Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
0-Click Account Takeover via OAuth Misconfiguration

OAuth is an authorization framework used to identify and authenticate users for an application.Continue reading on Medium »
Read more...
Fully remote + outside the US?
https://www.reddit.com/r/Pentesting/comments/1mkozus/fully_remote_outside_the_us/

<!-- SC_OFF -->It seems the general consensus on other cyber subreddits* is that (1) fully remote + (2) outside the US pretty rare for a cybersecurity job (mostly for legal + data compliance issues). However, I was wondering if this could be an exception for pentesting jobs? Because I would assume most malicious hacking attempts are from abroad, it seems it would make sense for pentesters to be abroad. edit: to work for a US-based company, and also I am a US citizen. <!-- SC_ON --> submitted by /u/KimchiFitness (https://www.reddit.com/user/KimchiFitness)
[link] (https://www.reddit.com/r/Pentesting/comments/1mkozus/fully_remote_outside_the_us/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mkozus/fully_remote_outside_the_us/)
The state of pentesting in 2025
https://www.reddit.com/r/Pentesting/comments/1mktm1e/the_state_of_pentesting_in_2025/

<!-- SC_OFF -->Hello everyone, I am writing this post because I need more advice on what the absolute hell im doing wrong. My qualifications include - B.S in Cybersecurity - OSCP - CRTO - Two pending CVE's (One I am already listed on a company site for) - 2 years of professional experience as a SOC Analyst - 4 years experience as a SOC Analyst intern - Was a part of a statewide cybersecurity initiative as a red team operator over a span of 4 days (prep was about 2 months) and was the sole member of the red teams to get an award. - 2 POC exploits on github for random CVE's and 1 for a crummy shellcode loader i made for CRTO I seriously can't land a pentesting job/find one now I haven't applied for and its killing me. I feel so overqualified and underpaid in my current role as a SOC analyst that its depressing me (60k annually). I've been working through portswigger courses in the meantime with Burp Pro trying to get the BSCP in a month or two but I feel im due for a new job at this point. My current company has done nothing with me to utilize my skills and my other peers at work who started when I did are upset about them not getting moved to different roles as management keeps hiring externally and mentors I've expressed these issues to have stated it is 100% bad management. So instead of sitting around and feeling sorry for myself what else can I do?!?! I know the job market is "bad' right now but I only really see those kind of posts from people who are trying to break into IT/Cybersec. I feel with pentesting there just arent any jobs out there for someone at my level example is I live in the DMV area i'll find a job that fits my qualifications perfect then i see "TS/SCI with full scope poly required" or one without clearance as in "Pentesting 10 years must be proficient in every technology and programming language for 90k annually" Any advice is appreciated. <!-- SC_ON --> submitted by /u/Netmond (https://www.reddit.com/user/Netmond)
[link] (https://www.reddit.com/r/Pentesting/comments/1mktm1e/the_state_of_pentesting_in_2025/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mktm1e/the_state_of_pentesting_in_2025/)
<!-- SC_OFF -->Just published a new post on Medium for anyone grinding through OSCP prep. “OSCP Exam Success: 5 Must-Know Commands and Tools Every Pentester Should Master” — a quick guide to the commands that saved me time and stress during the exam, and that I still use in real-world pentests. <!-- SC_ON --> submitted by /u/Anezaneo (https://www.reddit.com/user/Anezaneo)
[link] (https://infosecwriteups.com/oscp-exam-success-5-must-know-commands-and-tools-every-pentester-should-master-c65523e38cc1) [comments] (https://www.reddit.com/r/Pentesting/comments/1mkvnk8/5_commands_that_really_helped_me_during_my_oscp/)
Web Applications vs. Cloud
https://www.reddit.com/r/Pentesting/comments/1ml5ck5/web_applications_vs_cloud/

<!-- SC_OFF -->From what I've seen the majority of the pentesting work seems to be web apps. Do you think with the rapid growth and adoption of cloud, cloud penetration testing will overtake it in terms of volume of work and demand? Or will web remain the most sought after? <!-- SC_ON --> submitted by /u/Sad-Mountain-2031 (https://www.reddit.com/user/Sad-Mountain-2031)
[link] (https://www.reddit.com/r/Pentesting/comments/1ml5ck5/web_applications_vs_cloud/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ml5ck5/web_applications_vs_cloud/)
Server-Side Request Forgery (SSRF — OWASP A10): A Complete Guide to Hacking and Bug Bounties

Learn how SSRF allows an attacker to access the internal network, read cloud metadata, and escalate privileges.Continue reading on Medium »
Read more...
DNSSEC Explained

A practical guide to understanding DNSSEC, the bodyguard of DNS, what it is, how it works, and why it’s a big deal in securing DNS records.Continue reading on Zero2Root »
Read more...
Learn how SSRF allows an attacker to access the internal network, read cloud metadata, and escalate privileges.Continue reading on Medium » (https://medium.com/@jpablo13/server-side-request-forgery-ssrf-owasp-a10-a-complete-guide-to-hacking-and-bug-bounties-0b8f0825f83c?source=rss------bug_bounty-5)