Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
XSS Vulnerability report writing 301 (redirect) to Bounty$$$

Overview: The purpose of this report is to document cross-site scripting (XSS) vulnerability discovered in the web application…Continue reading on Medium »
Read more...
How a Simple IDOR Vulnerability Allowed Retrieving Any User’s PII Information

Dear readers,Continue reading on Medium »
Read more...
Local File Inclusion Vulnerability in Email Attachment Feature

Dear readers,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Learn Hackings

there are many legitimate ways to learn and practice ethical hacking skills. Here are a few suggestions

Continue reading on Medium »
Change Any User Data on NFT Marketplace crosea.io

Kali ini saya mau share bagaimana cara saya menemukan sebuah bug pada NFT Marketplace crosea.io. Pertama selalu saya tegaskan pekerjaan…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
JWT Authentication

I am trying to get more information about JWT Authentication in Node.js. I am having trouble finding the vulnerabilities, as I have not yet had a ton of experience with JSON or JavaScript, but a link a friend sent me caught my eye. Of course, I have googled, but it still hasn't clicked in my mind. Why/how is it vulnerable? Example: Say I have credentials to a site that uses JWT Auth and sets the cookie as the JWT. Is there an inherent issue with this? My first guess would be MITM but I'm not sure if that applies.

Again, I am fairly new to this, so any help would be appreciated!

submitted by /u/USIntrepid
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Easy Way To PrintNightmare CVE-2021–34527 PoC

https://cdn-images-1.medium.com/max/1456/0*Bq6VyRmYQXZERE8y
The print spooler service is started as the system account which is the highest account in windows that you can take over. You will trick…

Continue reading on Medium »