Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Buried in JavaScript: How One Comment Led Me to a Production API Key

Free Link 🎈Continue reading on InfoSec Write-ups »
Read more...
Twitter highlights, leaderboard screenshots, five-figure payouts, and “first critical of the month” posts paint a picture of constant…Continue reading on Medium » (https://mokhansec.medium.com/bug-bounty-burnout-and-the-boredom-of-repetitive-tasks-dacda4dac71a?source=rss------bug_bounty-5)
Yesterday, we discussed JWT tokens as digital wristbands that identify who you are and what you can do.
 Today, let’s meet their sneaky…Continue reading on Medium » (https://medium.com/@MuhammedAsfan/csrf-vs-jwt-the-one-story-that-finally-makes-it-click-16352ef67196?source=rss------bug_bounty-5)
OAuth 2.0 is the industry standard for authorization, allowing users to grant third-party websites and applications access to their…Continue reading on MeetCyber » (https://medium.com/meetcyber/deep-dive-oauth-2-0-vulnerabilities-exploitation-guide-a468f84d57b7?source=rss------bug_bounty-5)
## 🚀 Introduction
Bug bounty is one of the easiest ways to enter cybersecurity without a degree.
If you understand how websites work and…Continue reading on Medium » (https://medium.com/@abdulbarhacker/beginner-bug-bounty-guide-dfd886cfafd3?source=rss------bug_bounty-5)
The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…

Some vulnerabilities feel almost poetic. A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium »
Read more...
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…

Every bug hunter knows this feeling: You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium »
Read more...
The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…
https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5

Some vulnerabilities feel almost poetic.
 A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium » (https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5)
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…
https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5

Every bug hunter knows this feeling:
 You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium » (https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5)
How I Used an IDOR to Trigger XSS and Take Over All Accounts

The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium »
Read more...
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación

Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium »
Read more...
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium » (https://medium.com/@jpablo13/api10-2023-unsafe-consumption-of-apis-explotaci%C3%B3n-y-mitigaci%C3%B3n-2ec626af806e?source=rss------bug_bounty-5)