How I Ended Up in the WHO Hall of Fame via Google Dorking
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium »
Read more...
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium »
Read more...
Medium
How I Ended Up in the WHO Hall of Fame via Google Dorking
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…
Copy-Fail (CVE-2026-31431): From Low-Privileged Shell to Root in Seconds
From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root AccessContinue reading on Medium »
Read more...
From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root AccessContinue reading on Medium »
Read more...
Medium
🚨 Copy-Fail (CVE-2026-31431): From Low-Privileged Shell to Root in Seconds
From Foothold to Full Control: Exploiting Copy-Fail (CVE-2026-31431) for Instant Root Access
Threat Hunting for Network Based Attacks - LetsDefend [Part 2]
This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.Continue reading on Medium »
Read more...
This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.Continue reading on Medium »
Read more...
Medium
Threat Hunting for Network Based Attacks - LetsDefend [Part 2]🔥
This write-up is based on a training scenario from LetsDefend and is shared for educational purposes only.
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…Continue reading on Medium »
Read more...
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…Continue reading on Medium »
Read more...
Medium
I Received an Official Bug Bounty Certificate from a Major Payment Platform — Here Is What It Took
Responsible disclosure, a DOM-Based XSS on an authentication domain, and a certificate signed by the security team. This is the story…
Introduction & Phases Of Pentesting : From Structured Recon to Exploit Chaining ☠️
In modern offensive security, the objective is not just exploitation—it’s controlled impact, stealth, and precision.Continue reading on Medium »
Read more...
In modern offensive security, the objective is not just exploitation—it’s controlled impact, stealth, and precision.Continue reading on Medium »
Read more...
Medium
🔍 Introduction & Phases Of Pentesting : From Structured Recon to Exploit Chaining ☠️
In modern offensive security, the objective is not just exploitation—it’s controlled impact, stealth, and precision.
How I Earned Over $1,000+ from Local Bug Bounty Programs
https://medium.com/@radenrangguy/how-i-earned-over-1-000-from-local-bug-bounty-programs-a79e21be0701?source=rss------bug_bounty-5
https://medium.com/@radenrangguy/how-i-earned-over-1-000-from-local-bug-bounty-programs-a79e21be0701?source=rss------bug_bounty-5
Hi, my name is Rangga.Continue reading on Medium » (https://medium.com/@radenrangguy/how-i-earned-over-1-000-from-local-bug-bounty-programs-a79e21be0701?source=rss------bug_bounty-5)
The Bugs That Actually Hurt You Aren’t the Fancy Ones
https://medium.com/@SatyamPathania/the-bugs-that-actually-hurt-you-arent-the-fancy-ones-07d17b5eac16?source=rss------bug_bounty-5
https://medium.com/@SatyamPathania/the-bugs-that-actually-hurt-you-arent-the-fancy-ones-07d17b5eac16?source=rss------bug_bounty-5
I used to think hacking was about finding something… impressive.Continue reading on Medium » (https://medium.com/@SatyamPathania/the-bugs-that-actually-hurt-you-arent-the-fancy-ones-07d17b5eac16?source=rss------bug_bounty-5)
JWT & Token Exploitation — Advanced API Attacks (Part 5)
https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/jwt-token-exploitation-advanced-api-attacks-part-5-0a1e965b097e?source=rss------bug_bounty-5
https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/jwt-token-exploitation-advanced-api-attacks-part-5-0a1e965b097e?source=rss------bug_bounty-5
Break authentication, control sessions, and own the APIContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french » (https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/jwt-token-exploitation-advanced-api-attacks-part-5-0a1e965b097e?source=rss------bug_bounty-5)
How I Earned 100 CHF Finding a Real-World Vulnerability
https://doordiefordream.medium.com/how-i-earned-100-chf-finding-a-real-world-vulnerability-15aa73293eb3?source=rss------bug_bounty-5
https://doordiefordream.medium.com/how-i-earned-100-chf-finding-a-real-world-vulnerability-15aa73293eb3?source=rss------bug_bounty-5
Hi everyone, I found a simple vulnerability through fuzzing.Continue reading on Medium » (https://doordiefordream.medium.com/how-i-earned-100-chf-finding-a-real-world-vulnerability-15aa73293eb3?source=rss------bug_bounty-5)
How I Ended Up in the WHO Hall of Fame via Google Dorking
https://g0w6y.medium.com/how-i-ended-up-in-the-who-hall-of-fame-via-google-dorking-f85d2ebf47f4?source=rss------bug_bounty-5
https://g0w6y.medium.com/how-i-ended-up-in-the-who-hall-of-fame-via-google-dorking-f85d2ebf47f4?source=rss------bug_bounty-5
Hey folks, I am back with a new writeup. This one is about how I found a Broken Access Control issue on a WHO subdomain using Google…Continue reading on Medium » (https://g0w6y.medium.com/how-i-ended-up-in-the-who-hall-of-fame-via-google-dorking-f85d2ebf47f4?source=rss------bug_bounty-5)
⚡ Full Automation — Recon → Exploit Pipeline (Part 6)
From target → endpoints → vulnerabilities → results — fully automatedContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
From target → endpoints → vulnerabilities → results — fully automatedContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
Medium
⚡ Full Automation — Recon → Exploit Pipeline (Part 6)
From target → endpoints → vulnerabilities → results — fully automated
AI Agents for Penetration Testing | Claude Code & Gamma4
AI Agents for Penetration Testing 🤖🔍Continue reading on Medium »
Read more...
AI Agents for Penetration Testing 🤖🔍Continue reading on Medium »
Read more...
Medium
AI Agents for Penetration Testing | Claude Code & Gamma4
AI Agents for Penetration Testing 🤖🔍
The “Invite Only” Loophole That Led to a $3,000 Payout
There is a specific kind of adrenaline that hits when you find a bug in a system that’s supposed to be “Invite Only.”Continue reading on Medium »
Read more...
There is a specific kind of adrenaline that hits when you find a bug in a system that’s supposed to be “Invite Only.”Continue reading on Medium »
Read more...
Medium
The “Invite Only” Loophole That Led to a $3,000 Payout
There is a specific kind of adrenaline that hits when you find a bug in a system that’s supposed to be “Invite Only.” It feels like finding…
Find SQL injection with burp Suite scanner
During a testing, we came across this situation:Continue reading on Medium »
Read more...
During a testing, we came across this situation:Continue reading on Medium »
Read more...
Medium
Find SQL injection with burp Suite scanner
During a testing, we came across this situation: