Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.3K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Prompt Engineering Toolkit (2025 Edition)

“JavaScript files don’t just power the frontend — they spill secrets, expose APIs, and open attack paths. You just need to ask the right…Continue reading on MeetCyber »
Read more...
7 Easy Bugs That Still Work in 2025

How to Find Low-Hanging Vulnerabilities: A Step-by-Step Guide for Bug Bounty HuntersContinue reading on System Weakness »
Read more...
Logs Don’t Lie: How a GraphQL Debug Endpoint Spilled the Entire Database ️

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
A Deep Dive into Improper Authentication

Exploring How to Detect and Exploit Reusable OTP Issues, with a Case Study from HackerOne ReportContinue reading on InfoSec Write-ups »
Read more...
A01: Broken Access Control and A05: Security Misconfiguration Leads to Unauthenticated Access to…

While using a service that I recently paid for, there was a slight hiccup in the service which was preventing me from using it. This…Continue reading on InfoSec Write-ups »
Read more...
A Deep Dive into Improper Authentication

Exploring How to Detect and Exploit Reusable OTP Issues, with a Case Study from HackerOne ReportContinue reading on InfoSec Write-ups »
Read more...
Logs Don’t Lie: How a GraphQL Debug Endpoint Spilled the Entire Database ️

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
“Day 8: Mobile Hacking — How I Cracked a Banking App’s PIN in 10 Seconds ($5000 Bug)”

Two weeks ago, I reverse-engineered a “secure” banking app that claimed to use “military-grade encryption.” Turns out, they stored user…Continue reading on InfoSec Write-ups »
Read more...
Dorks For Sensitive Information Disclosure Part-3

Look google’s crawlers just got some juicy info……….Continue reading on Medium »
Read more...
Did you try this hackcubes challenge?
https://www.reddit.com/r/redteamsec/comments/1mo099d/did_you_try_this_hackcubes_challenge/

<!-- SC_OFF -->I stumbled upon a new platform called HackCubes (hackcubes.com) that has an invite-style challenge, kind of like the one HackTheBox used to have back in the day. It’s still pretty new, so I’m curious to see how it turns out — I’m planning to give it a try just for fun, they are giving away free APPsec exam vouchers. It reminded me of another CTF platform that’s been around for a while now, ParrotCTF (parrotctf.com), which some of you might have already checked out. Has anyone else here tried either of these kinds of invite challenges lately? <!-- SC_ON --> submitted by /u/EfficientRepeat6679 (https://www.reddit.com/user/EfficientRepeat6679)
[link] (http://hackcubes.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1mo099d/did_you_try_this_hackcubes_challenge/)
Rate Limiting in Web Applications: Bug That Pays Your Rent

Taming the flood before it drowns your system.Continue reading on Medium »
Read more...
Learn how to automate endpoint discovery using Burp and ZAP — two powerful tools for bug bounty hunting and pentesting.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/day5-recon-hacking-hidden-endpoints-how-to-use-burp-suite-owasp-zap-for-web-spidering-and-2a69aa4ffd3d?source=rss------bug_bounty-5)