Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Ghost in the WAF: Building “WAF-Whisper” — An Adaptive Evasion Engine

“Engineering an Intelligent Python Framework to Defeat Modern Firewalls”Continue reading on System Weakness »
Read more...
“Engineering an Intelligent Python Framework to Defeat Modern Firewalls”Continue reading on System Weakness » (https://systemweakness.com/ghost-in-the-waf-building-waf-whisper-an-adaptive-evasion-engine-54366af7e99a?source=rss------bug_bounty-5)
A few days ago, I was trying to purchase a product from a website. Everything looked normal during checkout, but something caught my…Continue reading on Medium » (https://xamiron.medium.com/how-i-discovered-a-price-manipulation-bug-while-buying-a-simple-product-d2584addbc74?source=rss------bug_bounty-5)
How I Discovered a Price Manipulation Bug While Buying a Simple Product

A few days ago, I was trying to purchase a product from a website. Everything looked normal during checkout, but something caught my…Continue reading on Medium »
Read more...
A few days ago, while testing a web platform of a company (let’s call it example.com), I discovered a classic yet dangerous vulnerability…Continue reading on Medium » (https://xamiron.medium.com/idor-parameter-tampering-vulnerability-how-a-simple-url-change-exposed-hidden-content-c8ce26e512ca?source=rss------bug_bounty-5)
IDOR & Parameter Tampering Vulnerability — How a Simple URL Change Exposed Hidden Content

A few days ago, while testing a web platform of a company (let’s call it example.com), I discovered a classic yet dangerous vulnerability…Continue reading on Medium »
Read more...
Internal vs External Pentest: 12 Tools Clients Don’t Know Exist (and How Pros Use Them)

Ever sat across from a client, nodding as they ask about “just running Nessus or nmap” for their pentest? Here’s a stat: 80% of successful…Continue reading on Medium »
Read more...
Best AD first Certification
https://www.reddit.com/r/Pentesting/comments/1pgrdvh/best_ad_first_certification/

<!-- SC_OFF -->hi, what is one of the "best" ad cert for beginner / intermediate? I just finished GOAD labs from orange cyberdefense and I do medium / hard ad box on hack the box. I was thiking of doing the CRTP (maybe too hard I dont really know) since it isnt that expensive but what do you think about pnpt or maybe others cert. Which one will really help me secure an intership (17 years old in france) <!-- SC_ON --> submitted by /u/ApprehensiveGolf4989 (https://www.reddit.com/user/ApprehensiveGolf4989)
[link] (https://www.reddit.com/r/Pentesting/comments/1pgrdvh/best_ad_first_certification/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pgrdvh/best_ad_first_certification/)
Ever sat across from a client, nodding as they ask about “just running Nessus or nmap” for their pentest? Here’s a stat: 80% of successful…Continue reading on Medium » (https://medium.com/@verylazytech/internal-vs-external-pentest-12-tools-clients-dont-know-exist-and-how-pros-use-them-bab73f2b23a6?source=rss------bug_bounty-5)
How I Built a One‑Click Bookmarklet Tool to Spot Input Fields & ErrorsContinue reading on Medium » (https://medium.com/@cyber_comics/inspectre-796902843430?source=rss------bug_bounty-5)
InSpectre

How I Built a One‑Click Bookmarklet Tool to Spot Input Fields & ErrorsContinue reading on Medium »
Read more...
How I Earn 938$ Online In One Week Via Android

Hello this is my story of my first week of earning through online via only my Android.Continue reading on Medium »
Read more...
Authentication Bypass Vulnerability Leading to Admin Panel Access

“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ، اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا،…Continue reading on Medium »
Read more...
Filtering Out Noise on Burp Suite with TLS Pass-Through (Quick Guide)

When testing applications with Burp Suite, it’s easy to get overwhelmed by noisy traffic: analytics scripts, ads, assets, and external…Continue reading on Medium »
Read more...