Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
A simple Wayback Machine recon uncovered archived pages exposing an estimated 44,560 job applicant emails, highlighting the risks of…Continue reading on OSINT Team » (https://osintteam.blog/how-a-simple-wayback-search-revealed-44-000-exposed-job-applicant-emails-c6c2c361985e?source=rss------bug_bounty-5)
Free Resources Every Broke College Student Can Use to Learn Hacking

No budget. No problem. Some of the best security professionals learned everything on free resources.Continue reading on Medium »
Read more...
My First Bug Bounty : A Beginner's Web Security Investigation

A beginner's journey from self-doubt and endless overthinking to taking action and conducting my first real web security investigation.Continue reading on Medium »
Read more...
How a Simple Wayback Search Revealed 44,000+ Exposed Job Applicant Emails

A simple Wayback Machine recon uncovered archived pages exposing an estimated 44,560 job applicant emails, highlighting the risks of…Continue reading on OSINT Team »
Read more...
[IDOR] The Ones Everyone Walks Past — Turning id=124 Into Account Takeover

What’s up everyone! Nitin hereContinue reading on Medium »
Read more...
My First Valid Bug: A Broken Object Level Authorization (BOLA) in Customer API

After months of grinding through labs, courses, and public program testing without a confirmed finding, I finally landed my first valid…Continue reading on Medium »
Read more...
From a Single WAF Bypass to 58,000+ Exposed Media Objects

A bug bounty case study in chaining overlooked misconfigurations into a full attack surfaceContinue reading on Medium »
Read more...
PortSwigger File Path Traversal Lab Solution, Simple Case

Web Security Academy by PortSwiggerContinue reading on Medium »
Read more...
Shadow AI: The Breach Nobody Approved, Signed Off On, or Even Saw Coming

A developer at a mid-sized fintech company pasted a chunk of proprietary source code into a free AI chatbot last spring, just to get a…Continue reading on Medium »
Read more...
Bug Hunting #1

Hello everyone,Continue reading on Medium »
Read more...
Got My First $$ Bug Bounty

I finally got my first bug bounty.Continue reading on InfoSec Write-ups »
Read more...
How I Systematically Find SQL Injection Bugs in Bug Bounty Programs (Step-by-Step Method)

SQLi is decades old and still one of the highest-paying bug classes in 2026 — here’s the exact recon-to-report process that actually finds…Continue reading on Medium »
Read more...
Dorks that could get you a good bounty in 2026

Google can index far more than publicly intended webpages. During an authorized bug bounty assessment, search operators can help…Continue reading on Medium »
Read more...
One IDOR, Three Leaks, $3K in Payouts

A single access-control mistake across multiple sharing APIs turned into three accepted reports – and three payouts.Continue reading on Medium »
Read more...
Need VAPT or Cybersecurity Support Before Your Next Product Launch or Enterprise Onboarding?
https://www.reddit.com/r/Pentesting/comments/1vkj1ar/need_vapt_or_cybersecurity_support_before_your/

<!-- SC_OFF -->Building or launching a product? Or has an enterprise customer suddenly asked: “Can you share your latest VAPT report?” Cenvox Global Solutions is a Chennai-based cybersecurity company supporting startups, SaaS companies, product teams, and growing businesses with security assessments and ongoing security services. Our team works across: 🔹 Web Application VAPT & Penetration Testing
🔹 API Security Testing
🔹 Mobile Application Penetration Testing
🔹 LLM / AI Application Security & Penetration Testing
🔹 Secure Source Code Review
🔹 MDR & SOC Security Monitoring These services can be useful when you’re preparing for a product launch, enterprise onboarding, customer-requested security assessment, retest, or ongoing security monitoring. Our approach is simple: Understand the product. Identify the real risks. Test what matters. Help the team fix it. You can review more about our services and background here:
www.cenvox.com If anyone here has an upcoming cybersecurity requirement, happy to connect and understand the scope. Feel free to DM me. <!-- SC_ON --> submitted by /u/rockzers (https://www.reddit.com/user/rockzers)
[link] (https://www.reddit.com/r/Pentesting/comments/1vkj1ar/need_vapt_or_cybersecurity_support_before_your/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vkj1ar/need_vapt_or_cybersecurity_support_before_your/)
BSCP I need tips
https://www.reddit.com/r/Pentesting/comments/1vkj9kk/bscp_i_need_tips/

<!-- SC_OFF -->I have soon the BSCP exam, I would like to know any tips that would help me pass it first try.
Everything is accepted! <!-- SC_ON --> submitted by /u/kirafoxoxx (https://www.reddit.com/user/kirafoxoxx)
[link] (https://www.reddit.com/r/Pentesting/comments/1vkj9kk/bscp_i_need_tips/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vkj9kk/bscp_i_need_tips/)
Can I progress in my career if I don't understand the TLS handshakes ?
https://www.reddit.com/r/Pentesting/comments/1vkp15q/can_i_progress_in_my_career_if_i_dont_understand/

<!-- SC_OFF -->I keep trying to memorise it but I fucking can't There is just a lot of steps . ServerKeyExchange , CertificateVerify, and a lot of other shit. I am in the middle of interviews and some people like to ask about these fundamentals. I just fucking can't. Been trying for 2 fucking days man <!-- SC_ON --> submitted by /u/ProcedureFar4995 (https://www.reddit.com/user/ProcedureFar4995)
[link] (https://www.reddit.com/r/Pentesting/comments/1vkp15q/can_i_progress_in_my_career_if_i_dont_understand/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vkp15q/can_i_progress_in_my_career_if_i_dont_understand/)