Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
I Turned One Recon Trick Into $3,350

Here’s How I Found a Critical Bug Others MissedContinue reading on Medium »
Read more...
[Video] Exploiting ADCS ESC1–ESC3 with Certify 2.0 – The Weekly Purple Team
https://www.reddit.com/r/redteamsec/comments/1mp4jn4/video_exploiting_adcs_esc1esc3_with_certify_20/

<!-- SC_OFF -->Just released the latest episode of The Weekly Purple Team, and this week we’re looking at how misconfigured Active Directory Certificate Services (ADCS) can be abused for privilege escalation. Using Certify 2.0, we walk through ESC1, ESC2, and ESC3 escalation paths: How each ESC technique works Live exploitation demos Blue team detection & mitigation tips If you work in offensive security or defensive operations, you’ve probably seen ADCS mentioned more in recent years — but many environments are still vulnerable because these escalation paths are under-tested and under-detected.
#cybersecurity #ADCS #privilegeescalation #windowssecurity #redteam #blueteam #purpleteam <!-- SC_ON --> submitted by /u/Infosecsamurai (https://www.reddit.com/user/Infosecsamurai)
[link] (https://youtu.be/Fg8akdlap58) [comments] (https://www.reddit.com/r/redteamsec/comments/1mp4jn4/video_exploiting_adcs_esc1esc3_with_certify_20/)
How I Found a Horizontal Privilege Escalation Vulnerability — From Recon to Exploit

Hi Researchers this is my 4rd Blog.Continue reading on InfoSec Write-ups »
Read more...
“Day 10: Defending the Digital Gateway — A White Hat’s Exploration of Chrome’s Security…

How Ethical Research Uncovers Critical Browser Vulnerabilities Before Attackers DoContinue reading on InfoSec Write-ups »
Read more...
How I get $ 1,000 and You Can Get it using Rate Limit on OTP

🚨 API Verification Code Brute Force VulnerabilityContinue reading on Medium »
Read more...
OAuth Açığı Nedir?

OAuth, günlük hayatta fark etmeden sıkça kullandığımız, ancak yanlış yapılandırıldığında ciddi güvenlik açıklarına yol açabilen bir…Continue reading on Medium »
Read more...
Bug Bounty: Authentication Testing — Brute Force to Bypass

Authentication is the digital gatekeeper of every secure system. If it’s broken, everything behind it is vulnerable. This blog dives deep…Continue reading on Medium »
Read more...
How I Use Perplexity for Bug Bounty Recon (and Squeeze Every Last Drop Out of It)

When most people talk about recon, they picture running a couple of tools, dumping thousands of subdomains, and then… getting lost in the…Continue reading on Medium »
Read more...
The Best Alternatives to Intelx.io

Credential stuffing is truly a satisfying bug to hunt. The feeling of inserting someone else’s credentials and logging in is like being…Continue reading on Medium »
Read more...
$125 For Unauthorized Campaign Modification via Insecure ID Parameter (IDOR)

📝 SummaryContinue reading on Medium »
Read more...
How I Found a Critical XSS On a Public Bug Bounty Program

INTRODUCTIONContinue reading on Medium »
Read more...
Unveiling Time-Based Blind SQL Injection in U.S. DoD Systems

Decoding the Art of Detecting and Exploiting Time-Based SQLi with Insights from HackerOne ReportContinue reading on OSINT Team »
Read more...
OAuth Login Bypasses & Account Linking Chaos — A Bug Bounty Adventure

During a routine bug bounty hunt, I stumbled upon an OAuth login flow behaving like it had a mind of its own. Two related quirks made me…Continue reading on Medium »
Read more...