Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
From Curiosity to Critical: Uncovering Chained Vulnerabilities in a Private Web App Pentest
https://medium.com/@samruthsriram/from-curiosity-to-critical-uncovering-chained-vulnerabilities-in-a-private-web-app-pentest-febdc60a19ce?source=rss------bug_bounty-5

Sometimes, the difference between a standard pentest and a high-impact security discovery is simply… not stopping too early.Continue reading on Medium » (https://medium.com/@samruthsriram/from-curiosity-to-critical-uncovering-chained-vulnerabilities-in-a-private-web-app-pentest-febdc60a19ce?source=rss------bug_bounty-5)
“Information is power. If you control the flow of data, you control everything.”Continue reading on Medium » (https://medium.com/@rajkumarkumawat.workup/bug-bounty-information-disclosure-leaks-logs-loose-ends-54cf53dbbf09?source=rss------bug_bounty-5)
My 100 Hour Rule for Bug Bounty !

In this post, I share my 100-Hour Rule — how I structure every minute of hunting into focused phases, avoid the sunk cost trap, and boost…Continue reading on Medium »
Read more...
<!-- SC_OFF -->It runs on iSH Shell, available on the app store. I modified some existing tools to work within it, made a few of my own and put it all together as a toolkit. Kinda like a Lazy Script for iPhone. I haven’t been able to test everything thoroughly but always looking for community feedback & suggestions! <!-- SC_ON --> submitted by /u/0x7_ (https://www.reddit.com/user/0x7_)
[link] (https://i.redd.it/xjpw70rcnlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadfy/i_did_the_unthinkable_and_made_a_pentesting/)
<!-- SC_OFF -->It runs on iSH Shell, available on the app store. I modified some existing tools to work within it, made a few of my own and put it all together as a toolkit. Kinda like a Lazy Script for iPhone. I haven’t been able to test everything thoroughly but always looking for community feedback & suggestions! <!-- SC_ON --> submitted by /u/0x7_ (https://www.reddit.com/user/0x7_)
[link] (https://i.redd.it/033p44ienlif1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1moadl3/i_did_the_unthinkable_and_made_a_pentesting/)
Is Penetration Testing Financially Stable in the Long Run?
https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/

<!-- SC_OFF -->I’m at the very beginning of my journey into penetration testing, and I keep hearing mixed opinions about its financial stability as a career. Some people say the competition is fierce, stable positions are hard to get, and the income isn’t always worth the amount of effort required. I’ve also read that bug bounty programs aren’t as lucrative as many influencers make them seem, and relying on them for a consistent income can be unrealistic. From your perspective as an experienced penetration tester (or someone working in offensive security), do you think it’s worth continuing in this field if one of my main motivations is passion combined with the expectation of a financially rewarding career? I’d appreciate honest insights about what the real job market looks like and whether pen testing is still a viable long-term career option. <!-- SC_ON --> submitted by /u/n42- (https://www.reddit.com/user/n42-)
[link] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/) [comments] (https://www.reddit.com/r/Pentesting/comments/1modwb2/is_penetration_testing_financially_stable_in_the/)
PenTest GPT
https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/

<!-- SC_OFF -->I am wondering if PenTest GPT is actually helpful, or if it is just another version of ChatGPT. Anyone has experience using it? <!-- SC_ON --> submitted by /u/turaoo (https://www.reddit.com/user/turaoo)
[link] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/) [comments] (https://www.reddit.com/r/Pentesting/comments/1moja8d/pentest_gpt/)
Google Cloud Partner API Credentials Found in Public Repo

Hey everyone,Continue reading on Medium »
Read more...
CARTE tips?
https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/

<!-- SC_OFF -->Hi everyone. I will be attending the CARTE exam soon. any tips or stuff I should know before doing the exam? I can't seem to find a lot of reviews on the internet about this certification. I did CARTP (not the exam) so I have those enumeration notes ready as well. I heard it's a messy environment on purpose so wondering how that will play out. How did you find the exam? How long did you take it to complete? Let me know :) Thanks! <!-- SC_ON --> submitted by /u/SilverAd2716 (https://www.reddit.com/user/SilverAd2716)
[link] (https://www.alteredsecurity.com/carte-bootcamp) [comments] (https://www.reddit.com/r/redteamsec/comments/1mogis2/carte_tips/)