Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
When AI Gossips: How I Eavesdropped on a Federated Learning System

You know that feeling when you’re at a party, and you can piece together everyone’s drama just by listening to random conversation…Continue reading on InfoSec Write-ups »
Read more...
How I Check for Subdomain Takeovers Part 1

Subdomain takeovers is a high risk vulnerability that negatively impacts businesses, but if found, can result in big rewards for a bug…Continue reading on InfoSec Write-ups »
Read more...
A new Tool for Silent Device Tracking
https://www.reddit.com/r/redteamsec/comments/1pn0ea2/a_new_tool_for_silent_device_tracking/

<!-- SC_OFF --> Hey everyone, I just released WaSonar, an WhatsApp reconnaissance tool that can enumerate how many devices are linked to an account (Desktop/Web/Phone), figure out when they come online using silent RTT probes, and remotely exhaust a target's battery, data, and performance with zero user interaction or alerts. Try it out (no setup needed): npx wasonar-cli login or install via npm install -g wasonar-cli Source: https://github.com/AjayAntoIsDev/wasonar <!-- SC_ON --> submitted by /u/Floopy1704 (https://www.reddit.com/user/Floopy1704)
[link] (https://github.com/AjayAntoIsDev/WaSonar) [comments] (https://www.reddit.com/r/redteamsec/comments/1pn0ea2/a_new_tool_for_silent_device_tracking/)
Your Browser Is Spying On You — Here’s Proof

Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…Continue reading on InfoSec Write-ups »
Read more...
I Didn’t Hack Anything — The App Gave Me Admin Access by Itself

Hey there!😁Continue reading on InfoSec Write-ups »
Read more...
How I Bypassed Voucher Limits Using a Race Condition Vulnerability

So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…Continue reading on InfoSec Write-ups »
Read more...
The Paradox of the 3.4 Million: Why You Can’t Find a Job in a “Desperate” Industry

If you scroll through LinkedIn or read the latest annual reports from (ISC)², you will see the same headline repeated ad nauseam: “The…Continue reading on InfoSec Write-ups »
Read more...
dig Command Explained: A Simple Guide to DNS Lookups for Networking & Cybersecurity

Learn what the dig command is, how DNS works, and how dig helps debug and investigate DNS in networking and cybersecurity.Continue reading on Medium »
Read more...
Your Browser Is Spying On You — Here’s Proof

Hi Vipul from The Hacker’s Log here 👋 Let me tell you a story that starts innocently… and ends with your browser knowing where you’ve…Continue reading on InfoSec Write-ups »
Read more...
How I Bypassed Voucher Limits Using a Race Condition Vulnerability

So last night I played a CTF. Of course, it was free and with no prize. I know you are not here to listen my bla bla bla about my CTF…Continue reading on InfoSec Write-ups »
Read more...
The Paradox of the 3.4 Million: Why You Can’t Find a Job in a “Desperate” Industry

If you scroll through LinkedIn or read the latest annual reports from (ISC)², you will see the same headline repeated ad nauseam: “The…Continue reading on InfoSec Write-ups »
Read more...
Bug Bounty Burnout and the Boredom of Repetitive Tasks

Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…Continue reading on Medium »
Read more...
CSRF vs JWT: The One Story That Finally Makes It Click

Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do. Today, let’s meet their sneaky…Continue reading on Medium »
Read more...
Deep Dive: OAuth 2.0 Vulnerabilities & Exploitation Guide

OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…Continue reading on MeetCyber »
Read more...
Negative AddOn to Financial Flaw — Business Logic Vulnerability

My Journey into a Rental Car Service’s Financial FlawContinue reading on Medium »
Read more...
Beginner Bug Bounty Guide

## 🚀 Introduction Bug bounty is one of the easiest ways to enter cybersecurity without a degree. If you understand how websites work and…Continue reading on Medium »
Read more...
# Common Web Vulnerabilities Every Developer Should Know

## 🔍 Introduction Most successful hacks don’t use advanced techniques. They exploit basic web vulnerabilities that developers often…Continue reading on Medium »
Read more...
$25,000| Critical Vulnerability was Found on HackerOne

In the world of bug bounty hunting, finding a vulnerability on the platform itself — HackerOne — is the ultimate “Inception” moment.Continue reading on Medium »
Read more...
Recon Dorking: The Art of Advanced Information Gathering for Cybersecurity

Subtitle: 50+ Techniques and Tools That Separate Amateurs from Professionals in ReconnaissanceContinue reading on Medium »
Read more...
A Hacker’s Christmas: Bug Bounties by Candlelight

While the world sleeps under tinsel and cheer, We grep through endpoints, one eye on the year. Firewalls whisper, logs softly confess…Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Buried in JavaScript: How One Comment Led Me to a Production API Key

Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...