Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
BlackField | HTB | Hard | OSCP Preparation

Firstly, export the machine’s IP as a variable. This means we don’t have to keep typing the IP of the target.Continue reading on Medium »
Read more...
From Manual Testing to Automation: Burp Suite + OpenCode Setup

IntroductionContinue reading on Medium »
Read more...
The “Incognito” Triage Fail: How Human Bias and Technical Ignorance Sabotage Real-World Security

What happens when a security researcher finds a vulnerability that affects 75% of global internet users, but the analyst tries to…Continue reading on Medium »
Read more...
I Stopped Chasing Tools And Started Finding Vulnerabilities

My scanner collection was impressive. My finding record was embarrassing.Continue reading on ILLUMINATION »
Read more...
Easiest Zero-click Account Takeover you’ll ever find

“And the forgot password link was sent to attacker’s mail, instead of victim’s mail” 😈 Oops, maybe we just went too ahead.Continue reading on Medium »
Read more...
186ms to Total Paralysis: Why “Security Features” are the New Denial of Service

What is more dangerous: A vulnerability that steals one user’s data, or a ‘Security Feature’ that allows an unauthenticated attacker to…Continue reading on Medium »
Read more...
Privilege Escalation — From Low Access to Full Control (Real-World Guide)

By GhostyjoeContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Lateral Movement — Turning One Compromise Into Full Control

By GhostyjoeContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
CSPT (Client-Side Path Traversal)

Alright, let’s talk about a bug that sounds boring… but can actually be 🔥 very spicy in bug bounty programs — CSPT (Client-Side Path…Continue reading on Medium »
Read more...
⚙️ 01. — Username and Password Enumeration via Different Responses

Difficulty: 🟢 ApprenticeContinue reading on Medium »
Read more...
Firstly, export the machine’s IP as a variable. This means we don’t have to keep typing the IP of the target.Continue reading on Medium » (https://medium.com/@SilentExploit/blackfield-htb-hard-oscp-preparation-20d804a3d1de?source=rss------bug_bounty-5)
What happens when a security researcher finds a vulnerability that affects 75% of global internet users, but the analyst tries to…Continue reading on Medium » (https://medium.com/@Xiac0heckmate/the-incognito-triage-fail-how-human-bias-and-technical-ignorance-sabotage-real-world-security-e2cf19fc52c6?source=rss------bug_bounty-5)