⤷ Title: One-Click Account Vulnerability: How I Discovered a Dangerous Authentication Flaw in a Global…
════════════════════════
𐀪 Author: Elie Attieh
════════════════════════
ⴵ Time: Fri, 27 Jun 2025 10:44:05 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #cybersecurity #bug_bounty_writeup #bug_bounty
════════════════════════
𐀪 Author: Elie Attieh
════════════════════════
ⴵ Time: Fri, 27 Jun 2025 10:44:05 GMT
════════════════════════
⌗ Tags: #hacking #pentesting #cybersecurity #bug_bounty_writeup #bug_bounty
Medium
One-Click Account Vulnerability: How I Discovered a Dangerous Authentication Flaw in a Global E-Commerce Giant
💬 Subtitle
⤷ Title: Zero Click Mass Account Takeover on Exchange
════════════════════════
𐀪 Author: Erfan Tavakoli
════════════════════════
ⴵ Time: Thu, 26 Jun 2025 22:35:24 GMT
════════════════════════
⌗ Tags: #account_takeover #exchange #bug_bounty_tips #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Erfan Tavakoli
════════════════════════
ⴵ Time: Thu, 26 Jun 2025 22:35:24 GMT
════════════════════════
⌗ Tags: #account_takeover #exchange #bug_bounty_tips #bug_bounty #bug_bounty_writeup
Medium
Zero Click Mass Account Takeover on Exchange
Hey everyone, I’m Erfan (Maverick). In this write-up, I’m going to show you how I discovered a vulnerability that I’ve named “Zero Click…
⤷ Title: How I Took a Website Completely Offline with a Funky Cache Poisoning Vulnerability (CPDOS)
════════════════════════
𐀪 Author: Erfan Tavakoli
════════════════════════
ⴵ Time: Thu, 26 Jun 2025 22:21:54 GMT
════════════════════════
⌗ Tags: #writeup #penetration_testing #bug_bounty_tips #bug_bounty #bug_bounty_writeup
════════════════════════
𐀪 Author: Erfan Tavakoli
════════════════════════
ⴵ Time: Thu, 26 Jun 2025 22:21:54 GMT
════════════════════════
⌗ Tags: #writeup #penetration_testing #bug_bounty_tips #bug_bounty #bug_bounty_writeup
Medium
How I Took a Website Completely Offline with a Funky Cache Poisoning Vulnerability (CPDOS)
Hey everyone, Erfan here! In this write-up, I want to share a fun story about a cache poisoning vulnerability I found that led to a…
⤷ Title: Broken Access Control via Hardcoded Bearer Token in Public JS File
════════════════════════
𐀪 Author: nooh zidan
════════════════════════
ⴵ Time: Thu, 26 Jun 2025 19:40:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_writeup #api #bug_bounty_tips
════════════════════════
𐀪 Author: nooh zidan
════════════════════════
ⴵ Time: Thu, 26 Jun 2025 19:40:48 GMT
════════════════════════
⌗ Tags: #cybersecurity #bug_bounty #bug_bounty_writeup #api #bug_bounty_tips
Medium
Broken Access Control via Hardcoded Bearer Token in Public JS File 💥
بِسْمِ اللَّـهِ الرَّحْمَٰنِ الرَّحِيمِ، وَالصَّلَاةُ وَالسَّلَامُ عَلَىٰ الْمَبْعُوثِ رَحْمَةً لِلْعَالَمِينَ ﷺ
⤷ Title: CVE-2025–0133 Made Easy — Find Vulnerable Assets in 2 Minutes
════════════════════════
𐀪 Author: LordofHeaven
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 06:45:26 GMT
════════════════════════
⌗ Tags: #fofa #shodan #global_protect #recon
════════════════════════
𐀪 Author: LordofHeaven
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 06:45:26 GMT
════════════════════════
⌗ Tags: #fofa #shodan #global_protect #recon
Medium
💥 CVE-2025–0133 Made Easy — Find Vulnerable Assets in 2 Minutes
You don’t need fancy tools. You just need good eyes and the right search queries. Here’s how I easily find real targets for…
⤷ Title: Bypassing Badge Authentication in an ICS Environment
════════════════════════
𐀪 Author: Stoic_Gang
════════════════════════
ⴵ Time: Fri, 27 Jun 2025 10:49:04 GMT
════════════════════════
⌗ Tags: #scada #recon #node_red #ot_security #tryhackme_walkthrough
════════════════════════
𐀪 Author: Stoic_Gang
════════════════════════
ⴵ Time: Fri, 27 Jun 2025 10:49:04 GMT
════════════════════════
⌗ Tags: #scada #recon #node_red #ot_security #tryhackme_walkthrough
Medium
Bypassing Badge Authentication in an ICS Environment
No credentials, no shell, no brute force, just a browser and a hunch.
This TryHackMe room was a clever twist on classic enumeration: find a…
This TryHackMe room was a clever twist on classic enumeration: find a…
⤷ Title: FOFA Dorking | Part 8
════════════════════════
𐀪 Author: AbhirupKonwar
════════════════════════
ⴵ Time: Tue, 24 Jun 2025 09:29:48 GMT
════════════════════════
⌗ Tags: #pentesting #fofa_dorking #bug_hunting #recon #fofa
════════════════════════
𐀪 Author: AbhirupKonwar
════════════════════════
ⴵ Time: Tue, 24 Jun 2025 09:29:48 GMT
════════════════════════
⌗ Tags: #pentesting #fofa_dorking #bug_hunting #recon #fofa
Medium
FOFA Dorking | Part 8
Finding unauth dashboards using FOFA Search Engine
⤷ Title: Simple manual recon leads to P1 finding and uncovering AWS access and secret keys
════════════════════════
𐀪 Author: Abdalah
════════════════════════
ⴵ Time: Sun, 22 Jun 2025 13:19:55 GMT
════════════════════════
⌗ Tags: #bug_hunting #penetration_testing #bug_bounty_writeup #bug_bounty #recon
════════════════════════
𐀪 Author: Abdalah
════════════════════════
ⴵ Time: Sun, 22 Jun 2025 13:19:55 GMT
════════════════════════
⌗ Tags: #bug_hunting #penetration_testing #bug_bounty_writeup #bug_bounty #recon
Medium
Simple manual recon leads to P1 finding and uncovering AWS access and secret keys
The finding is related to private program on bugcrowd so let us call it target.com
I have previously (about 2 years ago )reported p1 to…
I have previously (about 2 years ago )reported p1 to…
⤷ Title: Websocket response manipulation leads to access admin panel
════════════════════════
𐀪 Author: rood
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 13:45:39 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup
════════════════════════
𐀪 Author: rood
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 13:45:39 GMT
════════════════════════
⌗ Tags: #bug_bounty #bugbounty_writeup
Medium
Websocket response manipulation leads to access admin panel
Introduction
⤷ Title: ️ Day 7/30 My Go-To Browser Extensions for Bug Bounty Hunting & Cybersecurity
════════════════════════
𐀪 Author: Cyphersilhouette
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 12:31:53 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #burpsuite #bug_bounty #hacking #cybersecurity
════════════════════════
𐀪 Author: Cyphersilhouette
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 12:31:53 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #burpsuite #bug_bounty #hacking #cybersecurity
Medium
🛡️ Day 7/30 My Go-To Browser Extensions for Bug Bounty Hunting & Cybersecurity
Whether you’re a seasoned penetration tester or just getting into ethical hacking, using the right browser extensions for cybersecurity can…
⤷ Title: Redirection Gone Wrong: How Trust and the Referer Can Be Weaponized
════════════════════════
𐀪 Author: Isv
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 04:40:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bugbounty_writeup #bug_bounty #open_redirect #bug_bounty_hunter
════════════════════════
𐀪 Author: Isv
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 04:40:57 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #bugbounty_writeup #bug_bounty #open_redirect #bug_bounty_hunter
Medium
Redirection Gone Wrong: How Trust and the Referer Can Be Weaponized
🔐 Sometimes, it’s not the vulnerability itself… but how you chain it.
⤷ Title: 5 Sneaky Ways to Bypass 403 Forbidden Pages | Zuri
════════════════════════
𐀪 Author: Zuri
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 04:31:57 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #hacking_tools #cybersecurity #bypass #bug_bounty_tips
════════════════════════
𐀪 Author: Zuri
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 04:31:57 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #hacking_tools #cybersecurity #bypass #bug_bounty_tips
Medium
🚫 5 Sneaky Ways to Bypass 403 Forbidden Pages | Zuri
“403 Forbidden” — the dreaded message that tells you, “You’re not allowed here.” But what if that wasn’t the end of the road? What if it…
⤷ Title: Weak credentials lead to access to admin panel (Deep Recon) (Arabic)
════════════════════════
𐀪 Author: rood
════════════════════════
ⴵ Time: Wed, 25 Jun 2025 12:42:13 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bug_bounty
════════════════════════
𐀪 Author: rood
════════════════════════
ⴵ Time: Wed, 25 Jun 2025 12:42:13 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #bug_bounty
Medium
Weak credentials lead to access to admin panel (Deep Recon) (Arabic)
بسم الله الرحمن الرحيم
⤷ Title: Business Logic: How I Bypassed Device Login Limits on a Streaming Platform
════════════════════════
𐀪 Author: RAJVEER
════════════════════════
ⴵ Time: Wed, 25 Jun 2025 09:13:25 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #vulnerability #business_logic #cybersecurity #infosec
════════════════════════
𐀪 Author: RAJVEER
════════════════════════
ⴵ Time: Wed, 25 Jun 2025 09:13:25 GMT
════════════════════════
⌗ Tags: #bugbounty_writeup #vulnerability #business_logic #cybersecurity #infosec
Medium
Business Logic: How I Bypassed Device Login Limits on a Streaming Platform
After my semester exams were over, I decided to select a target and hunt on it.
⤷ Title: Got Deactivated? No Problem — Here’s a 10-Minute Window to Take Control
════════════════════════
𐀪 Author: ValidByAccident
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 10:57:01 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #bug_bounty_tips #vulnerability #sessions
════════════════════════
𐀪 Author: ValidByAccident
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 10:57:01 GMT
════════════════════════
⌗ Tags: #security #bug_bounty #bug_bounty_tips #vulnerability #sessions
Medium
💣 Got Deactivated? No Problem — Here’s a 10-Minute Window to Take Control 😎
You ever get kicked out of somewhere but the door takes 10 minutes to actually lock?
⤷ Title: Level Up Your Web Security Game: Essential Tools for PenTesting & Bug Bounty Hunting
════════════════════════
𐀪 Author: KALYAN CHAVALA
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 10:24:08 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #tools #bug_bounty
════════════════════════
𐀪 Author: KALYAN CHAVALA
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 10:24:08 GMT
════════════════════════
⌗ Tags: #bug_bounty_tips #cybersecurity #tools #bug_bounty
Medium
🛡️Level Up Your Web Security Game: Essential Tools for PenTesting & Bug Bounty Hunting 🔍
Whether you’re diving into bug bounty hunting, preparing for web application penetration testing, or just curious about ethical hacking…
⤷ Title: METABIGOR - OSINT Tool
════════════════════════
𐀪 Author: AbhirupKonwar
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 03:29:44 GMT
════════════════════════
⌗ Tags: #bug_bounty #osint #pentesting #information_security #bug_bounty_tips
════════════════════════
𐀪 Author: AbhirupKonwar
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 03:29:44 GMT
════════════════════════
⌗ Tags: #bug_bounty #osint #pentesting #information_security #bug_bounty_tips
Medium
METABIGOR - OSINT Tool
Recon tool for pentesters and bug bounty hunters
⤷ Title: Wishlist Logic bug: How I Manipulated Item Quantities Without Access
════════════════════════
𐀪 Author: 0xNanashi
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 00:45:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #penetration_testing #business_logic_bug
════════════════════════
𐀪 Author: 0xNanashi
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 00:45:49 GMT
════════════════════════
⌗ Tags: #bug_bounty #bug_bounty_tips #cybersecurity #penetration_testing #business_logic_bug
Medium
Wishlist Logic bug: How I Manipulated Item Quantities Without Access
Hello everyone! I’m Omar Mohamed, also known as 0xnanashi.
In this post, I’ll talk about a Vulnerability I have found that allows me to…
In this post, I’ll talk about a Vulnerability I have found that allows me to…
⤷ Title: FFUF: Effective Fuzzing for Pentesting and Bug Bounty
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 00:02:42 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec #ethical_hacking #penetration_testing
════════════════════════
𐀪 Author: JPablo13
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 00:02:42 GMT
════════════════════════
⌗ Tags: #bug_bounty #cybersecurity #infosec #ethical_hacking #penetration_testing
Medium
FFUF: Effective Fuzzing for Pentesting and Bug Bounty
Discover how FFUF boosts your cybersecurity arsenal. Essential fuzzing guide for pen testers and bug hunters.
⤷ Title: Behind the Race Condition Bug
════════════════════════
𐀪 Author: 0xNanashi
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 21:37:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #race_condition #bug_bounty_tips #business_logic_bug #bug_bounty
════════════════════════
𐀪 Author: 0xNanashi
════════════════════════
ⴵ Time: Sat, 28 Jun 2025 21:37:55 GMT
════════════════════════
⌗ Tags: #bug_bounty_writeup #race_condition #bug_bounty_tips #business_logic_bug #bug_bounty
Medium
Behind the Race Condition Bug
Hello everyone! I’m Omar Mohamed, also known as 0xnanashi.
In this post, I’ll walk you through a sneaky Race Condition vulnerability I…
In this post, I’ll walk you through a sneaky Race Condition vulnerability I…
⤷ Title: The Identity Crisis No One Is Talking About
════════════════════════
𐀪 Author: Prakhar Goel
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 00:24:44 GMT
════════════════════════
⌗ Tags: #identity_management #cybersecurity #technology_strategy #investing #ai_agent
════════════════════════
𐀪 Author: Prakhar Goel
════════════════════════
ⴵ Time: Sun, 29 Jun 2025 00:24:44 GMT
════════════════════════
⌗ Tags: #identity_management #cybersecurity #technology_strategy #investing #ai_agent
Medium
The Identity Crisis No One Is Talking About
Identity access management (IAM) systems today are built for humans: sessions, passwords, MFA prompts, login pages. Agents break that…