Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
There is a specific kind of adrenaline that hits when you find a bug in a system that’s supposed to be “Invite Only.”Continue reading on Medium » (https://medium.com/@21bec131/the-invite-only-loophole-that-led-to-a-3-000-payout-53aff5cca73a?source=rss------bug_bounty-5)
Where to learn how to do bounty hunting?
https://www.reddit.com/r/Pentesting/comments/1t0kn0n/where_to_learn_how_to_do_bounty_hunting/

<!-- SC_OFF -->I am a cyber student and have heard from few experienced people that bounty hunting is really good for my beginning steps.
But i don't know how to start it or where to learn how it is done.
Any suggestions? <!-- SC_ON --> submitted by /u/ArSlayer_01 (https://www.reddit.com/user/ArSlayer_01)
[link] (https://www.reddit.com/r/Pentesting/comments/1t0kn0n/where_to_learn_how_to_do_bounty_hunting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1t0kn0n/where_to_learn_how_to_do_bounty_hunting/)
Duplicate Avoid Karna Bug Bounty Ka Sabse Bada Dard: Smart Hunting Se Pehle Pahuncho, Pehle Kamao!

Series: Bug Bounty Zero se Hero 🦸 | Article #28 By HackerMD | 19 min readContinue reading on Medium »
Read more...
Fool the Lockout — picoCTF Writeup

Challenge DescriptionContinue reading on Medium »
Read more...
️ Stealth vs Aggressive Recon — Avoid Bans & Maximize Coverage (Part 7)

Scan smarter, stay under the radar, and still find critical bugsContinue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french »
Read more...
The Ghost in the Machine: A Bug Bounty Short Story

It was 2:00 AM, and my terminal was a blur of scrolling green text. I was deep into a private bug bounty program for a massive corporate…Continue reading on Medium »
Read more...
Race Conditions in the Wild: How Parallel Requests Turned a Simple Bug into a Critical Exploit

Most bug hunters miss race conditions completely - not because they are hard, but because they test the wrong wayContinue reading on Medium »
Read more...
Parameter Index Manipulation Leading to Unauthorized Field Injection

IntroductionContinue reading on Medium »
Read more...
How Visma’s Verbose OAuth Debugger Exposed an Entire Identity Infrastructure

Target: oauth.developers.stagaws.visma.comContinue reading on Medium »
Read more...
The Punycode Paradox: When Unicode Normalization Turns Into an ATO

The Illusion: “Please Provide a Valid Email ID”Continue reading on MeetCyber »
Read more...
Impacket Net Toolkit | Pentester’s Guide

A Complete Active Directory Attack & Defense GuideContinue reading on Medium »
Read more...
Real Estate CRM Pentest: Broken Auth + IDOR + Stored XSS — Full Attack Chain

Author: Shikhali Jamalzade (@alisalive) Type: Authorized Black Box Penetration Test Target: Anonymized — Real Estate CRM Web Application…Continue reading on Medium »
Read more...
How I Broke a Travel Giant’s “Non-Refundable” Policy for a $12,000 Bounty

If you’ve ever booked a “non-refundable” hotel room, you know that feeling of dread when your plans change. You’re locked in. The money is…Continue reading on Medium »
Read more...