Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
They Called It Luck — So NASA Did It Again

by Ninad GowdaContinue reading on Medium »
Read more...
Password Reset Poisoning: Receiving the Same Reset Link in My Inbox

A short walkthrough on how experimenting with request structures led to observing a password reset poisoning behavior.Continue reading on Medium »
Read more...
A short walkthrough on how experimenting with request structures led to observing a password reset poisoning behavior.Continue reading on Medium » (https://medium.com/@twilight/password-reset-poisoning-receiving-the-same-reset-link-in-my-inbox-1cb2b3ab0b80?source=rss------bug_bounty-5)
How To Become a Hacker

Author: Eric S. RaymondContinue reading on Medium »
Read more...
Why Most Bug Bounty Findings Come From Thinking, Not Tools

A practitioner’s guide to sustainable web security testingContinue reading on MeetCyber »
Read more...
My server was asking Amazon for sensitive credentials, and it was all because of a PDF button.Continue reading on Medium » (https://medium.com/@codii/from-a-simple-certificate-to-a-critical-cloud-flaw-a-bug-bounty-journey-1e613efc42fc?source=rss------bug_bounty-5)
From a Simple Certificate to a Critical Cloud Flaw: A Bug Bounty Journey

My server was asking Amazon for sensitive credentials, and it was all because of a PDF button.Continue reading on Medium »
Read more...
Write-Up — Publicly Exposed MySQL on an “Inactive” Subdomain (KAIAWEB-216)

During a scoped bug-bounty engagement I discovered a MySQL/MariaDB service publicly reachable on shop.kaia.io (IP 147.93.79.55) that…Continue reading on Medium »
Read more...
How I Found a Zero-Click Flaw by Questioning a “Safe” Rendering Path

Most impactful vulnerabilities are not found by scanning tools or exploit templates. They are found by questioning assumptions.Continue reading on Medium »
Read more...
Why Most Bug Bounty Findings Come From Thinking, Not Tools

A practitioner’s guide to sustainable web security testingContinue reading on Write A Catalyst »
Read more...
Why AI-Driven Vibe Hacking Demands a New DevSecOps Mindset

AI is no longer a side feature in modern businesses. By the end of this decade, it will be embedded into every critical workflow — from…Continue reading on Medium »
Read more...
Hidden Admin Tools → Full Exploitation Chains

How JavaScript-Exposed Admin Features Turn Into Real-World Critical VulnerabilitiesContinue reading on OSINT Team »
Read more...