Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Mythos can't replace real penetration testers and AI is not a threat, its a workforce amplifier.
https://www.reddit.com/r/Pentesting/comments/1strrg5/mythos_cant_replace_real_penetration_testers_and/

<!-- SC_OFF -->Hi All! I grew tired of hearing about how Mythos / AI will replace human penetration testers. Those of us who understand that real penetration testing is not a checkbox exercise, also know that AI can't touch what we do. I called it out here as best as I could and wanted to share. I welcome feedback, questions, etc. but I figured you'd all appreciate this. https://netragard.com/blog/claude-mythos-and-the-hype-that-will-get-you-breached/ <!-- SC_ON --> submitted by /u/netragard-inc (https://www.reddit.com/user/netragard-inc)
[link] (https://www.reddit.com/r/Pentesting/comments/1strrg5/mythos_cant_replace_real_penetration_testers_and/) [comments] (https://www.reddit.com/r/Pentesting/comments/1strrg5/mythos_cant_replace_real_penetration_testers_and/)
Recherche binôme sérieux (15 ans) – apprentissage & pratique en cyber / programmation / business / tech 🇫🇷
https://www.reddit.com/r/Pentesting/comments/1stw2vj/recherche_bin%C3%B4me_s%C3%A9rieux_15_ans_apprentissage/

<!-- SC_OFF -->Hey, Je cherche un binôme motivé (français de préférence) pour progresser sérieusement en cybersécurité principalement, et en tech en général. Moi : • Intéressé par le pentest / bug bounty / programmation / business • J’aime les projets concrets (scripts, outils, automatisation, sites web, SaaS) • Objectif long terme : monter en compétences + créer des projets (SaaS, etc.) Je cherche : • Quelqu’un de sérieux, régulier et ambitieux • Partant pour : • faire des CTF à 2 • apprendre ensemble (sécurité, dev, systèmes) • lancer des projets tech Pourquoi : Aller plus vite, se motiver et construire quelque chose de solide ensemble. Si t’es chaud, envoie-moi un message <!-- SC_ON --> submitted by /u/DataHorizon- (https://www.reddit.com/user/DataHorizon-)
[link] (https://www.reddit.com/r/Pentesting/comments/1stw2vj/recherche_bin%C3%B4me_s%C3%A9rieux_15_ans_apprentissage/) [comments] (https://www.reddit.com/r/Pentesting/comments/1stw2vj/recherche_bin%C3%B4me_s%C3%A9rieux_15_ans_apprentissage/)
Open Redirect Simple Bug, Powerful Chains: Phishing Se OAuth Bypass Tak! (Hinglish Mein)

Series: Bug Bounty Zero se Hero 🦸 | Article #22 By HackerMD | 16 min readContinue reading on Medium »
Read more...
The Easiest Bug Bounty Win You’re Overlooking [The $$ Bug Hiding in Plain Sight]

Today,Continue reading on Medium »
Read more...
SameSite=Strict? No Problem — Bypassing It With a Client-Side Redirect

Hey everyone, let’s talk about another CSRF lab from PortSwigger.net.Continue reading on Medium »
Read more...
GitHub Dorking: The Complete 2026 Hunter’s Guide to Finding Exposed Secrets

Every day, developers accidentally push secrets to public GitHub repositories. API keys. Database passwords. AWS credentials. Private…Continue reading on Medium »
Read more...
SSRF → Cloud Compromise — From Internal Access to Credentials

✍️ IntroductionContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
How a Newline Injection in Folder Names Broke Access Revocation: 750$ Bug

How a Newline Injection in Folder Names Broke Access Revocation Sometimes the smallest input validation issues can snowball into serious business logic flaws. This bug is a great example — a simple newline character (%0a) in a folder name was enough to block owners from revoking access rights, leaving attackers stuck with elevated privileges.Understanding the Target CollabSpace(pseudo name for private bbp product) is a cloud-based platform for project collaboration, offering resource sharing, folder management, and granular access controls. Owners can share resources and grant collaborators rights such as View, Edit, or Transfer Edit Rights. To maintain control, project owners should always be able to revoke or update collaborator access. However, this restriction was bypassed by abusing folder naming logic.The Flaw: Newline Injection in Folder Names The vulnerability occurred because the backend failed to validate folder names properly. By creating a folder with a newline character (%0a) at the start of its name, the system broke critical permission workflows. Here’s the malicious request:POST /api/v1/fs?path=&rid=<resource_id>&dirname=%0aattackerfolder HTTP/2 Host: collabspace.com This created a folder with a malformed name that disrupted backend path handling.Steps to ReproduceOwner grants Transfer Edit Rights to a collaborator (attacker).Attacker(editor user) creates a folder with %0a at the start of the folder name.Owner attempts to revoke rights or delete the folderThis action fails due to backend errors triggered by the malformed folder name. Result: The attacker retains their access indefinitely.ImpactPersistent Access: Attackers could keep edit rights permanently.Denial of Control: Owners couldn’t revoke access or delete malicious folders.Workflow Disruption: Ownership revocation logic was effectively broken.Potential Abuse: Attackers could create multiple such folders, locking down workspaces.Bounty & Program ResponseReported: July 7, 2025Triaged: July 9, 2025Severity: High (8.5) → downgraded to Medium (6.0)Bounty Awarded: $500 + $250 bonus The program acknowledged that although the confidentiality impact was low, this was a well-crafted and creative finding that broke ownership workflows, which earned a bonus.Key TakeawaysAlways check user inputs, including folder and file names.Small oversights in business logic can cause privilege persistence issues.Test boundaries with unusual inputs: newlines, nulls, special characters often reveal flaws.Even if a bug seems minor, well-documented reports can lead to bonus rewards.Conclusion This was a unique case where a simple newline injection caused project owners to lose control over collaborator access. It highlights how critical input validation is for access control and ownership workflows. Until next time, happy hacking! 🚀Connect and Engage 💬 What’s your experience with business logic bugs? Follow me on Twitter: @a13h1_ Keep clapping, commenting, and sharing your thoughts — your support motivates me to share more real bug bounty stories! How a Newline Injection in Folder Names Broke Access Revocation: 750$ Bug was originally published in InfoSec Write-ups on Medium, where people are continuing the conversation by highlighting and responding to this story.
Read more...
“Bug Bounty Bootcamp #35: SSRF — Turning the Server Into Your Personal Proxy to Hack Internal…

Imagine if you could trick a web server into visiting internal websites, reading local files, and even scanning private IP ranges on your…Continue reading on InfoSec Write-ups »
Read more...
Reflected XSS in Bali Government Search Endpoint

Summary:Continue reading on Medium »
Read more...
I Found AWS Credentials in a Public JavaScript Bundle. Here’s What That Means.

The bundle was minified. The credentials weren’t.Continue reading on Medium »
Read more...
How to Build a Fully Rooted Android 14 (API 34) Emulator on Windows 11 Using rootAVD

Create a modern rooted Android lab for pentesting, reversing, and mobile app analysis.Continue reading on MeetCyber »
Read more...
AEM Misconfiguration: How I Pulled 127MB of Internal Repository Data From a Luxury Brand — No Auth…

The URL was eight characters longer than it should have been. That’s all it took.Continue reading on Medium »
Read more...
dmi XSS → Admin Takeover — From Browser Control to Full Power

✍️ IntroductionContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...