Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Bounty $$$: Grafana LFI

A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team »
Read more...
$3,000 for Finding a Hidden Subdomain: My Reconnaissance Success Story

When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team »
Read more...
$1000 Bounty: Reset any password

A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH »
Read more...
I found a bug — but it was marked as duplicate. Here’s how I did it.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/my-simple-method-to-test-for-idor-vulnerabilities-5963f6ed8785?source=rss------bug_bounty-5)
🚀 Introduction: Why You Need Your Own Hacking LabContinue reading on OSINT Team » (https://osintteam.blog/how-to-create-hacking-lab-c994cdb0483a?source=rss------bug_bounty-5)
A simple plugin path traversal exposed sensitive server files on a public dashboardContinue reading on OSINT Team » (https://osintteam.blog/bounty-grafana-lfi-7cf9f167e1b2?source=rss------bug_bounty-5)
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team » (https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5)
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH » (https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5)
I Got ROOT Access to a Hosting Provider Without a Single Exploit

🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium »
Read more...
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]

Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium »
Read more...