Category: tutorials
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…
How I Manipulated My Rank on the Bugcrowd Platform
In recent years, Bug Bounties have gained significant popularity as a growing number of companies rely on crowdsourcing platforms to identify vulnerabilities within their systems. …
Using Inspect Element to Bypass Security restrictions | Bug Bounty POC
Hey guys so this blog post is how I was able to Bypass Security restrictions by using inspect element and use Paid Features.
Getting Started in Android Apps Pen-testing (Part-1)
Pen-testing android apps require different methodologies than web applications. The difference is that you have to figure out by different methods.
Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC
This blog post is about static analysis of Android App & due to insecure storage of SMS API credentials I was able to Takeover the SMS API.
Exploiting Insecure Firebase Database!
this blog post is about Exploiting Insecure Firebase Databases, due to Improper set security rules one can write data to the database in certain conditions here’s a Short POC tutor…
Hunting Insecure Direct Object Reference Vulnerabilities for Fun and Profit (PART-1)
This is my first Blog post and i am starting with IDOR Vulnerability. In this Post you will know about many endpoints to test IDOR vulnerability! Hope you will like it.
KNOXSS for Dummies! A new Detailed Guide to use KNOXSS Pro in real world
Hello to all my brothers and friends.
My Guide to Basic Recon? | Bug Bounties + Recon | Amazing Love story.
The Post describe basic steps i follow before starting actual hunt for bugs in a bug bounty program, how i map out the target and which tools to use.
Accessing Localhost via Vhost | VIRTUAL HOST ENUMERATION | BugBounty POC
The Blog post is about what are Virtual Host, how U can Enumerate them and get access to the vulnerable system, including POC of resent BugBounty Report.
What is Subdomain Hijack/Takeover Vulnerability? How to Identify? & Exploit It?
The post explains the basic of subdomain takeover vulnerability, how to identify and exploit the issue, post contains 5 diff services step to step guide.







