Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems

After years in bug bounty, here’s something most beginners don’t realize:Continue reading on OSINT Team »
Read more...
$5,000 Bounty: How I Hijacked Google Gemini’s UI via Python Code Execution

This exploit can be weaponized to target anyone,no user is beyond its reach.Continue reading on Medium »
Read more...
Automation doesn’t find bugs. Automated workflows combined with manual validation do. While beginners waste time running Nuclei on random…Continue reading on System Weakness » (https://systemweakness.com/the-bug-bounty-automation-stack-that-can-generate-10k-open-source-tools-only-93ed3e8b3ee7?source=rss------bug_bounty-5)
## 🌙 A Long Night of Nothing
I had been testing this e-commerce platform for almost eight hours straight.
No XSS. No SQL injection. No…Continue reading on Medium » (https://medium.com/@abdulbarhacker/the-api-endpoint-that-shouldnt-have-exposed-50-000-user-records-4b29b9f20df2?source=rss------bug_bounty-5)
Sometimes the most critical vulnerabilities don’t start with complex payloads, fuzzers, or zero‑day chains.Continue reading on Medium » (https://samael0x4.medium.com/how-a-public-readme-txt-led-to-a-critical-wordpress-cve-dc8776454011?source=rss------bug_bounty-5)
In real-world SOC investigations, attackers often disguise malicious data as normal-looking logs.
 This picoCTF challenge recreates that…Continue reading on Medium » (https://medium.com/@VulnHunt3r/forensics-flag-in-flame-when-logs-turn-into-images-3fc526d0a5bf?source=rss------bug_bounty-5)
First Pentesting
https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/

<!-- SC_OFF -->Hey folks, I’ve been given the chance to do pentesting on a web app my company is building. I’m really into cybersecurity and this feels like a big opportunity for me. The thing is… I’m kinda lost. I know the basics (OWASP Top 10, how web apps work, endpoints, etc.), but when it comes to actually doing a pentest, I freeze. I don’t really know how to turn theory into practice. It feels like I just need a push to get started and gain confidence. How did you handle your first real pentest?
Any advice on how to approach it without overthinking everything? Appreciate any tips or personal experiences. Stay safe :) <!-- SC_ON --> submitted by /u/Abject-Offer3045 (https://www.reddit.com/user/Abject-Offer3045)
[link] (https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pov3ba/first_pentesting/)
Finally built the Pentest Report Maker I wish I had as a freelancer. It’s free to try.
https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/

<!-- SC_OFF -->Hey everyone, Like many of you, I’ve spent years wrestling with broken Word templates, fixing indentation for the 100th time, and manually copy-pasting the same remediation advice for IDORs and XSS. It’s the worst part of the job. I’d rather be hacking than formatting. A few months ago, I decided to build the tool I wish I had: Atomik.sh It’s a dedicated pentest reporting platform (not just a document generator). You feed it findings (manually or from Burp/Nessus), and it spits out a clean, standardized PDF/DOCX. Core Features: No Word Styles: It handles the formatting automatically. Findings Library: Save your common write-ups (CVEs/CWEs) so you never write the same description twice. AI Assist: Uses AI to draft Executive Summaries or fix grammar in your PoCs (you have full edit control). Multi-User: Teams can collaborate on the same report. The Ask: I’m not here to sell you a subscription today. I frankly just need senior pentesters to tear this apart and tell me what sucks. Does the workflow actually save time compared to your current templates? Is the AI output useful or hallucinated garbage? What critical feature is missing? For this Subreddit: The "Community" tier is free forever (watermarked exports). However, if you want to test a clean, production-ready export, I don't want you to pay. DM me your email after you sign up, and I will manually add a "Hustle Pack" (5 clean export credits - $100 worth) to your account for free for the first 10 pentesters! I built this to solve a real pain point, and I need brutal honesty to make it indispensable. Link: https://atomik.sh (https://atomik.sh/) <!-- SC_ON --> submitted by /u/iriof23 (https://www.reddit.com/user/iriof23)
[link] (https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/) [comments] (https://www.reddit.com/r/Pentesting/comments/1pp95ig/finally_built_the_pentest_report_maker_i_wish_i/)
They Called It Luck — So NASA Did It Again

by Ninad GowdaContinue reading on Medium »
Read more...
Password Reset Poisoning: Receiving the Same Reset Link in My Inbox

A short walkthrough on how experimenting with request structures led to observing a password reset poisoning behavior.Continue reading on Medium »
Read more...