Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
The Authorization Check That Only Fired When You Asked It To

A payment-processor IDOR, a timing oracle, and how a hunting harness turned one weak signal into a criticalContinue reading on Medium »
Read more...
How I Got My First Bounty After a Year of Hunting

So, hello everyone! My name is Pranav Patil. I’m a security researcher and, like many of you reading this, I’m also on the bug bounty…Continue reading on Medium »
Read more...
The Offensive Security & Bug Bounty Stack I Built for Myself — Now Free for Everyone

A walkthrough of OpenSwarm’s 12-phase autonomous security pipeline — from scoping and recon to vulnerability hunting, exploitation…Continue reading on Medium »
Read more...
$$$ I Tried a Simple Registration Endpoint… and Accidentally Found a Critical Admin Account…

No login. No authorization. One API request. And suddenly… I had an administrator account.Continue reading on Medium »
Read more...
From an OTP Race Condition to Zero-Interaction Account Takeover

DisclaimerContinue reading on Medium »
Read more...
15 Access Control Mistakes Developers Keep Making: Master Real-World Application Security

Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?”Continue reading on Medium »
Read more...
Atlas
https://kitploit.com/en/tools/github/portbuster1337/atlas

Cross-platform network execution toolkit (SMB/Kerberos/WMI/LDAP/DCSync) built on TrustedSec's Titanis - NetExec-style workflow in C#
conductai
https://kitploit.com/en/tools/github/sseshachala/conductai

AI agent governance for teams. Runtime firewalls tell you what happened; Conduct Guard controls what can happen — signed policy, verified chain, fail-closed by default. Ships with Router (LLM proxy), 20+ compliance packs, canvas UI, and a playbook engine.
Hacker Club — Solving YesWeHack Dojo #53

IntroductionContinue reading on Medium »
Read more...
Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?”Continue reading on Medium » (https://medium.com/@verylazytech/15-access-control-mistakes-developers-keep-making-master-real-world-application-security-34df61fb9741?source=rss------bug_bounty-5)
alg:none and Friends — A JWT Hacking Field Guide

What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...