Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
بِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِ
اللَّهُمَّ صَلِّ وَسَلِّمْ وَبَارِكْ عَلَى سَيِّدِنَا مُحَمَّدٍContinue reading on Medium » (https://medium.com/@0xs3fo/how-i-turned-3-into-8-paid-bugs-b81c5384465c?source=rss------bug_bounty-5)
Bypassing 2FA via State Overwrite: A Tale of Logic Flaws and WAF Evasion

How an unprotected API endpoint allowed complete removal of Two-Factor Authentication using a desynchronized state.Continue reading on Medium »
Read more...
How an unprotected API endpoint allowed complete removal of Two-Factor Authentication using a desynchronized state.Continue reading on Medium » (https://medium.com/@HackerMD/bypassing-2fa-via-state-overwrite-a-tale-of-logic-flaws-and-waf-evasion-7e8c15a76282?source=rss------bug_bounty-5)
How I Earned Over $1,000+ from Local Bug Bounty Programs

Hi, my name is Rangga.Continue reading on Medium »
Read more...
The Bugs That Actually Hurt You Aren’t the Fancy Ones

I used to think hacking was about finding something… impressive.Continue reading on Medium »
Read more...
JWT & Token Exploitation — Advanced API Attacks (Part 5)

Break authentication, control sessions, and own the APIContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
How I Earned 100 CHF Finding a Real-World Vulnerability

Hi everyone, I found a simple vulnerability through fuzzing.Continue reading on Medium »
Read more...
How I Ended Up in the WHO Hall of Fame via Google Dorking

Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium »
Read more...
Copy-Fail (CVE-2026-31431): From Low-Privileged Shell to Root in Seconds

From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root AccessContinue reading on Medium »
Read more...
Credential Stuffing picoCTF Writeup

Challenge DescriptionContinue reading on Medium »
Read more...
Threat Hunting for Network Based Attacks - LetsDefend [Part 2]

This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.Continue reading on Medium »
Read more...
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took

Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…Continue reading on Medium »
Read more...
Introduction & Phases Of Pentesting : From Structured Recon to Exploit Chaining ☠️

In modern offensive security, the objective is not just exploitation—it’s controlled impact, stealth, and precision.Continue reading on Medium »
Read more...