Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Zero-Touch Recon: Finding Critical Web App Vulnerabilities Without Ever Logging In

“You don’t need credentials to hack — just curiosity, creativity, and the right passive recon stack.Continue reading on MeetCyber »
Read more...
Zero to Owned: The Ultimate Bug Bounty Recon Blueprint (2025 Edition)

“Most people start with payloads. Legends start with passive recon.”Continue reading on MeetCyber »
Read more...
The API Trapdoor — Hacking Mobile Apps Without Ever Installing Them

“Who needs an emulator when you have an endpoint?”Continue reading on System Weakness »
Read more...
Breaking Filter: XSS Bypass using ononmouseovermouseover, ONMOUSEOVER and without () \`\` [] …

Hi Everyone,Continue reading on Medium »
Read more...
Insecure by Design: How a Mobile API Let Me Reset Anyone’s Password With Just a Phone Number

Hey there!😁Continue reading on Medium »
Read more...
In this article, I will share a guide that may be useful for you wherever you are. May you be blessed with protection and good health.Continue reading on Medium » (https://0xjar.medium.com/graphql-for-the-next-api-penetration-test-0922b3adef58?source=rss------bug_bounty-5)
How to use “Caido Workflows” to scan for anything

How to build Caido passive workflows to scan HTTP requests & responses…Continue reading on Medium »
Read more...
From File Upload to Shell: A Deep Dive into RCE Exploits

🧠IntroductionContinue reading on Medium »
Read more...
️‍♂️ How I Landed Two P1s and My First Bug Bounty

Back in May 2025, I officially stepped into the world of bug bounty. I had been studying cybersecurity for a while but hadn’t actively…Continue reading on Medium »
Read more...
Public APIs vs. Private APIs: A Bug Hunter’s Perspective

Application Programming Interfaces (APIs) are the backbone of modern software architecture, enabling different systems to communicate and…Continue reading on Medium »
Read more...
SQL injection vulnerability in WHERE clause allowing retrieval of hidden data [ES] [PortSwigger]

La SQL Injection es una vulnerabilidad web que ocurre cuando una aplicación permite que el usuario final manipule entradas que forman…Continue reading on Medium »
Read more...
ShaktiCTF25

السلام عليكم ورحمه الله وربركاته / اهلا بيكم في:Continue reading on Medium »
Read more...
N0aziXss Origin Recon v3.1: The Ultimate CDN Bypass & Infrastructure Mapping Tool

Subtitle: How We Built a Military-Grade Reconnaissance Engine with Enhanced SSL/TLS and Error HandlingContinue reading on Medium »
Read more...
How to build Caido passive workflows to scan HTTP requests & responses…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-to-use-caido-workflows-to-scan-for-anything-07eed72ba06a?source=rss------bug_bounty-5)