Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Sign Out Everywhere Bypass: How I Found a Session Revocation Vulnerability in OAuth & Password…

Bismillāh ir-Raḥmān ir-Raḥīm.Continue reading on Medium »
Read more...
How an OAuth 2.0 Redirect URI Bypass Led to Account Takeover and an $8,000 Bounty

Single Sign-On (SSO) integrations are designed to streamline authentication, but subtle oversights in how callback parameters are…Continue reading on Medium »
Read more...
Findomain v11.0.0-beta.1

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
Read more...
PortSwigger Lab: User role controlled by request parameter

Platform: PortSwigger Web Security AcademyContinue reading on Medium »
Read more...
AI Bug Hunting 101: From Setup to Your First Scan

Setting up Burp Suite, MCP, and AI skills to speed up bug huntingContinue reading on Medium »
Read more...
Single Sign-On (SSO) integrations are designed to streamline authentication, but subtle oversights in how callback parameters are…Continue reading on Medium » (https://medium.com/@t4nv1/how-an-oauth-2-0-redirect-uri-bypass-led-to-account-takeover-and-an-8-000-bounty-ad67ba4b0db6?source=rss------bug_bounty-5)
Linux Luminarium — hello hackers

Hello HackersContinue reading on Medium »
Read more...
Exploiting Race Condition to Break Idempotency & Corrupt Data Integrity

Hello hackers! I’m back with another writeup. This time, I want to share a recent finding from a HackerOne program (jobs.target.com).Continue reading on Medium »
Read more...
Pondering Paths — Linux Luminarium Part 2

Part 1 is already available on my profile. Check my profile if you haven’t read it yet.Continue reading on Medium »
Read more...
How to Extract Information from Websites: Automated OSINT Techniques and Tools

A Complete Guide to Web Scraping, OSINT, and Data Extraction Using Automated ToolsContinue reading on OSINT Team »
Read more...
Sentora
https://kitploit.com/en/tools/github/d3vhex/sentora

An open-source, self-hosted AI-powered SIEM, EDR and SOAR platform for modern security operations.
hayduk
https://kitploit.com/en/tools/github/jolovicdev/hayduk

Graphical attack management console for Metasploit: the lineage of Armitage as a single Go binary with a browser UI. Live network topology, campaign workflows, Hail Mary, sessions, report export, and team mode.