Hacking Vidhya
前往频道在 Telegram
We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.
显示更多385
订阅者
+224 小时
+47 天
+2430 天
帖子存档
🪁 Happy Makar Sankranti! ☀️
May this beautiful festival bring new beginnings, positivity, and success into your life.
Just like kites rise high in the sky,
may your dreams soar higher and higher ✨
🌾 Wishing you:
• Bright days ahead
• Sweet moments like tilgul 🍬
• Growth, happiness & good health
Let go of the past, fly high, and shine brighter! 💛
🪁☀️ Happy Makar Sankranti to you and your loved ones! ☀️🪁
New #BugBounty repository:
Title: portpilot
Link: https://github.com/YuriPeixoto25/portpilot
🚀 ADVANCED RATE LIMIT BYPASS TECHNIQUES
🔥 1. Shadow Request Injection
Some servers only rate-limit the first request in a batch.
Send:
POST /login HTTP/1.1
Content-Length: 999
<request1-json>
<request2-json>
<request3-json>
Backend processes ALL.
Rate limiter sees only first.
⚠️ Works on Node, PHP, Laravel, Django.
🔥 2. Parameter Pollution (HPP)
Duplicate parameters:
email=a@gmail.com&email=b@gmail.com
Add parameter :- ?id=1
Some rate limiters read first, server reads second.
Bypass success 🎯
🔥 3. Clone Request to Sub-domains
Some targets share the SAME backend but DIFFERENT WAF rules.
Try:
• api.domain.com
• app.domain.com
• beta.domain.com
• shop.domain.com
• cdn.domain.com
• legacy.domain.com
Many rate limiters are per-subdomain → bypass 100%.
🔥 4. IP Rotation Inside Same Request
Add MULTIPLE IP headers:
X-Forwarded-For: 1.1.1.1, 2.2.2.2, 3.3.3.3
Some rate-limiters pick the last
Some pick the first
Some pick random
Result = Infinite bypass.
🔥 5. Fake Internal IP Address
Try:
X-Forwarded-For: 127.0.0.1
X-Client-IP: 0.0.0.0
X-Real-IP: 10.0.0.5
Servers often TRUST internal networks and SKIP rate limits 😳🔥
🔥 6. 9x Encoding Bypass (Insane)
Encode endpoint 9 times:
/login → / % 25 32 35 ... (nested)
Some rate limiters decode once
Backend decodes fully
→ Full bypass
🔥 7. JSON Structure Mutation
Servers check rate limit only on certain JSON structure.
Try:
Change order:
{"password":"x","email":"y"}
Add junk fields:
{"email":"y","password":"x","aaa":123}
Rate limiter breaks, server still accepts.
🔥 8. Header Case Manipulation
Randomize header casing:
CoNtEnT-TyPe: ApPlIcAtIoN/JsOn
Some rate limiters fail to parse header → bypass.
🔥 9. Chunked Transfer Encoding Attack
Send payload in pieces:
Transfer-Encoding: chunked
Rate limiter fails to read full body.
Server reads normally → unlimited requests.
🔥 10. HTTP Pipelining (LEGACY trick)
Send multiple requests over 1 TCP connection.
Rate limiter sees 1
Server sees MANY.
Works on old Java apps, Golang, Ruby.
🔥 11. WebSocket Upgrade Bypass
Some login / OTP / search endpoints are available via WebSocket.
WebSockets almost NEVER have rate limits.
🔥 12. CDN Desync
Send malformed headers so CDN & origin interpret differently:
X-Forwarded-For:\n8.8.8.8
CDN fails → no rate limit
Origin accepts → request processed
🔥 13. TLS Fingerprint Spoofing
Servers sometimes rate-limit by TLS fingerprint.
Use:
• curl
• httpx
• Go net/http
• mitmproxy
• Python aiohttp
Each produces different fingerprint → bypass.
🔥 14. Multiple Session Token Cycling
Generate new:
• csrf token
• sessionid
• deviceid
• auth cookie
Every few requests.
Some rate limiters bind to cookie instead of IP.
🔥 15. Protocol Switch
Try sending same request in:
• HTTP/1.0
• HTTP/1.1
• HTTP/2
• HTTP/2 Cleartext (H2C)
• HTTP/3 (QUIC)
Rate limiters often only filter 1 protocol type.
🔥 16. Use “OPTIONS” Preflight Abuse
Send:
OPTIONS /login
Some servers incorrectly validate auth & rate limit at OPTIONS.
🔥 17. Cache Poisoning
Poison cache key so rate limiter doesn’t see repeated requests:
/login?cachebuster=1
/cache/login
/login%20
/login#test
Each becomes unique to WAF.
🔥 18. Direct IP Attack (Skipping CDN)
Ping the target:
dig domain.com
Then request:
https://<server-IP>/api/login
CDN rate limits → bypassed.
Origin server → no rate limit.
🔥 19. Out-of-Spec HTTP Attacks
Send slightly broken requests:
• Extra spaces
• Missing CRLF
• Duplicate headers
• Null bytes: %00
Some rate limiters choke; backend still accepts.
🔥 20. TLS Renegotiation Flood
Establish many TLS handshakes → bypass application rate limit completely.
hiring hashtag#internship hashtag#intern
🛡️ Help us secure the future of HealthTech!
Plum is on a mission to make healthcare simple and inclusive for everyone. But to make healthcare accessible, we first have to make it secure.
We are looking for a motivated Cyber Security Intern to join our team in Bangalore! This isn't your typical "coffee-run" internship—you’ll be getting hands-on experience in VAPT, Cloud Security, and GRC (Governance, Risk, and Compliance).
What you’ll be doing:
✅ Conducting vulnerability scans and penetration testing.
✅ Managing third-party risk assessments.
✅ Supporting compliance for ISO 27001, SOC 2, and GDPR.
✅ Monitoring security alerts and cloud security.
Who you are :
✅ Final-year student, recent grad, or early-career professional (up to 1 year of experience).
✅ Familiar with Linux environments, Python/Java, and networking fundamentals.
✅ Passionate about cybersecurity, security frameworks, and data protection.
📍 Location: Whitefield, Bangalore (On-site) ⏳ Duration: 6 Months (Potential for full-time conversion)
⚠️ HOW TO APPLY: Email your resume to: 📧 Aashna Shroff aashna.s@plumhq.com
🔐 *How to Secure Your APIs – A Practical Guide*
APIs are the backbone of modern apps — but without security, they become open doors to attacks. Here's how to lock them down effectively:
---
✅ *1. Use Authentication & Authorization*
- Implement *OAuth2*, *JWT*, or *API keys*
- Enforce *role-based access control (RBAC)*
---
🔐 *2. Validate Inputs Strictly*
- Sanitize user inputs
- Use strong data validation (e.g., Joi, Yup)
- Prevent SQL & NoSQL injection
---
📦 *3. Rate Limiting & Throttling*
- Control request frequency to avoid abuse
- Use tools like *NGINX*, *API Gateway*, or *Cloudflare*
---
📜 *4. Use HTTPS Everywhere*
- Encrypt all data in transit
- Never expose APIs over HTTP
---
🕵️♂️ *5. Monitor & Log*
- Track unusual behavior
- Use centralized logging (e.g., ELK, Datadog)
---
🧱 *6. CORS & Firewall Rules*
- Restrict allowed origins
- Protect using *WAFs* and IP whitelisting
---
Secure APIs = Safe apps + Protected data + Trusted users
Build smart. Build safe.
🔎 ShadowxOsint Bot — ALL-IN-ONE OSINT
📞 Phone → Info
🪪 Aadhaar → Details
🚗 Vehicle / RC → Owner Info
🧑🧑🧒 Family Records
⭐ Telegram ID Lookup
🏦 IFSC & Bank Data
🌐 IP Address Tracking
💠 Crypto Address Intelligence
📸 Instagram Profile Lookup
⚡ Powered by 15+ OSINT APIs
🚀 Fast • Secure • Unlimited
➡️ Start Now: @ShadowxOsint_Bot
Web Cache Deception tips:👾
(a) Path Parameter
example.com/account.php example.com/account.php/nonexistent.css
(b) Encoded Newline (\n)
example.com/account.php example.com/account.php%0Anonexistent.css
(C)Encoded Semicolon (;)
example.com/account.php; par1; par2
example.com/account.php%3Bnonexistent.css
(D) Encoded POund (#)
EXPERIENCE example.com/account.php#summary example.com/account.php%23nonexistent.css
(e) Encoded Question Mark (?)
example.com/account.php?name=val example.com/account.php%3Fname=valnonexistent.css
#bugbounty #offsec #cacheDeception
Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release
https://thehackernews.com/2026/01/cisco-patches-ise-security.html
The Digital Detective’s Arsenal: Essential Tools for Forensics & Investigation
Evidence Integrity & Hashing
Securing the Data
Full Forensic Suites
File Recovery & Carving
Memory & Malware Forensics
OSINT & Reconnaissance
https://medium.com/@eRRoR_/the-digital-detectives-arsenal-essential-tools-for-forensics-investigation-d593083b39be
by eRRoR_
GET type CSRF Lead to Customer PII leak 💋
Senario Att4ck :
1. i invited myself myemail@mail. com to my account
2. got the invitation link from my email, it give you two option (accept / decline)
3. if you click decline invite it open that URL:
https://redacted.com/?corelationID=234d-SDFS- SDF345345&email=myemail@mail.com&accept=false
if you click accept it open:
https://redacted.com/?corelationID=234d-SDFS- SDF345345&email=myemail@mail.com&accept=true
so i had an Idea of changing my email to the victim email:
https://redacted.com/?corelationID=234d-SDFS- SDF345345&email=victimMail@mail.com&accept=true
if you send that link to the victim it AUTO accept him to our account
and the attacker can see: full name, and email address, country of the victim with only One click (or a page that auto open link)
CVE-2025-38001
CVE-2025-38001: Linux HFSC Eltree Use-After-Free - Debian 12 PoC syst3mfailure.io/rbtree-family-drama#linux #poc
