⤷ Title: How a Tampered role_id Gave Me Permanent, Invisible Control Over Other Users’ Organizations
════════════════════════
𐀪 Author: HASG
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:12:05 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #information_security #cybersecuirty #web_security
════════════════════════
𐀪 Author: HASG
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 06:12:05 GMT
════════════════════════
⌗ Tags: #penetration_testing #bug_bounty #information_security #cybersecuirty #web_security
Medium
How a Tampered role_id Gave Me Permanent, Invisible Control Over Other Users’ Organizations
السلام عليكم ورحمة الله وبركاته.
⤷ Title: Hunting IDOR & BOLA in REST APIs: A Practical Authorization Testing Methodology
════════════════════════
𐀪 Author: Ishant
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 11:08:37 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #api_security
════════════════════════
𐀪 Author: Ishant
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 11:08:37 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #api_security
Medium
Hunting IDOR & BOLA in REST APIs: A Practical Authorization Testing Methodology
A method for detecting broken authorization in REST APIs is shown using the OWASP crAPI.
⤷ Title: Bypassing Keyword and Character Filters to Achieve Reflected XSS
════════════════════════
𐀪 Author: Bahmed Boumriga
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:26:56 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #xss_attack #web_security #cybersecurity
════════════════════════
𐀪 Author: Bahmed Boumriga
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:26:56 GMT
════════════════════════
⌗ Tags: #bug_bounty #penetration_testing #xss_attack #web_security #cybersecurity
Medium
Bypassing Keyword and Character Filters to Achieve Reflected XSS
A Bug Bounty Writeup | HackerOne Report
⤷ Title: Ağ Dünyasının Görünmez Mimarisini Anlamak: Kritik Protokoller, Hangi Katmanda Ne Çalışır?
════════════════════════
𐀪 Author: Aslıhan Zeynep Koç
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #network_security #networking
════════════════════════
𐀪 Author: Aslıhan Zeynep Koç
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #application_security #cybersecurity #web_security #network_security #networking
⤷ Title: Include (THM) — From “Guest” to Root Flag: A Chain of Small Mistakes
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:02:37 GMT
════════════════════════
⌗ Tags: #include #ctf #idor #tryhackme #web_security
════════════════════════
𐀪 Author: Dr.Vixar
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 15:02:37 GMT
════════════════════════
⌗ Tags: #include #ctf #idor #tryhackme #web_security
Medium
Include (THM) — From “Guest” to Root Flag: A Chain of Small Mistakes
A web exploitation writeup covering IDOR, forced authentication bypass, base64-leaked credentials, Local File Inclusion, and SSH password…
⤷ Title: Hacker Holidays Day 8: Towel on the Sunbed
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:53:35 GMT
════════════════════════
⌗ Tags: #bug_bounty #web_security #cybersecurity #infosec #ctf
Medium
Hacker Holidays Day 8: Towel on the Sunbed
The setup
⤷ Title: Hacker Holidays Day 7: Following Someone Else’s Footprints to Root
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:21 GMT
════════════════════════
⌗ Tags: #web_security #nodejs #ctf #penetration_testing #cybersecurity
════════════════════════
𐀪 Author: Devyaniitware
════════════════════════
ⴵ Time: Thu, 13 Aug 2026 17:51:21 GMT
════════════════════════
⌗ Tags: #web_security #nodejs #ctf #penetration_testing #cybersecurity
Medium
Hacker Holidays Day 7: Following Someone Else’s Footprints to Root
The setup
⤷ Title: How a Single HTTP Redirect Bypassed SSRF Filters on 4 Programs Over 8 Years
════════════════════════
𐀪 Author: Raj Namdev
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 02:31:01 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #ethical_hacking #ssrf #bug_bounty
════════════════════════
𐀪 Author: Raj Namdev
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 02:31:01 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #ethical_hacking #ssrf #bug_bounty
Medium
How a Single HTTP Redirect Bypassed SSRF Filters on 4 Programs Over 8 Years
30-Second Version: One SSRF bypass technique — a single HTTP redirect — worked against Infogram (2017), Slack (2018), Bitwarden (2020), and…
⤷ Title: Server-Side Template Injection (SSTI) to Remote Code Execution (RCE): A Visual Guide for Pentesters…
════════════════════════
𐀪 Author: Kondibajogdand
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 05:41:00 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #web_security #ethical_hacking #web_application_security #security
════════════════════════
𐀪 Author: Kondibajogdand
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 05:41:00 GMT
════════════════════════
⌗ Tags: #web_penetration_testing #web_security #ethical_hacking #web_application_security #security
Medium
Server-Side Template Injection (SSTI) to Remote Code Execution (RCE): A Visual Guide for Pentesters and Developers
🎬 The Scene: A “Harmless” Name Field
⤷ Title: I Thought I Understood HTTP — Then I Opened Burp Suite
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 13:59:28 GMT
════════════════════════
⌗ Tags: #https #ethical_hacking #web_security #cybersecurity #burpsuite
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 13:59:28 GMT
════════════════════════
⌗ Tags: #https #ethical_hacking #web_security #cybersecurity #burpsuite
Medium
I Thought I Understood HTTP — Then I Opened Burp Suite
A hands-on journey into HTTP requests, responses, headers, cookies, and web application security.