⤷ Title: How I Bypassed Authentication on a Fintech Platform Using a Broken Password Reset Flow (Bug Bounty…
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 19:09:16 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #bug_bounty_writeup #security #cybersecurity
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 19:09:16 GMT
════════════════════════
⌗ Tags: #pentesting #bug_bounty #bug_bounty_writeup #security #cybersecurity
Medium
How I Bypassed Authentication on a Fintech Platform Using a Broken Password Reset Flow (Bug Bounty Writeup)
I almost closed the tab on this program twice.
⤷ Title: IDOR via Comma-Injection: How Concatenating Two IDs Leaked Cross-Tenant PII
════════════════════════
𐀪 Author: s0ufm3l
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 20:14:05 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_tips #pentesting
════════════════════════
𐀪 Author: s0ufm3l
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 20:14:05 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_tips #pentesting
Medium
IDOR via Comma-Injection: How Concatenating Two IDs Leaked Cross-Tenant PII
TL;DR: A permissions endpoint expected a single numeric user ID in one POST parameter. Sending two IDs separated by a comma — victim first…
⤷ Title: Writing Your First PIC Shellcode with Crystal Palace
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:00:10 GMT
════════════════════════
⌗ Tags: #red_team #malware #hacking #pentesting #infosec
════════════════════════
𐀪 Author: S12 - 0x12Dark Development
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 21:00:10 GMT
════════════════════════
⌗ Tags: #red_team #malware #hacking #pentesting #infosec
Medium
Writing Your First PIC Shellcode with Crystal Palace
The previous post covered what Crystal Palace is and why it exists. This one is hands-on. We’re building two PICOs from scratch, a…
⤷ Title: When Strong Password Hashing Isn’t Enough: Chaining SQL Injection into Account Takeover
════════════════════════
𐀪 Author: Hossein Zarei
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:31:09 GMT
════════════════════════
⌗ Tags: #account_takeover #cybersecurity #sql_injection #pentesting #ethical_hacking
════════════════════════
𐀪 Author: Hossein Zarei
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:31:09 GMT
════════════════════════
⌗ Tags: #account_takeover #cybersecurity #sql_injection #pentesting #ethical_hacking
Medium
When Strong Password Hashing Isn’t Enough: Chaining SQL Injection into Account Takeover
Hello everyone 👋
⤷ Title: The SSRF That Wasn’t Supposed to Work Twice
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 20:16:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #pentesting #bug_bounty_writeup #security
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 20:16:01 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #pentesting #bug_bounty_writeup #security
Medium
The SSRF That Wasn’t Supposed to Work Twice
This one has a twist in it, so bear with the setup. The bug wasn’t hard to find. Getting it accepted was the actual fight.
⤷ Title: Apostrophe Has Abolished the Password
════════════════════════
𐀪 Author: Leonardo R Cavalcante
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 03:56:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_app_pentesting #bug_bounty_tips #bug_bounty #pentesting
════════════════════════
𐀪 Author: Leonardo R Cavalcante
════════════════════════
ⴵ Time: Thu, 06 Aug 2026 03:56:15 GMT
════════════════════════
⌗ Tags: #cybersecurity #web_app_pentesting #bug_bounty_tips #bug_bounty #pentesting
Medium
Apostrophe Has Abolished the Password
The password was present.
⤷ Title: The Quiet SQLi Everyone Walks Past (And How to Catch It)
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #pentesting #bug_bounty #infosec
════════════════════════
𐀪 Author: Nitin yadav
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 11:31:01 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #pentesting #bug_bounty #infosec
Medium
The Quiet SQLi Everyone Walks Past (And How to Catch It)
What’s up everyone! Nitin here 👋
⤷ Title: How a $5,000 “Low Severity” Bug Turned Into the Ultimate Admin Trap
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:04:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #pentesting #cybersecurity #penetration_testing #bug_bounty
════════════════════════
𐀪 Author: T4nv1
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 14:04:06 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #pentesting #cybersecurity #penetration_testing #bug_bounty
Medium
How a $5,000 “Low Severity” Bug Turned Into the Ultimate Admin Trap
Every bug hunter knows the unwritten rule of public programs: if a target looks picked clean, you’re usually wasting your time.
⤷ Title: SunsetDecoy Walkthrough | proving Ground machine | Oscp prep
════════════════════════
𐀪 Author: Cybersecurity writeup's
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #pentesting #linux #ethical_hacking #cybersecurity #information_security
════════════════════════
𐀪 Author: Cybersecurity writeup's
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 15:01:03 GMT
════════════════════════
⌗ Tags: #pentesting #linux #ethical_hacking #cybersecurity #information_security
Medium
SunsetDecoy Walkthrough | proving Ground machine | Oscp prep
Sunset: Decoy Walkthrough
⤷ Title: VulnHub — Nezuko Walkthrough | CVE-2019–15107
════════════════════════
𐀪 Author: Maryam Salahli
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 23:27:14 GMT
════════════════════════
⌗ Tags: #nezuko #ctf_writeup #pentesting #vulnhub
════════════════════════
𐀪 Author: Maryam Salahli
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 23:27:14 GMT
════════════════════════
⌗ Tags: #nezuko #ctf_writeup #pentesting #vulnhub
Medium
VulnHub — Nezuko Walkthrough | CVE-2019–15107
Platform: VulnHub Machine: Nezuko Difficulty: Beginner / Intermediate Target IP: 192.168.100.103 Main Vulnerability: CVE-2019–15107