Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Become a hacker — 101, A list of resources

A massive list of resources to help you get into the wonderful world of ethical hacking …Continue reading on Medium »
Read more...
HTTP Request Smuggling: From Basics to Bounty

IntroductionContinue reading on Medium »
Read more...
HTTP/1.1 Its No Longer Safe

Millions of websites are still at risk because HTTP/1.1 can get confused about where one request ends and the next begins. Hackers are ….Continue reading on Medium »
Read more...
Business Logic Flaw in Invitation Feature Allows Full Account Takeover

📌 PendahuluanContinue reading on Medium »
Read more...
How I Chained Rate Limiting to Earn a Spot in Apple’s Hall of Fame

IntroductionContinue reading on Medium »
Read more...
How I Found a Logout Flaw That Kept Sessions Alive — A Real-World Bug Bounty Lesson

A powerful reminder that in bug bounty hunting, scope is everything.Continue reading on Medium »
Read more...
Account Takeover via Email Injection Tricks
https://medium.com/@7error/account-takeover-via-email-injection-tricks-db7701f3cddd?source=rss------bug_bounty-5

Sometimes, you don’t need an RCE or SQLi — just a weak email parser.
Here’s a sneaky way to hijack accounts when signup/login flows have…Continue reading on Medium » (https://medium.com/@7error/account-takeover-via-email-injection-tricks-db7701f3cddd?source=rss------bug_bounty-5)
A massive list of resources to help you get into the wonderful world of ethical hacking …Continue reading on Medium » (https://thexssrat.medium.com/become-a-hacker-101-a-list-of-resources-2e4c3f9b3d59?source=rss------bug_bounty-5)
I Found a $3,330 Bug Using Extract Grep Curl

A step-by-step guide to uncovering hidden vulnerabilities (ethically!) with common command-line tools.Continue reading on Medium »
Read more...
Prototype Pollution

In client-side JavaScript, this commonly leads to DOM XSS, while server-side prototype pollution can even result in remote code execution.Continue reading on Medium »
Read more...
SQL Injection Web Security Academy Union attack & Blind SQL

Union attackContinue reading on Medium »
Read more...
A step-by-step guide to uncovering hidden vulnerabilities (ethically!) with common command-line tools.Continue reading on Medium » (https://medium.com/@ibtissamhammadi1/i-found-a-3-330-bug-using-extract-grep-curl-9d52a463888b?source=rss------bug_bounty-5)