Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
The Reflected XSS Hidden Inside a Login Page — And How a Single Parameter Became a Security Weak…
https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5

Some vulnerabilities feel almost poetic.
 A login page — a place designed to protect access — accidentally becomes the perfect spot for an…Continue reading on Medium » (https://medium.com/@anshubind89/the-reflected-xss-hidden-inside-a-login-page-and-how-a-single-parameter-became-a-security-weak-ad52a584292f?source=rss------bug_bounty-5)
The CGI Script That Should Have Stayed Hidden — How a Forgotten Diagnostic File Exposed an…
https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5

Every bug hunter knows this feeling:
 You’re scanning a domain, expecting the usual — a login page, some APIs, maybe a misconfigured…Continue reading on Medium » (https://medium.com/@anshubind89/the-cgi-script-that-should-have-stayed-hidden-how-a-forgotten-diagnostic-file-exposed-an-46e9215743cd?source=rss------bug_bounty-5)
How I Used an IDOR to Trigger XSS and Take Over All Accounts

The IDOR-to-XSS chain that compromised an entire platform.Continue reading on Medium »
Read more...
API10–2023: Unsafe Consumption of APIs — Explotación y Mitigación

Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium »
Read more...
Guía de API10/UCA: El consumo inseguro de datos de servicios externos o microservicios. Aprende a explotar y mitigar el riesgo.Continue reading on Medium » (https://medium.com/@jpablo13/api10-2023-unsafe-consumption-of-apis-explotaci%C3%B3n-y-mitigaci%C3%B3n-2ec626af806e?source=rss------bug_bounty-5)
Advice for a cybersecurity freshman interested in pentesting
https://www.reddit.com/r/Pentesting/comments/1pmbjma/advice_for_a_cybersecurity_freshman_interested_in/

<!-- SC_OFF -->Hi guys! I’m Mira, a first-year cybersecurity student, and I want to move toward pentesting. If you were in my position today, what would you focus on first? What skills or fundamentals matter the most early on? Any advice is really appreciated! <!-- SC_ON --> submitted by /u/Relative-Pizza7720 (https://www.reddit.com/user/Relative-Pizza7720)
[link] (https://www.reddit.com/r/Pentesting/comments/1pmbjma/advice_for_a_cybersecurity_freshman_interested_in/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pmbjma/advice_for_a_cybersecurity_freshman_interested_in/)
"Kali live CD Network issue"
https://www.reddit.com/r/Pentesting/comments/1pmd6q4/kali_live_cd_network_issue/

<!-- SC_OFF -->I installed Kali live image on my USB and made it to persistent though not fully due to partition issues however I am able to access kali usb bootable on my desktop but when I tried to connect with my mobile hotspot it's not showing properly and unable to connect. May I kindly request someone here pls help me fix this issue, Thanks to all everyone here in advance <!-- SC_ON --> submitted by /u/DepthUnique5960 (https://www.reddit.com/user/DepthUnique5960)
[link] (https://www.reddit.com/r/Pentesting/comments/1pmd6q4/kali_live_cd_network_issue/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pmd6q4/kali_live_cd_network_issue/)
CVE-2025-64669: Uncovering Local Privilege Escalation Vulnerability in Windows Admin Center
https://www.reddit.com/r/redteamsec/comments/1pncyhx/cve202564669_uncovering_local_privilege/

<!-- SC_OFF -->Microsoft has released a fix for CVE-2025-64669, addressing a local privilege escalation vulnerability we reported in Windows Admin Center.
This issue allowed low privileged users to escalate to SYSTEM by abusing trusted components under insecure filesystem permissions. Microsoft validated the finding and shipped a fix as part of the latest update.
This CVE represents only the first vulnerability from our research.
We identified four distinct vulnerabilities during the investigation, and additional fixes and disclosures are coming.
More details soon.
Stay tuned. <!-- SC_ON --> submitted by /u/Fun_Preference1113 (https://www.reddit.com/user/Fun_Preference1113)
[link] (https://cymulate.com/blog/cve-2025-64669-windows-admin-center/) [comments] (https://www.reddit.com/r/redteamsec/comments/1pncyhx/cve202564669_uncovering_local_privilege/)
studying
https://www.reddit.com/r/redteamsec/comments/1pnjktj/studying/

<!-- SC_OFF -->Hey guys this is my plan to start studying for OSCP, how does it look? Phase 1: HTB several machines a week + PJPT Phase 2: PNTP course + PG practice (official off sec PG subscription) Phase 3: One learn offsec year access + PG practice ps: I will get PJPT and PNPT for the content. I know the cert doesn’t carry as much recognition, I am doing it mainly just for the content. <!-- SC_ON --> submitted by /u/CryptoInsiderZ (https://www.reddit.com/user/CryptoInsiderZ)
[link] (http://hackthebox.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1pnjktj/studying/)
A new Tool for Silent Device Tracking
https://www.reddit.com/r/Pentesting/comments/1pmdfi1/a_new_tool_for_silent_device_tracking/

<!-- SC_OFF -->Hey everyone, I just released WaSonar, an WhatsApp reconnaissance tool that can enumerate how many devices are linked to an account (Desktop/Web/Phone), figure out when they come online using silent RTT probes, and remotely exhaust a target's battery, data, and performance with zero user interaction or alerts. Try it out (no setup needed): "npx wasonar-cli login" or install via "npm install -g wasonar-cli" Source: https://github.com/AjayAntoIsDev/wasonar <!-- SC_ON --> submitted by /u/Floopy1704 (https://www.reddit.com/user/Floopy1704)
[link] (https://www.reddit.com/r/Pentesting/comments/1pmdfi1/a_new_tool_for_silent_device_tracking/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pmdfi1/a_new_tool_for_silent_device_tracking/)
The Cybersecurity Paradox: The Market Isn't Dying, It's Maturing, and We Need to Thank the Villains.
https://www.reddit.com/r/Pentesting/comments/1pme1n6/the_cybersecurity_paradox_the_market_isnt_dying/

<!-- SC_OFF -->Hey everyone, I'm seeing a ton of posts from people saying the cybersecurity job market is cooked, especially for entry-level. It feels awful, but let's be realistic: it's not dying, it's just maturing. Too many people flooded the gate with the same resume: A boot camp, a Security+ cert, and zero practical IT/networking experience. Companies realized that hiring a dozen Tier 1 SOC analysts with no troubleshooting skills wasn't sustainable. We created an expectation that you could jump from zero to six figures just by passing a multiple-choice test. The Reality: That bubble has popped. The market is now filtering out people who can't actually do the work. I believe demand for specialized people is still high but for newbies who need 2 years of hand holding is dying. Let's Be Honest: We Need the Villains This is the cold truth about our entire industry, and why the jobs will never truly die. If every single black hat hacker, ransomware group, and nation-state actor vanished tomorrow, 80% of our jobs would disappear with them. We rely on the escalating sophistication of the attacks to guarantee our budgets and our high salaries. The criminals are the only reason the C-suite takes us seriously. They are the ultimate job security. THEN SHOULD WE THANK THE VILLAINS? or become one to help others? I hope my mouse will not ring after this💀 <!-- SC_ON --> submitted by /u/maxlowy (https://www.reddit.com/user/maxlowy)
[link] (https://www.reddit.com/r/Pentesting/comments/1pme1n6/the_cybersecurity_paradox_the_market_isnt_dying/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pme1n6/the_cybersecurity_paradox_the_market_isnt_dying/)
Looking for advice.
https://www.reddit.com/r/Pentesting/comments/1pmgi0s/looking_for_advice/

<!-- SC_OFF -->I'm a boilermaker doing a full pivot into cyber and this is my rough framework. Certifications while I work. eJPT → PNPT → OSCP What scenario would an aspiring pentester have to overcome in order to consider them competent and an asset to a team ? <!-- SC_ON --> submitted by /u/Minge_Ninja420 (https://www.reddit.com/user/Minge_Ninja420)
[link] (https://www.reddit.com/r/Pentesting/comments/1pmgi0s/looking_for_advice/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pmgi0s/looking_for_advice/)
$200 Bounty: XSS via X-Forwarded-Host Header That Also Triggered an Open Redirect

When Blind Trust in HTTP Headers Turned a Secure Website Into an Attack SurfaceContinue reading on OSINT Team »
Read more...
10 OSINT Tools Every Cybersecurity Professional Should Know (Before Hackers Do) ️‍♂️

Cybersecurity isn’t just about firewalls, exploits, or code.Continue reading on OSINT Team »
Read more...