Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
I recently earned a total of $,$$$ in bug bounty rewards from a single target: https://www.[REDACTED].com/ — and it all started with…Continue reading on Medium » (https://medium.com/@depro0x/how-i-earned-by-escalating-a-basic-scan-into-critical-exposure-using-ai-c067d0a0580a?source=rss------bug_bounty-5)
“Bug Bounty Bootcamp #35: SSRF — Turning the Server Into Your Personal Proxy to Hack Internal…

Imagine if you could trick a web server into visiting internal websites, reading local files, and even scanning private IP ranges on your…Continue reading on InfoSec Write-ups »
Read more...
Imagine if you could trick a web server into visiting internal websites, reading local files, and even scanning private IP ranges on your…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/bug-bounty-bootcamp-35-ssrf-turning-the-server-into-your-personal-proxy-to-hack-internal-c9f74582cf0c?source=rss------bug_bounty-5)
How I Found a Critical Bug Using Claude Desktop (Free)

TL;DR: I fed a JavaScript bundle to Claude Desktop (I use Burp MCP with Claude). It mapped hidden endpoints I’d missed after multiple…Continue reading on Medium »
Read more...
Security Assessment — Pentesting: 23andMe Web Platform

Author: Leen Adeeb HackerOne: leenadeeb Program: 23andMe Bug Bounty (Public) Testing Date: April 23, 2026 Scope: api.23andme.com ·…Continue reading on Medium »
Read more...
Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)

Last week, 139 vulnerabilities were disclosed in 116 WordPress Plugins and 10 WordPress Themes, with contributions from 84 vulnerability…Continue reading on Medium »
Read more...
Bypassing a Payment Gateway Through Smali-Level Dead Code Discovery

How static analysis of an unused code path led to a full payment bypass in a production mobile application.Continue reading on Medium »
Read more...
Security Assessment: 23andMe Web Platform

Authorized bug bounty testing across authentication flows, object-level authorization, client-side disclosure, and e-commerce logic on a…Continue reading on Medium »
Read more...
How a Fake Image and an Expired Token Made a Server Confess Everything

During a recent assessment of a mobile application’s backend API, I triggered a verbose error response from a profile image upload…Continue reading on Medium »
Read more...
WebVersePro Labs — Challenge: Fermata Writeup (Reflected XSS)

OBJECTIVE: To identify the injection point, break out of an HTML comment block, and execute arbitrary JavaScript to retrieve the challenge…Continue reading on Medium »
Read more...
Race Condition Allows Users to Obtain More Than 1 Free Domain

Disclaimer: This is a report from someone else that I am studying, not my own finding. (Source: Automattic | Report #2616045 — Race…Continue reading on Medium »
Read more...
Day 10: Bypassing SameSite Lax with Method Override (CSRF Lab Walkthrough)

hello everyone, this is nobody.Continue reading on Medium »
Read more...
Guía Maestra de SSRF: Estrategias de Explotación y Mitigación

Aprende a detectar y explotar vulnerabilidades SSRF en entornos Cloud-Native, desde servicios de metadata hasta evasión de filtros.Continue reading on Medium »
Read more...
Bug Bounty Series— Part 1 (Bug Bounty Basics)

Inside: A deep dive into the lessons learned and techniques applied during my latest hands-on experiments.Continue reading on Medium »
Read more...
Currently on a internal pen test, need some fresh perspectives
https://www.reddit.com/r/Pentesting/comments/1stfh75/currently_on_a_internal_pen_test_need_some_fresh/

<!-- SC_OFF -->So I am currently on an internal AD pentest. I started of with responder and I got a lot of hashes both user and computer. SMB signing is disabled in some hosts so did a relay got an interactive smb shell, but all the accounts I relayed did not have any permissions to open the ADMIN and C share. I ran a mitm6 attack and got the loot. Took all the SAM account and tried asreproasting and kerberoasting, but didn’t yield to much. Found some VNC creds in an anonymous FTP server, but that doesn’t work either. I exploited iLO and created an admin user and signed into the site but the server is off and turning back on doesn’t seem smart. There is bluekeep and message queuejumper but I’m not going to exploit that since it’s too risky. Got an IPMI hash, need to crack it. This all that I have now and I still don’t have real initial access, seasoned penetesters out there how would you go forward now ? I know password guessing could work but I’ve never done it before and the lockout policy is pretty strong. Any ideas would be greatly appreciated. Just wanted to add - I’ve been trying to do an ADCS attack but I’m having tough time finding the CA. It’s not on the two DCs and I’ve heard it’s usually a standalone server. I think the client put that out of scope, because when I dumped in the loot, I saw a pentesting service account from the clients previous pentest. But how do you guys find the CA server though ? Another addition - both the DCs are vulnerable to coercion, petitotam and printer bug Edit - y’all are some real ones, I did not expect to get this much engagement and help especially this early in the morning. Y’all are goated. Thank you <!-- SC_ON --> submitted by /u/Tasty_Departure5277 (https://www.reddit.com/user/Tasty_Departure5277)
[link] (https://www.reddit.com/r/Pentesting/comments/1stfh75/currently_on_a_internal_pen_test_need_some_fresh/) [comments] (https://www.reddit.com/r/Pentesting/comments/1stfh75/currently_on_a_internal_pen_test_need_some_fresh/)