⤷ Title: HTB WEB FUZZING
════════════════════════
𐀪 Author: Darshil Ashvinbhai Thummar
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:06:09 GMT
════════════════════════
⌗ Tags: #htb #hacking #htb_academy #hackthebox_writeup
════════════════════════
𐀪 Author: Darshil Ashvinbhai Thummar
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:06:09 GMT
════════════════════════
⌗ Tags: #htb #hacking #htb_academy #hackthebox_writeup
Medium
HTB WEB FUZZING
Summary
⤷ Title: I Scored 100% on OSCP After 6 Months of Hell (Here’s Everything I Learned)
════════════════════════
𐀪 Author: Abdullah Javeed
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:31:48 GMT
════════════════════════
⌗ Tags: #ethical_hacking #oscp #programming #cybersecurity #penetration_testing
════════════════════════
𐀪 Author: Abdullah Javeed
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:31:48 GMT
════════════════════════
⌗ Tags: #ethical_hacking #oscp #programming #cybersecurity #penetration_testing
Medium
I Scored 100% on OSCP After 6 Months of Hell (Here’s Everything I Learned)
A complete breakdown of my strategy, lab methodology, and the mindset shift required to conquer the PWK-200
⤷ Title: Pentest to CVE Research
════════════════════════
𐀪 Author: Edward Amarh
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:02:54 GMT
════════════════════════
⌗ Tags: #cve #penetration_testing #offensive_security #open_source #red_team
════════════════════════
𐀪 Author: Edward Amarh
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:02:54 GMT
════════════════════════
⌗ Tags: #cve #penetration_testing #offensive_security #open_source #red_team
Medium
Pentest to CVE Research
Overview
⤷ Title: Getting Started with Burp Suite for API Security Testing
════════════════════════
𐀪 Author: Joyatee Datta
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:01:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #api_security_testing #burpsuite #api_security
════════════════════════
𐀪 Author: Joyatee Datta
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:01:18 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #api_security_testing #burpsuite #api_security
Medium
Getting Started with Burp Suite for API Security Testing
As I began exploring API security, one thing quickly became clear: APIs now power nearly 83% of all internet traffic, quietly driving…
⤷ Title: Advent of Cyber 25' Day 5 — Santa’s Little IDOR
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:52:12 GMT
════════════════════════
⌗ Tags: #tryhackme #idor_vulnerability #tryhackme_writeup #idor #advent_of_cyber_2025
════════════════════════
𐀪 Author: Steven Estill Jr
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:52:12 GMT
════════════════════════
⌗ Tags: #tryhackme #idor_vulnerability #tryhackme_writeup #idor #advent_of_cyber_2025
Medium
Advent of Cyber 25' Day 5 — Santa’s Little IDOR
Essentially, this is saying that a web app, will have a database. The database holds the information for the web app. So for example, if…
⤷ Title: Understanding Broken Object Level Authorisation (BOLA)
════════════════════════
𐀪 Author: Sharon Nicole Dube
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:15:43 GMT
════════════════════════
⌗ Tags: #api_security_testing #owasp_top_10 #api #tryhackme #api1
════════════════════════
𐀪 Author: Sharon Nicole Dube
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:15:43 GMT
════════════════════════
⌗ Tags: #api_security_testing #owasp_top_10 #api #tryhackme #api1
Medium
Understanding Broken Object Level Authorisation (BOLA)
OWASP publishes the API Security Top 10 list, which highlights the most critical API vulnerabilities. In the latest edition, Broken Object…
⤷ Title: Advent of Cyber 2025 - Day 17: CyberChef - Hoperation Save McSkidy
════════════════════════
𐀪 Author: Akshat Patel
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 17:27:12 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme_walkthrough #tryhackme #password_management #passwords
════════════════════════
𐀪 Author: Akshat Patel
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 17:27:12 GMT
════════════════════════
⌗ Tags: #advent_of_cyber_2025 #tryhackme_walkthrough #tryhackme #password_management #passwords
Medium
Advent of Cyber 2025 - Day 17: CyberChef & Hoperation Save McSkidy
I’ve always thought CyberChef had one of the coolest nicknames in security: the Cyber Swiss Army Knife. Day 17 of Advent of Cyber 2025…
⤷ Title: API Keys, Tokens, and Secrets: How They Leak and How Developers Can Avoid It
════════════════════════
𐀪 Author: Anishamudani
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:38:20 GMT
════════════════════════
⌗ Tags: #api_token #api_security #config_json #token_mismanagement
════════════════════════
𐀪 Author: Anishamudani
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 21:38:20 GMT
════════════════════════
⌗ Tags: #api_token #api_security #config_json #token_mismanagement
Medium
API Keys, Tokens, and Secrets: How They Leak and How Developers Can Avoid It
Welcome back to NINI’S SIMPLE GUIDE TO API SECURITY.
⤷ Title: How I Performed Basic API Security Tests Using
Postman (Beginner Edition)
════════════════════════
𐀪 Author: Stella Obatoye
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:37:05 GMT
════════════════════════
⌗ Tags: #api_security_testing #postman #authentication #api_pentesting #api_security
Postman (Beginner Edition)
════════════════════════
𐀪 Author: Stella Obatoye
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:37:05 GMT
════════════════════════
⌗ Tags: #api_security_testing #postman #authentication #api_pentesting #api_security
Medium
How I Performed Basic API Security Tests Using
Postman (Beginner Edition)
Postman (Beginner Edition)
In this article, I’ll be trying some security checks on the Vulnerable Application in Postman.
⤷ Title: Sharing my SSRF (Server-Side Request Forgery) blog
════════════════════════
𐀪 Author: Priyesh Pahade
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:53:49 GMT
════════════════════════
⌗ Tags: #ssrf_bug #ssrf #web_application_security #ssrf_attack #ssrf_vulnerability
════════════════════════
𐀪 Author: Priyesh Pahade
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 20:53:49 GMT
════════════════════════
⌗ Tags: #ssrf_bug #ssrf #web_application_security #ssrf_attack #ssrf_vulnerability
Medium
🚀 Sharing my SSRF (Server-Side Request Forgery) blog
I’ve been working on understanding SSRF deeply — not just finding it, but understanding why it’s dangerous, how it leads to real impact…
⤷ Title: The Cybersecurity Side of AI Crypto Bots: What Users Need to Know
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:19:27 +0000
════════════════════════
⌗ Tags: #Cryptocurrency #AI #Artificial Intelligence #Crypto #Cryptocurency #Cybersecurity #Technology
════════════════════════
𐀪 Author: Owais Sultan
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:19:27 +0000
════════════════════════
⌗ Tags: #Cryptocurrency #AI #Artificial Intelligence #Crypto #Cryptocurency #Cybersecurity #Technology
Hackread
The Cybersecurity Side of AI Crypto Bots: What Users Need to Know
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #osint #cybersecurity_writeups
════════════════════════
𐀪 Author: Krish_cyber
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:56 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty_writeup #bug_bounty #osint #cybersecurity_writeups
Medium
Business Logic Bugs That Paid Big: How “Working as Intended” Broke Million-Dollar Systems 🧠💰
After years in bug bounty, here’s something most beginners don’t realize:
⤷ Title: $2,500 Bounty: How a Simple Race Condition Let Me Get Paid Multiple Times by HackerOne
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:31 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #cybersecurity #tech #bug_bounty
════════════════════════
𐀪 Author: Monika sharma
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:40:31 GMT
════════════════════════
⌗ Tags: #technology #penetration_testing #cybersecurity #tech #bug_bounty
Medium
$2,500 Bounty: How a Simple Race Condition Let Me Get Paid Multiple Times by HackerOne
When Clicking “Confirm Retest” Faster Than the Server Could Think Turned Into Free Money
⤷ Title: What is API Security and Why Should Everyday People Care About it?
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:46:34 GMT
════════════════════════
⌗ Tags: #application #api_security #application_security #api
════════════════════════
𐀪 Author: Veronica Peter
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:46:34 GMT
════════════════════════
⌗ Tags: #application #api_security #application_security #api
Medium
What is API Security and Why Should Everyday People Care About it?
Ever wondered what really happens behind the scenes when you tap “Sign in with Google” and, in seconds, the app knows who you are, without…
⤷ Title: Lab: 2FA broken logic
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:23:05 GMT
════════════════════════
⌗ Tags: #pentesting #ctf #hacking #medium #ctf_writeup
════════════════════════
𐀪 Author: Songül Kızılay Özügürler
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:23:05 GMT
════════════════════════
⌗ Tags: #pentesting #ctf #hacking #medium #ctf_writeup
Medium
Lab: 2FA broken logic
Bu lab’da, iki faktörlü kimlik doğrulama (2FA) mekanizmasının hatalı bir mantıkla uygulanması nedeniyle nasıl bypass edilebildiğini…
⤷ Title: SNORT WALKTHROUGH (TRY HACK ME )
════════════════════════
𐀪 Author: The Commoness
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:42:31 GMT
════════════════════════
⌗ Tags: #incident_response #tryhackme_walkthrough #tryhackme_snort #tryhackme #tryhackme_writeup
════════════════════════
𐀪 Author: The Commoness
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:42:31 GMT
════════════════════════
⌗ Tags: #incident_response #tryhackme_walkthrough #tryhackme_snort #tryhackme #tryhackme_writeup
Medium
SNORT WALKTHROUGH (TRY HACK ME )
https://tryhackme.com/room/snort
TASK-2
TASK-2
⤷ Title: HackTheBox — File Uploads-Whitelist Filters
════════════════════════
𐀪 Author: 415141
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:27:18 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_security #file_upload #hackthebox
════════════════════════
𐀪 Author: 415141
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:27:18 GMT
════════════════════════
⌗ Tags: #ethical_hacking #cybersecurity #web_security #file_upload #hackthebox
Medium
HackTheBox — File Uploads-Whitelist Filters
This module covers whitelist filters, which only allow specific file types. It is possible to bypass with double extensions…
⤷ Title: “Script” Engellemek Yetmez: Reflected XSS Gerçeği
════════════════════════
𐀪 Author: Melih Yılmaz
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:09:33 GMT
════════════════════════
⌗ Tags: #xss_attack #web_security #cybersecurity #web_application_security #ethical_hacking
════════════════════════
𐀪 Author: Melih Yılmaz
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:09:33 GMT
════════════════════════
⌗ Tags: #xss_attack #web_security #cybersecurity #web_application_security #ethical_hacking
Medium
“Script” Engellemek Yetmez: Reflected XSS Gerçeği
XSS saldırıları, web uygulamalarında sıkça karşılaşılan ve temelde bir enjeksiyon zafiyeti olarak değerlendirilen güvenlik açıklarıdır. Bu…
⤷ Title: Vulnhub Deathnote: 1 Walkthrough
════════════════════════
𐀪 Author: Luke Gearty
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:06:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerable_machine #ethical_hacking #hack_to_learn #vulnhub_walkthrough
════════════════════════
𐀪 Author: Luke Gearty
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:06:07 GMT
════════════════════════
⌗ Tags: #cybersecurity #vulnerable_machine #ethical_hacking #hack_to_learn #vulnhub_walkthrough
Medium
Vulnhub Deathnote: 1 Walkthrough
“Deathnote: 1” is a vulnerable machine on Vulnhub, rated as easy. This post will be a walkthrough of hacking the machine and escalating…
⤷ Title: The Invisible Glue of the Internet: What Is API Security and Why It Matters to You
════════════════════════
𐀪 Author: Ngobirifalyne
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:51:32 GMT
════════════════════════
⌗ Tags: #api_introduction #api_security #api #getting_started_with_api #api_usage
════════════════════════
𐀪 Author: Ngobirifalyne
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:51:32 GMT
════════════════════════
⌗ Tags: #api_introduction #api_security #api #getting_started_with_api #api_usage
Medium
The Invisible Glue of the Internet: What Is API Security and Why It Matters to You
Imagine you are sitting in a restaurant. You are the customer, and the kitchen is the system that prepares your food. But how does the…
⤷ Title: Solving OIDC Integration Challenges with Kong API Gateway and Angular UI
════════════════════════
𐀪 Author: Amanuel Eshete
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:48:41 GMT
════════════════════════
⌗ Tags: #kong_api_gateway #api_security #openid_connect #microservices #angular
════════════════════════
𐀪 Author: Amanuel Eshete
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 22:48:41 GMT
════════════════════════
⌗ Tags: #kong_api_gateway #api_security #openid_connect #microservices #angular
Medium
Solving OIDC Integration Challenges with Kong API Gateway and Angular UI
Integrating OpenID Connect (OIDC) into a microservices platform can feel straightforward — until subtle issues put your UI, APIs, and…