New Writeup❗️
Date: Thu, 08 Jul 2021 18:15:56 GMT
Title: the pen is mightier than the sword. (in bug hunting)
Link: https://medium.com/p/11166beada06
Date: Thu, 08 Jul 2021 18:15:56 GMT
Title: the pen is mightier than the sword. (in bug hunting)
Link: https://medium.com/p/11166beada06
Medium
the pen is mightier than the sword. (in bug hunting)
Hey folks, This is Captain_hook from BC. actually, I started my career about 1 and a half years ago, and I decided to share some things…
New Writeup❗️
Date: Fri, 24 Jun 2022 13:38:46 GMT
Title: Writing your own Burpsuite Extensions: Complete Guide
Link: https://medium.com/p/cb7aba4dbceb
Date: Fri, 24 Jun 2022 13:38:46 GMT
Title: Writing your own Burpsuite Extensions: Complete Guide
Link: https://medium.com/p/cb7aba4dbceb
Medium
Writing your own Burpsuite Extensions: Complete Guide
Recently I had to create some extensions for Burpsuite. I tried finding resources that could help me but couldn’t find much. Most of them…
New Writeup❗️
Date: Sat, 20 Nov 2021 11:00:47 GMT
Title: Peeping through a Web-Socket
Link: https://medium.com/p/936ed55a2c31
Date: Sat, 20 Nov 2021 11:00:47 GMT
Title: Peeping through a Web-Socket
Link: https://medium.com/p/936ed55a2c31
Medium
Peeping through a Web-Socket
Recently, I had found a bug related to web sockets through which I was able to view all the messages being sent to the victim user.
New Writeup❗️
Date: Wed, 26 May 2021 12:51:44 GMT
Title: How I hacked a Target again and again…
Link: https://medium.com/p/6db2e462221f
Date: Wed, 26 May 2021 12:51:44 GMT
Title: How I hacked a Target again and again…
Link: https://medium.com/p/6db2e462221f
Medium
How I hacked a Target again and again…
This all started with a when I was hunting on a private program; I found a few subdomains of almost similar UI and requests but different…
New Writeup❗️
Date: Sat, 06 Mar 2021 17:36:43 GMT
Title: Exploiting a hidden and forgotten Bug
Link: https://medium.com/p/49ce7ad4de39
Date: Sat, 06 Mar 2021 17:36:43 GMT
Title: Exploiting a hidden and forgotten Bug
Link: https://medium.com/p/49ce7ad4de39
Medium
Exploiting a hidden and forgotten Bug
This writeup is about a bug that existed in HTML to PDF generation functionality in a program.
New Writeup❗️
Date: Fri, 26 Feb 2021 18:00:47 GMT
Title: The story of my First Bug
Link: https://medium.com/p/573c4f628bc0
Date: Fri, 26 Feb 2021 18:00:47 GMT
Title: The story of my First Bug
Link: https://medium.com/p/573c4f628bc0
Medium
The story of my First Bug
Just like other newbies, I had been practising on portswigger academy, feeding on writeups day in and day out waiting for my first valid…
New Writeup❗️
Date: Sun, 22 Nov 2020 07:31:59 GMT
Title: Escalating XSS to Account Takeover
Link: https://medium.com/p/ffde08624937
Date: Sun, 22 Nov 2020 07:31:59 GMT
Title: Escalating XSS to Account Takeover
Link: https://medium.com/p/ffde08624937
Medium
Escalating XSS to Account Takeover
Escalating a Reflected XSS to Account Takeover
New Writeup❗️
Date: Tue, 23 Aug 2022 19:30:34 GMT
Title: Making small things BIG
Link: https://medium.com/p/972cf772bb5a
Date: Tue, 23 Aug 2022 19:30:34 GMT
Title: Making small things BIG
Link: https://medium.com/p/972cf772bb5a
Medium
Making small things BIG
Hacking Salesforce sites.
New Writeup❗️
Date: Tue, 23 Aug 2022 12:30:50 GMT
Title: Finding Hidden Gems with Nuclei Templates!
Link: https://medium.com/p/b3125950a5cd
Date: Tue, 23 Aug 2022 12:30:50 GMT
Title: Finding Hidden Gems with Nuclei Templates!
Link: https://medium.com/p/b3125950a5cd
Medium
Finding Hidden Gems with Nuclei Templates!
Lately, I have been thinking about automation.
New Writeup❗️
Date: Fri, 19 Mar 2021 00:13:48 GMT
Title: How to Harpon Big Blue!
Link: https://medium.com/p/c163722638d8
Date: Fri, 19 Mar 2021 00:13:48 GMT
Title: How to Harpon Big Blue!
Link: https://medium.com/p/c163722638d8
Medium
How to Harpon Big Blue!
A story about creating backdoors in IBM’s Websphere Portal! This is a feature I’m told…
New Writeup❗️
Date: Thu, 11 Feb 2021 19:16:04 GMT
Title: The CVE That Will Never Die!
Link: https://medium.com/p/86149b450840
Date: Thu, 11 Feb 2021 19:16:04 GMT
Title: The CVE That Will Never Die!
Link: https://medium.com/p/86149b450840
Medium
The CVE That Will Never Die!
While exploring targets lately on Synack and HackerOne, I keep coming across this old CVE, it’s CVE-2016–0957. For those that don’t recall…
New Writeup❗️
Date: Tue, 14 Dec 2021 16:22:06 GMT
Title: My [CVE-2021–45043] LFI Write-up
Link: https://medium.com/p/441dad30dd7f
Date: Tue, 14 Dec 2021 16:22:06 GMT
Title: My [CVE-2021–45043] LFI Write-up
Link: https://medium.com/p/441dad30dd7f
Medium
My [CVE-2021–45043] LFI Write-up
Hey Hackers & Hunters,
New Writeup❗️
Date: Fri, 03 Dec 2021 15:32:50 GMT
Title: My mindset while hunting on Yandex and my SSRF
Link: https://medium.com/p/e19af20ed4d
Date: Fri, 03 Dec 2021 15:32:50 GMT
Title: My mindset while hunting on Yandex and my SSRF
Link: https://medium.com/p/e19af20ed4d
Medium
My mindset while hunting on Yandex and my SSRF
Hey hunters!
New Writeup❗️
Date: Tue, 30 Nov 2021 18:22:46 GMT
Title: How i was able to bypass Cloudflare WAF for SQLi payload
Link: https://medium.com/p/b9e7a4260026
Date: Tue, 30 Nov 2021 18:22:46 GMT
Title: How i was able to bypass Cloudflare WAF for SQLi payload
Link: https://medium.com/p/b9e7a4260026
Medium
How i was able to bypass Cloudflare WAF for SQLi payload
Bypassing Cloudflare for achieving SQL Injection
🗿1
New Writeup❗️
Date: Tue, 30 Nov 2021 17:22:13 GMT
Title: My write-up in hacking IBM’s administration panel and getting SQLi on it
Link: https://medium.com/p/51404c7bee27
Date: Tue, 30 Nov 2021 17:22:13 GMT
Title: My write-up in hacking IBM’s administration panel and getting SQLi on it
Link: https://medium.com/p/51404c7bee27
Medium
My write-up in hacking IBM’s administration panel and getting SQLi on it
Hi hackers and hunters!
New Writeup❗️
Date: Sat, 04 Sep 2021 12:08:16 GMT
Title: How i hacked BBC mail servers
Link: https://medium.com/p/e61bb6faed2d
Date: Sat, 04 Sep 2021 12:08:16 GMT
Title: How i hacked BBC mail servers
Link: https://medium.com/p/e61bb6faed2d
Medium
How i hacked BBC mail servers
Walk-through in hacking BBC mail servers through chained vulnerability
New Writeup❗️
Date: Sun, 27 Dec 2020 00:31:03 GMT
Title: Cyber Talents New Year CTF — Note Checker SQLi Challenge
Link: https://medium.com/p/7427328a455
Date: Sun, 27 Dec 2020 00:31:03 GMT
Title: Cyber Talents New Year CTF — Note Checker SQLi Challenge
Link: https://medium.com/p/7427328a455
Medium
Cyber Talents New Year CTF — Note Checker SQLi Challenge
Hey Hunters !!, This cyber talents ctf was very crazy and excited specially this challenge -Note Checker- it was semi-hard but also very…
New Writeup❗️
Date: Sun, 15 Nov 2020 21:33:28 GMT
Title: RCE via Server-Side Template Injection
Link: https://medium.com/p/ad46f8e0c2ae
Date: Sun, 15 Nov 2020 21:33:28 GMT
Title: RCE via Server-Side Template Injection
Link: https://medium.com/p/ad46f8e0c2ae
Medium
RCE via Server-Side Template Injection
In this write-up, we’ll see how I identified a remote code execution vulnerability and bypassed the Akamai WAF rule(s). While I was doing…
New Writeup❗️
Date: Tue, 10 Nov 2020 05:29:18 GMT
Title: BugPoC XSS Challenge- Wacky
Link: https://medium.com/p/e64255b543f2
Date: Tue, 10 Nov 2020 05:29:18 GMT
Title: BugPoC XSS Challenge- Wacky
Link: https://medium.com/p/e64255b543f2
Medium
BugPoC XSS Challenge- Wacky
Introduction
New Writeup❗️
Date: Sat, 29 Jan 2022 09:52:24 GMT
Title: Eliminating Authorization Vulnerabilities with Dacquiri
Link: https://medium.com/p/882b38146f36
Date: Sat, 29 Jan 2022 09:52:24 GMT
Title: Eliminating Authorization Vulnerabilities with Dacquiri
Link: https://medium.com/p/882b38146f36
Medium
Eliminating Authorization Vulnerabilities with Dacquiri
Dacquiri identifies and eliminates authorization vulnerabilities by turning them into compiler errors.