Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
🧠 + 💣 = ⚔️ Total Exploitation Guide for Ethical HackersContinue reading on Medium » (https://medium.com/@zoningxtr/full-lfi-to-rce-via-apache-access-logs-e521ec06ec1a?source=rss------bug_bounty-5)
I Found 50+ XSS Flaws Using Just My Browser

How a Simple Chrome Trick Turned Into a $5,000 Bug BountyContinue reading on Medium »
Read more...
DNS proxy for C2 communications
https://www.reddit.com/r/redteamsec/comments/1mhjgqf/dns_proxy_for_c2_communications/

<!-- SC_OFF -->Hello there, I write a medium tutorial about How to setup DNS proxy for C2 commuications and a example with Myhic <!-- SC_ON --> submitted by /u/umbraXsecure (https://www.reddit.com/user/umbraXsecure)
[link] (https://medium.com/@umbraxsecure/dns-proxy-for-c2-servers-c1a3f2cf4944) [comments] (https://www.reddit.com/r/redteamsec/comments/1mhjgqf/dns_proxy_for_c2_communications/)
Bypassing Authentication and Triggering XSS via Simple URL Manipulation
https://medium.com/@aloneinjector1/bypassing-authentication-and-triggering-xss-via-simple-url-manipulation-a3d56c66b136?source=rss------bug_bounty-5

In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…Continue reading on Medium » (https://medium.com/@aloneinjector1/bypassing-authentication-and-triggering-xss-via-simple-url-manipulation-a3d56c66b136?source=rss------bug_bounty-5)
Bypassing Authentication and Triggering XSS via Simple URL Manipulation

In this write-up, I’m sharing a real-world case where I discovered multiple web vulnerabilities — including authentication bypass…Continue reading on Medium »
Read more...
The 2025 GitHub Recon Checklist for Bug Bounty Hunters

GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…Continue reading on Medium »
Read more...
The 2025 GitHub Recon Checklist for Bug Bounty Hunters
https://medium.com/@tillson.galloway/the-2025-github-recon-checklist-for-bug-bounty-hunters-e626ee1a1012?source=rss------bug_bounty-5

GitHub is a goldmine for bug bounty recon. Many organizations (and their developers) unknowingly expose sensitive information through code…Continue reading on Medium » (https://medium.com/@tillson.galloway/the-2025-github-recon-checklist-for-bug-bounty-hunters-e626ee1a1012?source=rss------bug_bounty-5)
Need help with a virtual machine
https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/

<!-- SC_OFF -->Hello, For the past few months, I have been learning about offensive cybersecurity. So I created a Linux virtual machine on VirtualBox (Kali). The problem is that it has very poor performance. However, it has 14GB of RAM, 220MB of video memory, 8 processor core, plenty of disk space, and I even enabled 3D acceleration. I'm using a fairly recent ThinkPad with 32 GB of RAM. But my virtual machine is still slow and has poor visual performance. So I'd like to know if there's a hidden option or something that needs to be changed in its configuration. (I have version 7.1.8 of VirtualBox.) <!-- SC_ON --> submitted by /u/Annual-Stress2264 (https://www.reddit.com/user/Annual-Stress2264)
[link] (https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mh9s9o/need_help_with_a_virtual_machine/)
Is a degree required for pentest role?
https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/

<!-- SC_OFF -->Hi,Im still beginner in ethical hacking world(2 months in) and had seen a lot of experience one before me doing amazing things in penetration testing and it makes me wonder since its a technical role,is a degree needed for this role to even be seen let alone landing a business position?Im looking foward for any opinion regarding this “controversial” topic.Thanks! <!-- SC_ON --> submitted by /u/Emotional-Aside8923 (https://www.reddit.com/user/Emotional-Aside8923)
[link] (https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mhbt0d/is_a_degree_required_for_pentest_role/)
<!-- SC_OFF -->Will this wifi module support monitor mode and packet ejection? It has ralink RT5370 chipset ? I have found this in a electronic shop and I bought it. Will it worth it or just a failed purchase? <!-- SC_ON --> submitted by /u/thepardaox (https://www.reddit.com/user/thepardaox)
[link] (https://www.reddit.com/gallery/1mhee77) [comments] (https://www.reddit.com/r/Pentesting/comments/1mhee77/will_a_wifi_adapter_support_monitor_mode_and/)
IDS Nedir ve Çeşitlerinde Bulunan Güvenlik Açıkları ?

IDS (Intrusion Detection System) yani Türkçe adı ile izinsiz giriş tespit sistemi/sistemleri , olası güvenlik ihlalleri ve yetkisiz erişim…Continue reading on Medium »
Read more...