Dalam dunia Bug Bounty, skill memang penting tapi tools yang tepat adalah pengungkit kemampuanmu. Sama seperti seorang tukang tidak bisa…Continue reading on Medium » (https://medium.com/@krisnawhy300/bug-bounty-series-3-tools-bug-bounty-untuk-pemula-9725141bf8cc?source=rss------bug_bounty-5)
GraphQL for the next API Penetration Testing
In this article, I will share a guide that may be useful for you wherever you are. May you be blessed with protection and good health.Continue reading on Medium »
Read more...
In this article, I will share a guide that may be useful for you wherever you are. May you be blessed with protection and good health.Continue reading on Medium »
Read more...
Medium
GraphQL for the next API Penetration Testing
In this article, I will share a guide that may be useful for you wherever you are. May you be blessed with protection and good health.
Bug Bounty - La mejor herramienta es una mente incómoda
https://gorkaaa.medium.com/bug-bounty-la-mejor-herramienta-es-una-mente-inc%C3%B3moda-45c3309ca923?source=rss------bug_bounty-5
https://gorkaaa.medium.com/bug-bounty-la-mejor-herramienta-es-una-mente-inc%C3%B3moda-45c3309ca923?source=rss------bug_bounty-5
1. Introducción: el poder del pensamiento disidenteContinue reading on Medium » (https://gorkaaa.medium.com/bug-bounty-la-mejor-herramienta-es-una-mente-inc%C3%B3moda-45c3309ca923?source=rss------bug_bounty-5)
Zero-Touch Recon: Finding Critical Web App Vulnerabilities Without Ever Logging In
“You don’t need credentials to hack — just curiosity, creativity, and the right passive recon stack.Continue reading on MeetCyber »
Read more...
“You don’t need credentials to hack — just curiosity, creativity, and the right passive recon stack.Continue reading on MeetCyber »
Read more...
Medium
🧠 Zero-Touch Recon: Finding Web App Vulnerabilities Without Ever Logging In
“You don’t need credentials to hack — just curiosity, creativity, and the right passive recon stack.
Zero to Owned: The Ultimate Bug Bounty Recon Blueprint (2025 Edition)
“Most people start with payloads. Legends start with passive recon.”Continue reading on MeetCyber »
Read more...
“Most people start with payloads. Legends start with passive recon.”Continue reading on MeetCyber »
Read more...
Medium
🧠 Zero to Owned: The Ultimate Bug Bounty Recon Blueprint (2025 Edition)
“Most people start with payloads. Legends start with passive recon.”
The API Trapdoor — Hacking Mobile Apps Without Ever Installing Them
“Who needs an emulator when you have an endpoint?”Continue reading on System Weakness »
Read more...
“Who needs an emulator when you have an endpoint?”Continue reading on System Weakness »
Read more...
Medium
The API Trapdoor — Hacking Mobile Apps Without Ever Installing Them
“Who needs an emulator when you have an endpoint?”
Breaking Filter: XSS Bypass using ononmouseovermouseover, ONMOUSEOVER and without () \`\` [] …
Hi Everyone,Continue reading on Medium »
Read more...
Hi Everyone,Continue reading on Medium »
Read more...
Medium
Breaking Filter: XSS Bypass using ononmouseovermouseover, ONMOUSEOVER and without () `` [] …
Hi Everyone,
Insecure by Design: How a Mobile API Let Me Reset Anyone’s Password With Just a Phone Number
Hey there!😁Continue reading on Medium »
Read more...
Hey there!😁Continue reading on Medium »
Read more...
Medium
📱 Insecure by Design: How a Mobile API Let Me Reset Anyone’s Password With Just a Phone Number 🔓
Hey there!😁
GraphQL for the next API Penetration Testing
https://0xjar.medium.com/graphql-for-the-next-api-penetration-test-0922b3adef58?source=rss------bug_bounty-5
https://0xjar.medium.com/graphql-for-the-next-api-penetration-test-0922b3adef58?source=rss------bug_bounty-5
In this article, I will share a guide that may be useful for you wherever you are. May you be blessed with protection and good health.Continue reading on Medium » (https://0xjar.medium.com/graphql-for-the-next-api-penetration-test-0922b3adef58?source=rss------bug_bounty-5)
How to use “Caido Workflows” to scan for anything
How to build Caido passive workflows to scan HTTP requests & responses…Continue reading on Medium »
Read more...
How to build Caido passive workflows to scan HTTP requests & responses…Continue reading on Medium »
Read more...
Medium
How to use “Caido Workflows” to scan for anything
How to build Caido passive workflows to scan HTTP requests & responses…
From File Upload to Shell: A Deep Dive into RCE Exploits
🧠IntroductionContinue reading on Medium »
Read more...
🧠IntroductionContinue reading on Medium »
Read more...
Medium
From File Upload to Shell: A Deep Dive into RCE Exploits
🧠Introduction
️♂️ How I Landed Two P1s and My First Bug Bounty
Back in May 2025, I officially stepped into the world of bug bounty. I had been studying cybersecurity for a while but hadn’t actively…Continue reading on Medium »
Read more...
Back in May 2025, I officially stepped into the world of bug bounty. I had been studying cybersecurity for a while but hadn’t actively…Continue reading on Medium »
Read more...
Medium
🕵️♂️ How I Landed Two P1s and My First Bug Bounty
Back in May 2025, I officially stepped into the world of bug bounty. I had been studying cybersecurity for a while but hadn’t actively…
Public APIs vs. Private APIs: A Bug Hunter’s Perspective
Application Programming Interfaces (APIs) are the backbone of modern software architecture, enabling different systems to communicate and…Continue reading on Medium »
Read more...
Application Programming Interfaces (APIs) are the backbone of modern software architecture, enabling different systems to communicate and…Continue reading on Medium »
Read more...
Medium
Public APIs vs. Private APIs: A Bug Hunter’s Perspective
Application Programming Interfaces (APIs) are the backbone of modern software architecture, enabling different systems to communicate and…
SQL injection vulnerability in WHERE clause allowing retrieval of hidden data [ES] [PortSwigger]
La SQL Injection es una vulnerabilidad web que ocurre cuando una aplicación permite que el usuario final manipule entradas que forman…Continue reading on Medium »
Read more...
La SQL Injection es una vulnerabilidad web que ocurre cuando una aplicación permite que el usuario final manipule entradas que forman…Continue reading on Medium »
Read more...
Medium
SQL injection vulnerability in WHERE clause allowing retrieval of hidden data [ES] [PortSwigger]
La SQL Injection es una vulnerabilidad web que ocurre cuando una aplicación permite que el usuario final manipule entradas que forman parte…
N0aziXss Origin Recon v3.1: The Ultimate CDN Bypass & Infrastructure Mapping Tool
Subtitle: How We Built a Military-Grade Reconnaissance Engine with Enhanced SSL/TLS and Error HandlingContinue reading on Medium »
Read more...
Subtitle: How We Built a Military-Grade Reconnaissance Engine with Enhanced SSL/TLS and Error HandlingContinue reading on Medium »
Read more...
Medium
N0aziXss Origin Recon v3.1: The Ultimate CDN Bypass & Infrastructure Mapping Tool
Subtitle: How We Built a Military-Grade Reconnaissance Engine with Enhanced SSL/TLS and Error Handling