Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
CSS Injection in Real Bug Bounty Engagements: A Reproducible Pattern in Custom Profile Features

SummaryContinue reading on Medium »
Read more...
Hey Everyone, I am Dishant Modi. Today in this writeup I am not going to explain/decode any bug class and also not showing any bug…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/the-hardest-year-of-my-career-journey-65fd8edd19a3?source=rss------bug_bounty-5)
Most people think a Security Operations Center (SOC) only exists inside massive enterprises with expensive hardware, dedicated analysts…Continue reading on Medium » (https://medium.com/@pentesterclubpvtltd/build-your-own-security-operations-center-soc-at-home-a29208eebc42?source=rss------bug_bounty-5)
What happens when a web application lets you upload anything — and why that’s a bigger problem than most developers realize. Part 1 of the…Continue reading on Medium » (https://medium.com/@monceffennan1240/file-upload-attacks-understanding-the-basics-cb6d3ee3c29b?source=rss------bug_bounty-5)
MacBook for PenTesting
https://www.reddit.com/r/Pentesting/comments/1trp6gx/macbook_for_pentesting/

<!-- SC_OFF -->Would anyone recommend using MacBook as the primary machine for pen testing? Any difficulty with professional testing, tools availability and generally the experience compared to a windows machine? <!-- SC_ON --> submitted by /u/viixxiv (https://www.reddit.com/user/viixxiv)
[link] (https://www.reddit.com/r/Pentesting/comments/1trp6gx/macbook_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1trp6gx/macbook_for_pentesting/)
It feels good when the python script works! 😀
https://www.reddit.com/r/Pentesting/comments/1trqffp/it_feels_good_when_the_python_script_works/

<!-- SC_OFF -->[*] Target: localhost [+] WordPress detected [*] No username provided. Starting username enumeration... [*] Enumerating username for localhost... [+] Username found via REST API: vuln [+] USERNAME ENUMERATION SUCCESSFUL: vuln [*] Next step: Run password brute with: python domain_brute.py localhost vuln [?] Proceed with password brute now? (y/n): y [*] Brute forcing password for username: vuln [*] Testing 5000 password candidates... [*] Progress: 0/5000 [*] Progress: 100/5000 [*] Progress: 200/5000 [*] Progress: 300/5000 [*] Progress: 400/5000 [*] Progress: 500/5000 [*] Progress: 600/5000 <!-- SC_ON --> submitted by /u/Sad-Restaurant-7283 (https://www.reddit.com/user/Sad-Restaurant-7283)
[link] (https://www.reddit.com/r/Pentesting/comments/1trqffp/it_feels_good_when_the_python_script_works/) [comments] (https://www.reddit.com/r/Pentesting/comments/1trqffp/it_feels_good_when_the_python_script_works/)
Development for Pentesting
https://www.reddit.com/r/Pentesting/comments/1tru16r/development_for_pentesting/

<!-- SC_OFF -->I expect that I am going to be laughed at for asking this question but I'll take the risk regardless. I am doing a bachelors in software engineering (first semester) and I really want to get into pentesting and ethical hacking. Most people online say that I should just have basic programming, networking and operating system knowledge to get started and I can learn everything else as I go. However, I have heard some people say that if I really want to be good at ethical hacking I should first invest time learning development. So my question is that in order to become really good at this craft do I really need to spend time learning say full stack web development? If so, then how do I know I've learned enough development to get started with penetration testing. I've seen videos online where people discuss how self taught developers are bad at programming because they dont invest time learning data structured , algorithms and design and architectural patterns. Without these fundamentals they cant become good programmers and thats why I am asking this question cuz I am afraid that in the case of ethical hacking without the fundamentals (development) I might not be able to truly become an expert at this. PS. I could ask this question to an LLM but honestly I dont think they can provide the honesty and nuance of a human being. <!-- SC_ON --> submitted by /u/RoyalInformation2969 (https://www.reddit.com/user/RoyalInformation2969)
[link] (https://www.reddit.com/r/Pentesting/comments/1tru16r/development_for_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1tru16r/development_for_pentesting/)
Would this be a good stepping stone into pentesting
https://www.reddit.com/r/Pentesting/comments/1truopt/would_this_be_a_good_stepping_stone_into/

<!-- SC_OFF -->Hello,
I’m currently facing a bit of a dilemma and would appreciate some advice
.
I recently completed a 4-year apprenticeship as an IT specialist focused on platform engineering/development. I worked for a very small company (4 employees total), where my responsibilities were mainly IT support with some system administration mixed in. At the same time, I completed the eJPT and PNPT, and since January I’ve also been studying Cyber Security & Networking part-time while working full-time. I’m now looking for a new job and have received an offer for a Junior Cyber Security Engineer position at a large healthcare organization with more than 10‘000 employees. The role would include:
• Operating and maintaining security platforms in a critical healthcare environment
• Managing firewall policies, network segmentation, and proxy configurations (Fortinet)
• Handling security incidents, changes, and service requests in an ITSM environment
• Responding to security incidents
• Supporting security platform development across a large multi-site infrastructure
• Assisting with technical analysis, documentation, and implementation of security improvements My long-term goal is to move into offensive security / pentesting, ideally within the next couple of years. Do you think this role would be a good stepping stone toward pentesting, or would I be better off trying to land a SOC Analyst / Security Analyst position first? For context, I already have the eJPT and PNPT and plan to continue working on offensive security skills outside of work. I am 21 years old. I’d love to hear from people who made a similar transition.
Thanks! <!-- SC_ON --> submitted by /u/Friendly_Ad_78 (https://www.reddit.com/user/Friendly_Ad_78)
[link] (https://www.reddit.com/r/Pentesting/comments/1truopt/would_this_be_a_good_stepping_stone_into/) [comments] (https://www.reddit.com/r/Pentesting/comments/1truopt/would_this_be_a_good_stepping_stone_into/)
Looking for VAPT / Pentesting Internship
https://www.reddit.com/r/Pentesting/comments/1trxepo/looking_for_vapt_pentesting_internship/

<!-- SC_OFF -->Hey everyone, I’m from India and currently looking for a VAPT / penetration testing internship. I’ve been learning web security and working with tools like Burp Suite, and also exploring bug bounty. If anyone knows about internship openings (remote or India-based) or can guide me on where to apply, it would really help. Thanks in advance! <!-- SC_ON --> submitted by /u/Federal_Poetry_8384 (https://www.reddit.com/user/Federal_Poetry_8384)
[link] (https://www.reddit.com/r/Pentesting/comments/1trxepo/looking_for_vapt_pentesting_internship/) [comments] (https://www.reddit.com/r/Pentesting/comments/1trxepo/looking_for_vapt_pentesting_internship/)
IDOR BugBounty Labs: 5 Realistic Challenges to Master Insecure Direct Object Reference

An intentionally vulnerable e-commerce platform that teaches you to find, exploit, and understand IDOR vulnerabilities — the way they…Continue reading on Medium »
Read more...
How to Choose a Target That Won’t Waste Your Time

Not all bounty programs are worth hunting. Here’s how I pick the ones that pay.Continue reading on Medium »
Read more...