Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
When a patch for a critical vulnerability drops in a library downloaded over 500 million times a week, you expect it to be bulletproof…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/how-we-bypassed-an-axios-security-patch-cve-2026-42043-the-16-million-ip-loophole-6f2dd8968757?source=rss------bug_bounty-5)
If you’ve spent any time hunting on bug bounty programs, you’ve probably experienced this.Continue reading on Bug Bounty Hunting: A Comprehensive Guide in English and french » (https://medium.com/bug-bounty-hunting-a-comprehensive-guide-in/i-got-tired-of-running-the-same-recon-commands-every-day-so-i-built-this-92583e840c60?source=rss------bug_bounty-5)
The Live Demo Trap That Forced Me to Master Flutter Web Routing
https://medium.com/@muhammadomar0335/the-live-demo-trap-that-forced-me-to-master-flutter-web-routing-11a71e646b46?source=rss------bug_bounty-5

Picture this. You’re in a high-stakes technical interview, sharing your screen, demoing a production-ready application you built.Continue reading on Medium » (https://medium.com/@muhammadomar0335/the-live-demo-trap-that-forced-me-to-master-flutter-web-routing-11a71e646b46?source=rss------bug_bounty-5)
Hi Everyone! This write is about a Cross-Site Request Forgery (CSRF) vulnerability in the payment flow that allowed an attacker to trigger…Continue reading on Medium » (https://medium.com/@a13h1/575-csrf-triggering-payment-receipt-emails-without-user-consent-6014dd5a17b0?source=rss------bug_bounty-5)
Blind SSRF that Leads To Port Scaning And Descover The Infrastracture

There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium »
Read more...
Race Conditions — The $15k Bug That Breaks Logic

Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium »
Read more...
The Definitive Guide to Subdomain Enumeration

A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium »
Read more...
There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium » (https://medium.com/@tomahawk0ctf/blind-ssrf-that-leads-to-port-scaning-and-descover-the-infrastracture-1b1f1ef05453?source=rss------bug_bounty-5)
Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium » (https://medium.com/@cyber-ninjaaa/race-conditions-the-15k-bug-that-breaks-logic-bed2f325bc04?source=rss------bug_bounty-5)
A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium » (https://medium.com/@tanvir.infosec/the-definitive-guide-to-subdomain-enumeration-e2c04476ef27?source=rss------bug_bounty-5)
SAML Username Collision Leading to Full ATO

I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…Continue reading on Medium »
Read more...