Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
The Live Demo Trap That Forced Me to Master Flutter Web Routing
https://medium.com/@muhammadomar0335/the-live-demo-trap-that-forced-me-to-master-flutter-web-routing-11a71e646b46?source=rss------bug_bounty-5

Picture this. You’re in a high-stakes technical interview, sharing your screen, demoing a production-ready application you built.Continue reading on Medium » (https://medium.com/@muhammadomar0335/the-live-demo-trap-that-forced-me-to-master-flutter-web-routing-11a71e646b46?source=rss------bug_bounty-5)
Hi Everyone! This write is about a Cross-Site Request Forgery (CSRF) vulnerability in the payment flow that allowed an attacker to trigger…Continue reading on Medium » (https://medium.com/@a13h1/575-csrf-triggering-payment-receipt-emails-without-user-consent-6014dd5a17b0?source=rss------bug_bounty-5)
Blind SSRF that Leads To Port Scaning And Descover The Infrastracture

There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium »
Read more...
Race Conditions — The $15k Bug That Breaks Logic

Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium »
Read more...
The Definitive Guide to Subdomain Enumeration

A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium »
Read more...
There is a quote that says, “There is no place safe like home (127.0.0.1).” But now, it’s not safe either, hehe :)Continue reading on Medium » (https://medium.com/@tomahawk0ctf/blind-ssrf-that-leads-to-port-scaning-and-descover-the-infrastracture-1b1f1ef05453?source=rss------bug_bounty-5)
Race conditions are about tricking the server into doing something twice. Really really fast.Continue reading on Medium » (https://medium.com/@cyber-ninjaaa/race-conditions-the-15k-bug-that-breaks-logic-bed2f325bc04?source=rss------bug_bounty-5)
A practitioner’s deep-dive into every tested technique — passive, active, brute-force, and permutation-based — for mapping the full attack…Continue reading on Medium » (https://medium.com/@tanvir.infosec/the-definitive-guide-to-subdomain-enumeration-e2c04476ef27?source=rss------bug_bounty-5)
SAML Username Collision Leading to Full ATO

I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…Continue reading on Medium »
Read more...
Private Polls? Not Really — Exploiting Access Control and Logic Flaws

بسْمِ اللَّهِ الرَّحْمٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى النَّبِيِّ الْمُجَاهِدِ الشَّهِيدِ…اللَّهُمَّ انصُرْ أَهْلَ غَزَّةَ…Continue reading on Medium »
Read more...
CSRF Account Takeover: Rejected by the Security Team, Rewarded by the Security Director ($$$)

Hi guys,Continue reading on Medium »
Read more...
Reporting a Low-Severity YouTube Logic Issue to Google Taught Me a Lot

There’s a strange moment every beginner in cybersecurity remembers.Continue reading on Medium »
Read more...