Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
<!-- SC_OFF -->Hello all, If you do bug bounty hunting or pentests you surely came across many hosts served from an NGINX server, in this lab (published to OWASP) I combined over 20 misconfigurations found in real world bug disclosures and both classic and novel security research, with an extensive blog where I explained everything you need to level up your NGINX hunting game. Feel free to check it out, give it a star on Github if you like it, and suggest any ideas you want me to add/fix... https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/ Happy hunting! <!-- SC_ON --> submitted by /u/OilOverall4190 (https://www.reddit.com/user/OilOverall4190)
[link] (https://vwad.owasp.org/app/damn-vulnerable-nginx-proxy-dvnp/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vnu9aw/lab_damn_vulnerable_nginx_proxy_dvnp/)
How to Find Your First Bug Bounty Vulnerability in 2026 (The Beginner Method That Actually Pays)

Everyone's searching CVE-2026-50522, Here's the step-by-step IDOR method beginners actually use to find paid bugs, by b0dj0x.Continue reading on Medium »
Read more...
Ash Keeps Searching the Tall Grass, While Python Prepares for the Next Gym Battle

Ash had learned something important about Pokémon battles.Continue reading on Medium »
Read more...
How Expired Domains Become Weapons for Scams and Malware

Alternative title: The Hidden Cybercrime Economy Behind Expired DomainsContinue reading on Medium »
Read more...
I Changed ₹500 to ₹1 — How I Found a Payment Logic Bug in a QR Code

The QR Code Looked Normal. The Payment Logic Wasn’t.Continue reading on Medium »
Read more...
A developer at a mid-sized fintech company pasted a chunk of proprietary source code into a free AI chatbot last spring, just to get a…Continue reading on Medium » (https://medium.com/@t3nv1/shadow-ai-the-breach-nobody-approved-signed-off-on-or-even-saw-coming-e97737fe30eb?source=rss------bug_bounty-5)
SQLi is decades old and still one of the highest-paying bug classes in 2026 — here’s the exact recon-to-report process that actually finds…Continue reading on Medium » (https://medium.com/@b0dj0x/how-i-systematically-find-sql-injection-bugs-in-bug-bounty-programs-step-by-step-method-0bbaf03c4722?source=rss------bug_bounty-5)
Google can index far more than publicly intended webpages. During an authorized bug bounty assessment, search operators can help…Continue reading on Medium » (https://medium.com/@thenewdate24/dorks-that-could-get-you-a-good-bounty-in-2026-a8cde06f18ed?source=rss------bug_bounty-5)
How a Simple API Misconfiguration Leaked PII of 100,000+ Users

A Quick Word on MeContinue reading on Medium »
Read more...