users to access Pro Plan features by…Continue reading on Medium » (https://medium.com/@aminefarah802/2-000-critical-samsung-bug-bounty-bypassing-plan-restrictions-via-business-logic-flaw-e18eace8a6cf?source=rss------bug_bounty-5)
Prompt Injection to Bounty: Part 2 — Chaining with SSRF, BOLA & RCE

In Part 1, we explored what Prompt Injection is, how it works, and how real-world systems are already being exploited. But this rabbit…Continue reading on Medium »
Read more...
Prompt-Driven Vulnerability Chains: How to Build Multi-Step Exploits from Low-Severity Bugs with AI

Security testing has evolved far beyond single-click exploits. Today, real-world compromise often requires the ability to chain multiple…Continue reading on Medium »
Read more...
Elastic Heart: How a Misconfigured Kibana Dashboard Sang Like a Canary

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
Insufficient Workflow Validation: A Logic Flaw Case Study

Discover how insecure logic in online purchase workflows can lead to major security breaches and revenue loss.Continue reading on OSINT Team »
Read more...
“$ Unearthing Digital Ghosts: How Deleted GitHub Files Can Make Your Bug Bounty Fortune”

The Illusion of “Delete”Continue reading on Medium »
Read more...
Meta Bug Bounty: Unauthorized Access and Control Over Private Image IDs on meta ai

🧠 IntroductionContinue reading on Medium »
Read more...
From Zero to Super Admin: A Bug Story from My Internship

👩🏻‍💻“13 Days. No Login. No Hope. Then… Admin Unlocked.”Continue reading on Medium »
Read more...