Tag: tutorials
Purple Teaming: What Not to Do in OT & IoT Testing to Avoid Halting the Factory or Sinking the Oil Rig
Testing operational and IoT systems is no easy feat, especially when the stakes involve halting a factory or sinking an oil rig. Every one of us who has embarked on the journey to …
Finding Hidden Threats: How I Found Leaked AWS Credentials in an Android App API Using DAST
Found a critical vulnerability involving leaked AWS credentials within an Android App API during a bug bounty hunt. by utilizing Dynamic Application Security Testing (DAST) and the…
How I Manipulated My Rank on the Bugcrowd Platform
In recent years, Bug Bounties have gained significant popularity as a growing number of companies rely on crowdsourcing platforms to identify vulnerabilities within their systems. …
Hacking Subscription Plans for free service.
The blog post describes how I was able to bypass subscription plans to get access to paid services for free.
Using Inspect Element to Bypass Security restrictions | Bug Bounty POC
Hey guys so this blog post is how I was able to Bypass Security restrictions by using inspect element and use Paid Features.
Hacking SMS API Service Provider of a Company |Android App Static Security Analysis | Bug Bounty POC
This blog post is about static analysis of Android App & due to insecure storage of SMS API credentials I was able to Takeover the SMS API.
Exploiting Insecure Firebase Database!
this blog post is about Exploiting Insecure Firebase Databases, due to Improper set security rules one can write data to the database in certain conditions here’s a Short POC tutor…
KNOXSS for Dummies! A new Detailed Guide to use KNOXSS Pro in real world
Hello to all my brothers and friends.
What is Subdomain Hijack/Takeover Vulnerability? How to Identify? & Exploit It?
The post explains the basic of subdomain takeover vulnerability, how to identify and exploit the issue, post contains 5 diff services step to step guide.






