Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
A casual app suggestion led to a discovery that exposed over 100,000 users’ private data here’s how it unfolded.Continue reading on Medium » (https://kkonann.medium.com/i-found-a-major-privacy-leak-in-a-popular-social-app-just-because-a-friend-said-check-this-out-cd7edd798e32?source=rss------bug_bounty-5)
I wasn’t even looking for it — but a misconfigured JWT realm led me to a $4,750 payday.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/how-i-found-a-4-750-security-flaw-by-accident-6acb32eaede5?source=rss------bug_bounty-5)
Microsoft has increased its Zero Day Quest bug bounty prize pool to $5 million for 2025, with a focus on AI and cloud vulnerabilities…Continue reading on Medium » (https://medium.com/@thedhruvsingh/microsoft-raises-zero-day-quest-prize-pool-to-5-million-to-tackle-ai-and-cloud-vulnerabilities-9425c7e6553d?source=rss------bug_bounty-5)
Jangan dikit-dikit “Bypass”. Gak semua yang “Aneh” itu vulnerability

Udah yakin ini “bypass” tapi ternyata ditolak? mungkin ini salah kamu!Continue reading on Medium »
Read more...
Starting Bug Bounty — Documenting My Journey

Hey guys. I’m starting bug bounty.Continue reading on Medium »
Read more...
Portswigger XML External Entity (XXE) Injection Labs — Apprentice

Exploiting XXE Using External Entities to Retrieve FilesContinue reading on Medium »
Read more...
Portswigger XML External Entity (XXE) Injection Labs — Practitioner

Blind XXE with Out-of-Band InteractionContinue reading on Medium »
Read more...
Portswigger XML External Entity (XXE) Injection Labs — Expert

Exploiting XXE to Retrieve Data by Repurposing a Local DTDContinue reading on Medium »
Read more...
Coinbase Breach: Threats Exposed

A Real-World Hook: The Coinbase BreachContinue reading on Medium »
Read more...
How an API Token Flaw Let Me Bypass Premium Restrictions

Hi Guys, Welcome back to yet another article, Today, I want to walk you through one of the bugs I found while hunting on HackerOne. I was…Continue reading on Medium »
Read more...
Bug Bounty Hunting — Are Self Hosted Programs Any Better?

You’ll see why I think External Programs are not worth itContinue reading on Activated Thinker »
Read more...
CTF Day(44)

picoCTF Web Exploitation: More CookiesContinue reading on Medium »
Read more...
Portswigger Information Disclosure Labs — Apprentice

Information Disclosure in Error MessagesContinue reading on Medium »
Read more...
Portswigger Information disclosure Labs — Practitioner

Information Disclosure in Version Control HistoryContinue reading on Medium »
Read more...
CTF Day(45)

picoCTF Web Exploitation: It is my BirthdayContinue reading on Medium »
Read more...