Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
StegoRSA — picoCTF Writeup (Steganography + RSA Deep Dive)

Challenge DescriptionContinue reading on Medium »
Read more...
How I Found Internal Products Exposed via API

While testing a web application during my internship, I came across an interesting API endpoint:Continue reading on Medium »
Read more...
Hey there 👋
You’ve probably heard about the famous Y2K bug, right? The one that made the world panic as the year 2000 approached.Continue reading on Medium » (https://medium.com/@shubhamvartak01/the-year-2038-problem-the-next-y2k-waiting-to-happen-2ba3fdc72ea5?source=rss------bug_bounty-5)
Intro — Recently there was an incident involving Axios where a malicious version got pushed to npm. It wasn’t really a bug in Axios code…Continue reading on Medium » (https://medium.com/@akshatshirsat77/axios-npm-compromise-recreation-poc-write-up-302ee17e659b?source=rss------bug_bounty-5)
️Unmasking the Battlefield: Understanding the Professional Hacker Mindset

जय श्री राम 🚩 ,HackersContinue reading on Medium »
Read more...
Reverse Engineering a WhatsApp 0-Click Vulnerability: A Deep Dive into CVE-2025–43300

Based on “Reverse Engineering a WhatsApp 0-Click Vulnerability” by Billy EllisContinue reading on InfoSec Write-ups »
Read more...
An AI Grader Was Tricked Into Giving a Perfect Score Here’s How Prompt Injection Works

A real-world vulnerability class discovered in a production AI application — reproduced in a controlled lab to show developers exactly…Continue reading on Medium »
Read more...
Based on “Reverse Engineering a WhatsApp 0-Click Vulnerability” by Billy EllisContinue reading on InfoSec Write-ups » (https://infosecwriteups.com/reverse-engineering-a-whatsapp-0-click-vulnerability-a-deep-dive-into-cve-2025-43300-d8d425644fe9?source=rss------bug_bounty-5)
A real-world vulnerability class discovered in a production AI application — reproduced in a controlled lab to show developers exactly…Continue reading on Medium » (https://blackhawkk.medium.com/an-ai-grader-was-tricked-into-giving-a-perfect-score-heres-how-prompt-injection-works-613df9411584?source=rss------bug_bounty-5)
Exploiting Certificates for Lateral Movement

Pass-the-Certificate is a highly effective post-exploitation technique that leverages X.509 certificates instead of traditional passwords…Continue reading on Medium »
Read more...
AmassAdvanced Recon Mastery: Attack Surface Ko Poora Expose Karo! (Hinglish Mein)

Series: Bug Bounty Zero se Hero 🦸 | Article #7 By HackerMD | 18 min readContinue reading on Medium »
Read more...
How I Found a Critical SAML Authentication Bypasson a Major Automotive Company's Dealer Portal

INTRODUCTION:Continue reading on Medium »
Read more...
Advanced IDOR Guide: How to Find and Exploit Broken Access Control in Modern APIs

Stop looking for id=1. Start hunting the authorization mistakes developers don’t see.Continue reading on Medium »
Read more...