Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Every day, developers accidentally push secrets to public GitHub repositories. API keys. Database passwords. AWS credentials. Private…Continue reading on Medium » (https://medium.com/@thenewdate24/github-dorking-the-complete-2026-hunters-guide-to-finding-exposed-secrets-9a72331ed5bb?source=rss------bug_bounty-5)
Stored DoS via Missing Parameter

بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ ─────────────Continue reading on Medium »
Read more...
بِسْمِ اللَّهِ الرَّحْمَنِ الرَّحِيمِ ─────────────Continue reading on Medium » (https://medium.com/@mostafaabogoda8/stored-dos-via-missing-parameter-4e0394f211d4?source=rss------bug_bounty-5)
Adventures at Black Hat Asia 2026: Windows Shellcoding Training and MSRC Researcher Celebration

It’s been a crazy week at Black Hat Asia 2026 in Singapore.Continue reading on InfoSec Write-ups »
Read more...
From Fake Flag to Full RCE — Clankers Market Writeup

Clankers Market | b01lers CTF Solved by: S0n1c_404Continue reading on Medium »
Read more...
Environment Cross-Trust: Leveraging Staging APIs to “Buy” for $0.00

Many bug hunters are afraid to delve into the scope of famous companies, thinking it’s the most complex system they’ve ever seen. Based on…Continue reading on Medium »
Read more...
How I Earned €200 in 10 Minutes by Exploiting a Race Condition on a Job Application Portal

A simple business logic bypass using Burp Suite’s parallel sending feature — no complex exploit, no fancy tooling. Just timing.Continue reading on Medium »
Read more...
Easiest $100 on Hackerone | Null Byte Broke Authentication

Welcome again!Continue reading on OSINT Team »
Read more...
WebVersePro Labs — Challenge: Herbalist Remedies Writeup (NoSQL Injection)

OBJECTIVE: Bypass the authentication mechanism of a MongoDB-backed web application by exploiting a NoSQL Injection (NoSQLi) vulnerability…Continue reading on Medium »
Read more...
SSRF Master Guide: Exploitation and Mitigation Strategies

Learn how to identify and exploit SSRF vulnerabilities in cloud-native environments, from metadata services to filter bypass.Continue reading on Medium »
Read more...
Lab: HTTP request smuggling, confirming a CL.TE vulnerability via differential responses

Before diving into the lab, there are some important concepts we need to understand first: what Content-Length and Transfer-Encoding are…Continue reading on Medium »
Read more...