Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
How I Ended Up in the WHO Hall of Fame via Google Dorking

Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium »
Read more...
Copy-Fail (CVE-2026-31431): From Low-Privileged Shell to Root in Seconds

From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root AccessContinue reading on Medium »
Read more...
Credential Stuffing picoCTF Writeup

Challenge DescriptionContinue reading on Medium »
Read more...
Threat Hunting for Network Based Attacks - LetsDefend [Part 2]

This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.Continue reading on Medium »
Read more...
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took

Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…Continue reading on Medium »
Read more...
Introduction & Phases Of Pentesting : From Structured Recon to Exploit Chaining ☠️

In modern offensive security, the objective is not just exploitation—it’s controlled impact, stealth, and precision.Continue reading on Medium »
Read more...
Break authentication, control sessions, and own the APIContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french » (https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/jwt-token-exploitation-advanced-api-attacks-part-5-0a1e965b097e?source=rss------bug_bounty-5)
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium » (https://g0w6y.medium.com/how-i-ended-up-in-the-who-hall-of-fame-via-google-dorking-f85d2ebf47f4?source=rss------bug_bounty-5)
Full Automation — Recon → Exploit Pipeline (Part 6)

From target → endpoints → vulnerabilities → results — fully automatedContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
AI Agents for Penetration Testing | Claude Code & Gamma4

AI Agents for Penetration Testing 🤖🔍Continue reading on Medium »
Read more...
The “Invite Only” Loophole That Led to a $3,000 Payout

There is a specific kind of adrenaline that hits when you find a bug in a system that’s supposed to be “Invite Only.”Continue reading on Medium »
Read more...
Find SQL injection with burp Suite scanner

During a testing, we came across this situation:Continue reading on Medium »
Read more...