Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
“بِسْمِ اللَّهِ، وَالْحَمْدُ لِلَّهِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِ اللَّهِ،
 اللَّهُمَّ عَلِّمْنَا مَا يَنْفَعُنَا،…Continue reading on Medium » (https://medium.com/@geme000/authentication-bypass-vulnerability-leading-to-admin-panel-access-42ff825765bc?source=rss------bug_bounty-5)
When testing applications with Burp Suite, it’s easy to get overwhelmed by noisy traffic: analytics scripts, ads, assets, and external…Continue reading on Medium » (https://medium.com/@MaMad4Ever/filtering-out-noise-on-burp-suite-with-tls-pass-through-quick-guide-b8c58440f302?source=rss------bug_bounty-5)
️‍♂️ My Complete Recon Workflow for Bug Bounty Hunting (2025 Edition)

If you want to find real bugs, you have to start with real recon.Continue reading on Medium »
Read more...
What a Honeypot Taught Me About Real-World Deception in Cybersecurity

Most people think cybersecurity is about breaking things — finding bugs, crashing systems, getting a shell. It’s the highlight reel. But…Continue reading on OSINT Team »
Read more...
Most people think cybersecurity is about breaking things — finding bugs, crashing systems, getting a shell. It’s the highlight reel. But…Continue reading on OSINT Team » (https://osintteam.blog/what-a-honeypot-taught-me-about-real-world-deception-in-cybersecurity-0e8ea5241a34?source=rss------bug_bounty-5)
CVE-2025-55182: A Pre-Authentication RCE in Next.js - Complete Guide

Hey there, back again with another post! 😄Continue reading on InfoSec Write-ups »
Read more...
️ I Discovered a Parameter Pollution Vulnerability in a Payment QR System

BY NIMIT AHIR | “🚨 I Can Buy Anything for ₹5 by Exploiting a Payment QR Vulnerability ⚠️💸” | LinkedInContinue reading on Medium »
Read more...
JWT Authentication Bypass via Algorithm Confusion With No Exposed Key

How weak JWT algorithm handling exposes admin-level access without leaking a private key.Continue reading on MeetCyber »
Read more...
The Unconventional OSINT: How Dark Web Tools Gave Me the Edge to Find a $ Bug ️‍♂️

Free Link🎈Continue reading on InfoSec Write-ups »
Read more...
Backdoor CTF-2025: Flask of Cookies writeup | by Dargham Ali

Flask of Cookies WEB writeup by Dargham Ali for Backdoor CTF 2025: exploiting weak Flask SECRET_KEY to forge admin session cookie.Continue reading on Medium »
Read more...
Linux Network Sniffing & Packet Capture for Hackers

Network traffic analysis is one of the most critical skills for hackers, defenders, and red‑team operators. Today we cover tcpdump, Tshark…Continue reading on Medium »
Read more...
When One Slash Broke the Rules — Finding an Open Redirect on a Major Marketplace

Some bugs are loud and dramatic. Others slip in quietly, hiding in tiny assumptions — like how a website handles its URLs.Continue reading on Medium »
Read more...
The Day I Found a Public Laravel Log Viewer — And Why It Could Have Exposed an Entire Hospital…

Bug bounty hunting isn’t always about breaking into systems or crafting clever payloads. Sometimes, it’s about discovering something…Continue reading on Medium »
Read more...
API8:2023 Security Misconfiguration: Detección, Impacto y Mitigación

Guía completa sobre la vulnerabilidad API8:2023 (Security Misconfiguration): Ejemplos, metodología de detección y mitigación esencial.Continue reading on Medium »
Read more...
Bug Bounty Hunting: The Real Playbook for Beginners That Actually Works

The Exact Recon → Bug → Report Flow That Still Pays in 2025Continue reading on OSINT Team »
Read more...