Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.2K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Ever found yourself staring down a “bypass” bug report and thinking, “How did we miss this?”Continue reading on Medium » (https://medium.com/@verylazytech/15-access-control-mistakes-developers-keep-making-master-real-world-application-security-34df61fb9741?source=rss------bug_bounty-5)
alg:none and Friends — A JWT Hacking Field Guide

What’s up everyone! Nitin here 👋Continue reading on Medium »
Read more...
How an Unsanitized PDF Export Engine Led to Local File Inclusion and a $14,000 Bounty

When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium »
Read more...
PEASS-ng v20260829-c348cd6e

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Read more...
When auditing modern enterprise applications, reporting features like “Export to PDF,” “Generate Invoice,” or “Download Summary” are…Continue reading on Medium » (https://medium.com/@t4nv1/how-an-unsanitized-pdf-export-engine-led-to-local-file-inclusion-and-a-14-000-bounty-971c19603d94?source=rss------bug_bounty-5)
One parameter & Two IDORs

بسم الله الرحمن الرحيم, اللهم صلي وسلم وزد وبارك على سيدنا محمد وعلى آله وصحبه وسلمContinue reading on Medium »
Read more...
From Zero Credentials to Super Admin: An SSO Authentication Bypass on AT&T

The Door Was Already OpenContinue reading on Medium »
Read more...
The Dark Reality of Mod APKs on Android | Hidden Security Risks

Modified Android applications — commonly called Mod APKs — are everywhere.Continue reading on Medium »
Read more...
The Bid Button Was Disabled — So I Sent the Bid Anyway

How a client-side payment check on a livestream auction platform turned into a High-severity business logic bug (CVSS 8.5) — found on a…Continue reading on Medium »
Read more...
Buyer Verification Gate Not Enforced Server-Side: Unverified Buyer Wins Live Auction (High)

Target: Private bug bounty program — livestream auction platform (anonymized) Severity: High Vulnerability class: Improper Authorization /…Continue reading on Medium »
Read more...
opencanary
https://kitploit.com/en/tools/github/thinkst/opencanary

Low-resource honeypot that emulates common network services to detect post-breach attacker activity, with extensible protocol modules and configurable alerting.
PEASS-ng v20260829-c348cd6e
https://kitploit.com/en/posts/github-peass-ng-peass-ng-20260829-c348cd6e

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Microsoft-Sentinel-SecOps
https://kitploit.com/en/tools/github/eshlomo1/microsoft-sentinel-secops

SOC operations content for Microsoft Sentinel, including hunting queries, incident response playbooks, and security event analysis for Azure cloud environments.