Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Recently, I stumbled upon a classic yet dangerous misconfiguration:
 an exposed GraphQL endpoint that handed over sensitive user data no…Continue reading on Medium » (https://medium.com/@77r4sed/%EF%B8%8F-how-i-found-an-unauthenticated-graphql-data-exposure-and-got-0-for-it-edfb07bf72a8?source=rss------bug_bounty-5)
How I Found and Exploited a Critical Remote Code Execution in OpenSSH (CVE-2024–6387) Using Shodan…
https://medium.com/@FufuFaf1/how-i-found-and-exploited-a-critical-remote-code-execution-in-openssh-cve-2024-6387-using-shodan-172b8535f53d?source=rss------bug_bounty-5

## Introduction 
Bug bounty hunting isn’t just about blasting payloads or brute forcing right away — it’s about smart reconnaissance and…Continue reading on Medium » (https://medium.com/@FufuFaf1/how-i-found-and-exploited-a-critical-remote-code-execution-in-openssh-cve-2024-6387-using-shodan-172b8535f53d?source=rss------bug_bounty-5)
In the ever-evolving landscape of cybersecurity, one of the most underestimated and overlooked vulnerabilities remains the Insecure Direct…Continue reading on Medium » (https://theosintedge.medium.com/new-types-of-hacking-idor-attacks-evolved-ce556e25572e?source=rss------bug_bounty-5)
Vulnerable and obsolete components (OWASP A06): Hacking and Bug Bounty Guide

Discover how outdated libraries and frameworks are entry points for RCE and data leakage. Protect your systems!Continue reading on Medium »
Read more...
Discover how outdated libraries and frameworks are entry points for RCE and data leakage. Protect your systems!Continue reading on Medium » (https://medium.com/@jpablo13/vulnerable-and-obsolete-components-owasp-a06-hacking-and-bug-bounty-guide-0f8b3d1736c4?source=rss------bug_bounty-5)
OS command injection, simple case [ES] [PortSwigger]

Imagina que pudieras dar instrucciones secretas al sistema operativo y obtener el resultado sin ningún tipo de filtro, utilizando un canal…Continue reading on Medium »
Read more...
Imagina que pudieras dar instrucciones secretas al sistema operativo y obtener el resultado sin ningún tipo de filtro, utilizando un canal…Continue reading on Medium » (https://h0lm3s.medium.com/os-command-injection-simple-case-es-portswigger-601126eea44a?source=rss------bug_bounty-5)
Anyone have experience with bypassing sentinelone edr?
https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/

<!-- SC_OFF -->Im Stucked in one red team engagement. Need some guidance from experts here. <!-- SC_ON --> submitted by /u/Designer-Ad6955 (https://www.reddit.com/user/Designer-Ad6955)
[link] (https://google.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/)
SharePoint ToolShell: The Most sophisticated Enterprise hack of 2025

By Mostefa Jakboub | Threat Hunter & Security ResearcherContinue reading on Medium »
Read more...
Insecure OTP Mechanism: How I Discovered a Replay Attack Vulnerability

Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium »
Read more...