Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
OAuth Açığı Nedir?

OAuth, günlük hayatta fark etmeden sıkça kullandığımız, ancak yanlış yapılandırıldığında ciddi güvenlik açıklarına yol açabilen bir…Continue reading on Medium »
Read more...
Bug Bounty: Authentication Testing — Brute Force to Bypass

Authentication is the digital gatekeeper of every secure system. If it’s broken, everything behind it is vulnerable. This blog dives deep…Continue reading on Medium »
Read more...
How I Use Perplexity for Bug Bounty Recon (and Squeeze Every Last Drop Out of It)

When most people talk about recon, they picture running a couple of tools, dumping thousands of subdomains, and then… getting lost in the…Continue reading on Medium »
Read more...
The Best Alternatives to Intelx.io

Credential stuffing is truly a satisfying bug to hunt. The feeling of inserting someone else’s credentials and logging in is like being…Continue reading on Medium »
Read more...
$125 For Unauthorized Campaign Modification via Insecure ID Parameter (IDOR)

📝 SummaryContinue reading on Medium »
Read more...
How I Found a Critical XSS On a Public Bug Bounty Program

INTRODUCTIONContinue reading on Medium »
Read more...
Unveiling Time-Based Blind SQL Injection in U.S. DoD Systems

Decoding the Art of Detecting and Exploiting Time-Based SQLi with Insights from HackerOne ReportContinue reading on OSINT Team »
Read more...
OAuth Login Bypasses & Account Linking Chaos — A Bug Bounty Adventure

During a routine bug bounty hunt, I stumbled upon an OAuth login flow behaving like it had a mind of its own. Two related quirks made me…Continue reading on Medium »
Read more...
Authentication is the digital gatekeeper of every secure system. If it’s broken, everything behind it is vulnerable. This blog dives deep…Continue reading on Medium » (https://medium.com/@rajkumarkumawat.workup/bug-bounty-authentication-testing-brute-force-to-bypass-acc770fbd019?source=rss------bug_bounty-5)
When most people talk about recon, they picture running a couple of tools, dumping thousands of subdomains, and then… getting lost in the…Continue reading on Medium » (https://saeed0x1.medium.com/how-i-use-perplexity-for-bug-bounty-recon-and-squeeze-every-last-drop-out-of-it-a7061842a77f?source=rss------bug_bounty-5)
From Simple Restriction Bypass to Internal Privilege Escalation to High Impact IDOR

IntroductionContinue reading on Medium »
Read more...
Azure WebApp Node.JS + backed based on AKS + Psql
https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/

<!-- SC_OFF -->My corporate it is delivering some kind of application based on public WebApp services with backed based on AKS+psql. We are wondering how we can check vulnerabilities/app pentest regularly from our side? Which tool should we consider to use? <!-- SC_ON --> submitted by /u/smierdzigira (https://www.reddit.com/user/smierdzigira)
[link] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/)
Where to start an offensive Role
https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/

<!-- SC_OFF -->Hi, I'd like to know where to start a offensive Role learning path, I know certs, such as eJPT, OSCP, PNPT, PJPT. I've never done machines on TryHackme o HTB, I focused on defensive role as a SOC Analyst, however, I would like to switch to an hacking role, but I don't know how to start. What can you recommend me, which path o certs you'd recommend me to jump over hacking with pretty basic knowledge? <!-- SC_ON --> submitted by /u/Commercial_Baker_236 (https://www.reddit.com/user/Commercial_Baker_236)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/)
IDOR in Invitation Flow Leads to Denial of Signup and Account Manipulation

IntroductionContinue reading on Medium »
Read more...
Path Confusion: The Subtle Trick That Fooled the Cache

What is Web Cache Deception? Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium »
Read more...
Logical 2FA Bypass via Missing clientId Parameter in Profile Update Endpoint

IntroductionContinue reading on Medium »
Read more...