Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
WP-Hunter v2.0.2 Released: Faster, Smarter WordPress Security Scanning with 23 Exclusive PHP Rules

The ultimate open-source WordPress security scanner just got even better.Continue reading on Medium »
Read more...
Exploiting Weak JWT Secrets in a Bug Bounty Target

In this report, I will walk through a JWT-related security issue identified during testing and explain the steps taken to analyze it.Continue reading on Medium »
Read more...
The Invite That Took Over Accounts: A Logic Flaw

Hey Hackers, I am Parth Narula. A penetration tester, bug hunter, red teamer and overall a security researcher. I live for those moments…Continue reading on LegionHunters »
Read more...
My First CVSS 10.0 Bug: How I Took Control of Industrial Robots from My Bedroom ?

What if I told you that from my student bedroom, I was able to control robots located thousands of kilometers away? No, this isn’t science…Continue reading on Medium »
Read more...
Mass Account Lockout Using Organization Invites

الحمد لله الذي عَلَّمَ بالقلم.. عَلَّمَ الإنسانَ ما لم يَعْلَم والصلاةُ والسلامُ على خيرِ مُعَلِّمي الناسِ الخير محمد أما بعدContinue reading on Medium »
Read more...
Privilege Escalation via Role Manipulation

Last month I discovered a vulnerability in a private healthcare program that rewarded me $$$$ through their bug bounty program.Continue reading on Medium »
Read more...
6. WebSocket Authorization Bypass Vulnerability leads to $$$

Modern applications love WebSockets.Continue reading on InfoSec Write-ups »
Read more...
Lab: CORS vulnerability with basic origin reflection(Portswigger Labs)

This website has an insecure CORS configuration in that it trusts all origins.Continue reading on InfoSec Write-ups »
Read more...
6. WebSocket Authorization Bypass Vulnerability leads to $$$

Modern applications love WebSockets.Continue reading on InfoSec Write-ups »
Read more...
Breaking the Box: bypassing Node.js Filesystem Permissions via Symlinks (CVE-2025–55130)

Based on the original report by natann on HackerOne: https://hackerone.com/reports/3417819Continue reading on InfoSec Write-ups »
Read more...
How I Bought a $1400 Jacket for Free Using a Business Logic Flaw

How I Bought a $400 Jacket for Free Using a Business Logic Flaw Business logic flaws are some of the most dangerous yet overlooked vulnerabilities in modern web applications. They don’t rely on complex payloads or advanced tools—just understanding how the application is supposed to work and finding where it doesn’t.🎯 Target Overview The application was an e-commerce platform selling premium clothing items. One particular product caught my attention:Product: Lightweight l33t leather jacketPrice: ~$1400User account: Standard customer account The platform also offered multiple promotional features:New customer discount couponsNewsletter signup rewards At first glance, everything looked normal.🧠 Initial Testing After logging in, I added the leather jacket to my cart and moved to checkout.Coupon #1 – New Customer Offer The site advertised a coupon for new customers:NEWCUST5 Applying this coupon reduced the price by $5, as expected. I tried basic abuse techniques:Logging out and back inChanging the email addressReapplying the coupon ➡️ Result: Coupon reuse was blocked. So far, so good.🔍 Finding Another Discount Path While browsing the site further, I noticed a newsletter signup option at the bottom of the home page. It promised a discount for signing up. After subscribing, I received a new coupon:SIGNUP30 When applied at checkout, this coupon reduced the cart value by $401, effectively covering the entire jacket cost. This immediately raised a red flag 🚩.💥 Exploitation: Coupon Stacking Logic Flaw Here’s where things got interesting.Step-by-step Exploitation 1. Added the leather jacket to the cart 2. Applied NEWCUST5 3. Applied SIGNUP30 afterward What Should Have Happened? The application should reject multiple coupons Or validate whether discounts exceed product value Or restrict coupon combinations What Actually Happened? The application only validated the last coupon. It did not track previously applied discounts. The total price was recalculated incorrectly.➡️ Final cart value: $0 No errors. No warnings.🛒 Order Placement I proceeded to place the order. ✔️ Order confirmed ✔️ No payment required ✔️ Premium item successfully purchased for freeImpact achieved.> Business Logic Flaw – Coupon Reuse / Coupon Stacking📉 Impact This issue could lead to:Complete revenue loss on high-value productsAbuse by automated scriptsLoss of trust in promotional systems🏁 Final Thoughts This bug wasn’t about bypassing authentication or injecting payloads—it was about thinking logically and questioning assumptions. If you’re starting out in bug bounty hunting, business logic bugs are gold:Less competitionHigh impactHard to detect automaticallyThanks guys…Clap, Share, Comment your thoughts. How I Bought a $1400 Jacket for Free Using a Business Logic Flaw was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...