Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
CSRF Account Takeover: Rejected by the Security Team, Rewarded by the Security Director ($$$)

Hi guys,Continue reading on Medium »
Read more...
Reporting a Low-Severity YouTube Logic Issue to Google Taught Me a Lot

There’s a strange moment every beginner in cybersecurity remembers.Continue reading on Medium »
Read more...
I was testing an application that supported both local accounts and SAML-based SSO. Nothing looked obviously broken. Signatures were valid…Continue reading on Medium » (https://medium.com/@m0n3m/saml-username-collision-leading-to-full-ato-b1f3595e1cc8?source=rss------bug_bounty-5)
بسْمِ اللَّهِ الرَّحْمٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى النَّبِيِّ الْمُجَاهِدِ الشَّهِيدِ…اللَّهُمَّ انصُرْ أَهْلَ غَزَّةَ…Continue reading on Medium » (https://medium.com/@yosefmostef99/private-polls-not-really-exploiting-access-control-and-logic-flaws-943ff0bb5cc4?source=rss------bug_bounty-5)
JWT Security Testing Methodology: A Complete Guide for Bug Bounty Hunters

IntroductionContinue reading on Medium »
Read more...
The Dumbest Bug I Ever Found (And Why Complexity Is Overrated)

Three hours of complex testing. Four seconds of clicking a link.Continue reading on Medium »
Read more...
Steps or flow to start pen testing the Wordpress site
https://www.reddit.com/r/Pentesting/comments/1tqx73d/steps_or_flow_to_start_pen_testing_the_wordpress/

<!-- SC_OFF -->Yes, I understand that Google can provide tools and references, but I would like to have a proper discussion around this. I can find the tools myself, however, what I really need is guidance on the workflow, the logic behind it, where to begin, what milestones or goals should be achieved at each stage, and how the overall process should conclude. I’m looking to understand the complete approach rather than just collecting tools. <!-- SC_ON --> submitted by /u/El_Diablo_official (https://www.reddit.com/user/El_Diablo_official)
[link] (https://www.reddit.com/r/Pentesting/comments/1tqx73d/steps_or_flow_to_start_pen_testing_the_wordpress/) [comments] (https://www.reddit.com/r/Pentesting/comments/1tqx73d/steps_or_flow_to_start_pen_testing_the_wordpress/)
SecLeaf Q2 CTF 2026 Writeups

From reconnaissance to flag capture: a complete breakdown of my solutions.Continue reading on Medium »
Read more...