Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Imagina que pudieras dar instrucciones secretas al sistema operativo y obtener el resultado sin ningún tipo de filtro, utilizando un canal…Continue reading on Medium » (https://h0lm3s.medium.com/os-command-injection-simple-case-es-portswigger-601126eea44a?source=rss------bug_bounty-5)
Anyone have experience with bypassing sentinelone edr?
https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/

<!-- SC_OFF -->Im Stucked in one red team engagement. Need some guidance from experts here. <!-- SC_ON --> submitted by /u/Designer-Ad6955 (https://www.reddit.com/user/Designer-Ad6955)
[link] (https://google.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1m9hj3s/anyone_have_experience_with_bypassing_sentinelone/)
SharePoint ToolShell: The Most sophisticated Enterprise hack of 2025

By Mostefa Jakboub | Threat Hunter & Security ResearcherContinue reading on Medium »
Read more...
Insecure OTP Mechanism: How I Discovered a Replay Attack Vulnerability

Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium »
Read more...
<!-- SC_OFF -->Just published a new write-up where I walk through how a small HTTP method misconfiguration led to admin credentials being exposed. It's a simple but impactful example of why misconfigurations matter. 📖 Read it here: https://is4curity.medium.com/admin-emails-passwords-exposed-via-http-method-change-da23186f37d3 Let me know what you think and feel free to share similar cases! <!-- SC_ON --> submitted by /u/General_Speaker9653 (https://www.reddit.com/user/General_Speaker9653)
[link] (https://i.redd.it/puj4vxkmi4ff1.png) [comments] (https://www.reddit.com/r/Pentesting/comments/1m9h51p/admin_emails_passwords_exposed_via_http_method/)
The Bug Hiding in Plain Sight: A Simple Click Led to Cross-Org Account Takeover

Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…Continue reading on Medium »
Read more...
Recently, while auditing an application’s authentication mechanisms, I unearthed a subtle but serious flaw in the way it handled One-Time…Continue reading on Medium » (https://medium.com/@gowthami09027/insecure-otp-mechanism-how-i-discovered-a-replay-attack-vulnerability-a1c10e49c298?source=rss------bug_bounty-5)
Sometimes, the most powerful bugs don’t hide behind layers of complexity— they sit quietly in the open, waiting for someone to ask the…Continue reading on Medium » (https://ayaa101.medium.com/the-bug-hiding-in-plain-sight-a-simple-click-led-to-cross-org-account-takeover-82b77f640f6f?source=rss------bug_bounty-5)
SSRF via Flawed Request Parsing Leads to SSRF and Internal Admin Access

Exploiting Misconfigured Routing to Breach Internal Networks through SSRF.Continue reading on InfoSec Write-ups »
Read more...
How I Found a $3,000 Bug Using Just Recon

How I Found a $3,000 Bug Using Just ReconContinue reading on Medium »
Read more...