Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
When I first got into bug bounty hunting, I used to think finding big bugs required fancy payloads and hardcore exploitation skills. But…Continue reading on OSINT Team » (https://osintteam.blog/3-000-for-finding-a-hidden-subdomain-my-reconnaissance-success-story-990396554a2e?source=rss------bug_bounty-5)
A simple logic flaw in Pixiv’s password reset flow enabled unrestricted verification code brute-forcing — earning a $1000 bountyContinue reading on T3CH » (https://medium.com/h7w/1000-bounty-reset-any-password-474606e18441?source=rss------bug_bounty-5)
I Got ROOT Access to a Hosting Provider Without a Single Exploit

🧠 Boring Recon That Led Somewhere InterestingContinue reading on Medium »
Read more...
SQL injection vulnerability allowing login bypass [ES] [PortSwigger]

Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium »
Read more...
Continuando con la vulnerabilidad SQLi, en esta ocasión tocaremos principalmente el Bypass de un sistema de autenticación por medio de…Continue reading on Medium » (https://h0lm3s.medium.com/sql-injection-vulnerability-allowing-login-bypass-es-portswigger-53c7adf477df?source=rss------bug_bounty-5)
I’m thrilled to share that I’ve secured the 3rd position in one of HackerOne’s programs! What makes this achievement even more special is…Continue reading on Medium » (https://medium.com/@umeryousuf26/hackerone-19b7aeaf7c6a?source=rss------bug_bounty-5)
Best Certifications in 2025 non beginner.
https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/

<!-- SC_OFF -->Throwing this out to the hive mind: after 4 years pentesting and playing red team full time (never bothered with certs, just dove straight into real exercises), I’m finally thinking of getting certified but not with a starter one since it overlaps my experience. What’s your “no nonsense” favorite cert for someone already living and breathing pentest/red team? OSCP, OSEP, CRTO, GPEN, CPTS, something else? I just want to improve my résumé <!-- SC_ON --> submitted by /u/wh1t3k4t (https://www.reddit.com/user/wh1t3k4t)
[link] (https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ma32vx/best_certifications_in_2025_non_beginner/)
Fed up with pentesting methodology chaos? Built something to fix it.
https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/

<!-- SC_OFF -->Hello r/Pentesting (https://www.reddit.com/r/Pentesting) , Is anyone else tired of tracking methodologies across scattered notes, Excel sheets, and random text files? Ever find yourself thinking: Where did I put that command from last month? I remember that scenario... but what did I do last time? How do I clearly show this complex attack chain to my customer? Why is my methodology/documentation/life such a mess? Hmm what can I do at this point in my pentest mission? Did I have enough coverage? How can I share my findings or a whole "snapshot" of my current progress with my team? My friend and I developed a FOSS platform called Penflow to make our work easier as security engineers. Here's what we ended up with: Visual methodology organization Attack kill chain mapping with proper relationship tracking Built on Neo4j for the graph database magic AI powered chat and node suggestion UI that doesn't look like garbage from 2005 (we actually spent time on this) Looking for your feedback 🙏 GitHub: https://github.com/rb-x/penflow <!-- SC_ON --> submitted by /u/DoubleMirror1008 (https://www.reddit.com/user/DoubleMirror1008)
[link] (https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mab1ru/fed_up_with_pentesting_methodology_chaos_built/)
“Bug Bounty ”Telerik Report Server Authentication Bypass — CVE-2024–4358 “POC”

Telerik Report Server Tool that helps to businesses to store, manage and share the reports in one Central placeContinue reading on Medium »
Read more...