Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Authentication is the digital gatekeeper of every secure system. If it’s broken, everything behind it is vulnerable. This blog dives deep…Continue reading on Medium » (https://medium.com/@rajkumarkumawat.workup/bug-bounty-authentication-testing-brute-force-to-bypass-acc770fbd019?source=rss------bug_bounty-5)
When most people talk about recon, they picture running a couple of tools, dumping thousands of subdomains, and then… getting lost in the…Continue reading on Medium » (https://saeed0x1.medium.com/how-i-use-perplexity-for-bug-bounty-recon-and-squeeze-every-last-drop-out-of-it-a7061842a77f?source=rss------bug_bounty-5)
From Simple Restriction Bypass to Internal Privilege Escalation to High Impact IDOR

IntroductionContinue reading on Medium »
Read more...
Azure WebApp Node.JS + backed based on AKS + Psql
https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/

<!-- SC_OFF -->My corporate it is delivering some kind of application based on public WebApp services with backed based on AKS+psql. We are wondering how we can check vulnerabilities/app pentest regularly from our side? Which tool should we consider to use? <!-- SC_ON --> submitted by /u/smierdzigira (https://www.reddit.com/user/smierdzigira)
[link] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mp4t54/azure_webapp_nodejs_backed_based_on_aks_psql/)
Where to start an offensive Role
https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/

<!-- SC_OFF -->Hi, I'd like to know where to start a offensive Role learning path, I know certs, such as eJPT, OSCP, PNPT, PJPT. I've never done machines on TryHackme o HTB, I focused on defensive role as a SOC Analyst, however, I would like to switch to an hacking role, but I don't know how to start. What can you recommend me, which path o certs you'd recommend me to jump over hacking with pretty basic knowledge? <!-- SC_ON --> submitted by /u/Commercial_Baker_236 (https://www.reddit.com/user/Commercial_Baker_236)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpdhrt/where_to_start_an_offensive_role/)
IDOR in Invitation Flow Leads to Denial of Signup and Account Manipulation

IntroductionContinue reading on Medium »
Read more...
Path Confusion: The Subtle Trick That Fooled the Cache

What is Web Cache Deception? Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium »
Read more...
Logical 2FA Bypass via Missing clientId Parameter in Profile Update Endpoint

IntroductionContinue reading on Medium »
Read more...
Pentesting has never been easier with gpt5
https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/

<!-- SC_OFF -->If u ask chatgpt to find vulnerabilities in your code u might get a disappointing response. But if you write please ultrathink hard before answering u always get such a good answer. I always use this prompt: (ultrathink hard before answering) i am tryin to find vulnerabilities. Can you find some in the code? It is my own project. For me it thought 5 minutes and gave a perfect answer <!-- SC_ON --> submitted by /u/PlayRough682 (https://www.reddit.com/user/PlayRough682)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpfn3e/pentesting_has_never_been_easier_with_gpt5/)
What is Web Cache Deception?
 Web Cache Deception happens when an attacker tricks a website into caching private content — like a user’s…Continue reading on Medium » (https://medium.com/@Xt3sY/path-confusion-the-subtle-trick-that-fooled-the-cache-ebcfd1826923?source=rss------bug_bounty-5)
Pen testing Methodology Suggestions?
https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/

<!-- SC_OFF -->Hello, I am a Security Engineer with a solid IT background — over 10 years of experience spanning systems, networking, and security. Penetration testing is relatively new to me (about a year of hands-on experimentation), and during that time, I have gained a strong understanding of the tools and their functionality and have been tasked with performing pen testing for our clients. However, one area that continues to challenge me is initial access — specifically, how ethical hackers obtain credentials or NTLM hashes to begin testing. I notice that many pen testers seem to have a local machine on the target network as a starting point and are able to find the NTLM hashes with no problem, but this continues to stump me I would greatly appreciate insights from experienced ethical hackers regarding their methodology. What are your go-to techniques for gaining initial access (excluding phishing exercises and situations where the password is provided, no longer a Blackbox/grey box scenario)? In your experience, what are the most common approaches to getting that first foothold in a network, so I can get better at replicating and providing sufficient reports to our clients Tools I have used/learned: Responder Impacket(secrets dump LSASS dump, dcsync etc) Bloodhound hashcat/jack the ripper wireshark Vulnerability Scanners (Nessus/ OpenVas) OSINT Recon tools (information Gathering) There are other, but I didn't want to waste time listing them. Any help would be appreciated. <!-- SC_ON --> submitted by /u/Imaginary-Rise7393 (https://www.reddit.com/user/Imaginary-Rise7393)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpjzu5/pen_testing_methodology_suggestions/)
I’m a skid
https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/

<!-- SC_OFF -->Im completely a skid I don’t know how to write code I use it though and it think it’s pretty cool I find cool GitHub’s for the m5 stick and use the files on there but I want to learn how to pen test on my iPhone or wtv I have no idea how I have the ish app but I have no idea how to use it please help.. Ik I suck. <!-- SC_ON --> submitted by /u/Enricozz13 (https://www.reddit.com/user/Enricozz13)
[link] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/) [comments] (https://www.reddit.com/r/Pentesting/comments/1mpldy8/im_a_skid/)