uk
Feedback
Hacking Vidhya

Hacking Vidhya

Відкрити в Telegram

We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.

Показати більше
385
Підписники
+224 години
+47 днів
+2430 днів
Архів дописів
🎑🎑 Bug bounty guide 🎑🎑 Identification and reporting of bugs and vulns in a responsible way. All depends on  interest and hardwork, not on degree, age, branch, college, etc. 🎑 What to study? 1. Internet, HTTP, TCP/IP 2. Networking 3. Command line 4. Linux 5. Web technologies, javascript, php, java 6. Atleast 1 prog language (Python/C/JAVA/Ruby..) 🎑 Choose your path (imp) 1. Web pentesting 2. Mobile pentesting 3. Desktop apps 🎑  Resources 1. Books   For web    1. Web app hackers handbook    2. Web hacking 101    3. Hacker's playbook 1,2,3    4. Hacking art of exploitation    5. Mastering modern web pen testing    6. OWASP Testing guide   For mobile    1. Mobile application hacker's handbook 🎑  Youtube channels   1. Hacking    1. Live Overflow    2. Hackersploit    3. Bugcrowd    4. Hak5    5. Hackerone   Programming    1. thenewboston    2. codeacademy 🎑  Writeups, Articles, blogs   1. Medium (infosec writeups)   2. Hackerone public reports   3. owasp.org   4. Portswigger   5. Reddit (Netsec)   6. DEFCON conference videos   7. Forums 🎑  Practice (imp) Tools   1. Burpsuite   2. nmap   3. dirbuster   4. sublist3r   5. Netcat 🎑  Testing labs   1. DVWA   2. bWAPP   3. Vulnhub   4. Metasploitable   5. CTF365   6. Hack the box 🎑  Start! Select a platform   1. Hackerone   2. Bugcrowd   3. Open bug bounty   4. Zerocopter   5. Antihack   6. Synack (private) 1. Choose wisely (first not for bounty) 2. Select a bug for hunt 3. Exhaustive search 4. Not straightforward always REPORT: 5. Create a descriptive report 6. Follow responsible disclosure 7. Create POC and steps to reproduce 🎑  Words of wisdom 1. PATIENCE IS THE KEY, takes years to master, don't fall for overnight success 2. Do not expect someone will spoon feed you everything. 3. Confidence 4. Not always for bounty 5. Learn a lot 6. Won't find at the beginning, don't lose hope 7. Stay focused 8. Depend on yourself 9. Stay updated with infosec world ━━━━━━━━━━━━━ Share and support 🤟😉

API Pentesting Series — Part 7 Before you attack APIs, you need a solid lab. This part covers: • Tooling (Burp, DevTools, Pos
API Pentesting Series — Part 7 Before you attack APIs, you need a solid lab. This part covers: • Tooling (Burp, DevTools, Postman) • Discovery tools (Kiterunner, Nikto) • Docker-based vulnerable APIs • Full environment setup Notion Notes 🔗: https://notion.so/aacle/PART-7-API-PenTesting-Series-LAB-SETUP-2b9f7b9ea30e809f8e8ddc938eb0fb1a

Hey everyone! 👋 First of all, sorry for being inactive for a while. Our last event was a long time ago, and many of you have been waiting for new sessions. We’re now getting ready to restart everything with fresh energy! ⚡️ 💡 Tell us what topics you want for the next event. What kind of session or workshop should we host? Any speakers you want us to invite? Share your ideas here 👇 👉 https://chat.whatsapp.com/ES6N2CXl4tkIvKNMUNAv4h 🎤 Suggested Topics (you can choose or add your own): Bug Bounty Deep Dive (XSS, SQLi, API bugs, live demos) Malware Development & Malware Analysis Real-world Pentesting Walkthrough Mobile Hacking (Android / iOS) AI + Cybersecurity (Bypasses, Detection, Automation) OSINT Live Case Studies WAF Bypass Techniques Cybersecurity Career Guidance 📍 We’re also planning an offline meet-up soon! If you’re interested, please drop your city name so we can plan better. Let’s make Hacking Vidhya active, strong, and valuable again! 💙 Your suggestions matter 🙌

Repost from N/a
Grok 4.1 Jailbreak - Sensory Archiv.txt0.04 KB

📢 Important Update for WhatsApp, Telegram, Signal & Snapchat Users in India! India’s Department of Telecommunications (DoT)
📢 Important Update for WhatsApp, Telegram, Signal & Snapchat Users in India!
India’s Department of Telecommunications (DoT) has given major messaging apps 90 days to implement a new rule called SIM Binding. 🔒 What is SIM Binding? After this rule is enforced, if you 👉 remove the SIM card that was used during account registration, the app will stop working. This means the same SIM used for registration must remain active in the device. 📅 Deadline: February 2026 All messaging platforms in India will be required to follow this policy.
⚠️ This update aims to improve security and prevent misuse of messaging apps. #NEWS @HACKTSUKI

🛡️ Vulnerability in Zora ERC20Z via Uniswap v3/v4 A researcher discovered a critical price vulnerability in the Zora contrac
🛡️ Vulnerability in Zora ERC20Z via Uniswap v3/v4 A researcher discovered a critical price vulnerability in the Zora contract, exploiting a Uniswap feature — the ability to manipulate the token price when there is no liquidity by performing swaps with zero amount. The first exploit attempt failed due to protections, but an updated method successfully changed the token price and drained ETH from the pool. Zora quickly fixed the bug and rewarded the researcher with an $11,000 USDC bounty. 🔗 Details

Common Rate Limit Bypass Techniques IP Spoofing Altering a request’s source IP to appear from another device, and rotating IPs lets an attacker bypass per-IP limits. You can use the following Burp Extensions for IP Spoofing: BurpFakeIP: GitHub IP-Rotate: GitHub Changing User-Agent Rate-limit systems often track the User-Agent header; changing or randomizing it makes requests appear from different clients, and attackers may brute-force the User-Agent field (e.g., with tools like Burp Suite Intruder). Header Manipulation Header manipulation alters HTTP headers (e.g., X-Forwarded-For, X-Real-IP) to trick servers — bypassing IP restrictions, evading rate limits, or hiding the real IP from logs and filters. Common Headers by 🕷Spix0r Requesting with Different HTTP Methods Some rate-limiters monitor only certain HTTP methods (e.g., GET/POST); attackers may bypass them by sending requests with other methods (PUT, DELETE, OPTIONS) and testing alternatives (e.g., with Burp Suite Repeater). HTTP request methods Parameter Name Variation Some backends accept alternate parameter names and still process requests, enabling attackers to bypass input filters, WAFs, or login restrictions.
username=admin&password=1234
user=admin&pass=1234
uname=admin&pwd=1234
login=admin&passwd=1234
u=admin&p=1234
email=admin&key=1234
id=admin&token=1234
Encoding Tricks Encoding represents characters in different formats; attackers use encoding to obfuscate payloads and bypass input filters, WAFs, or validation rules.
user=admin%20        # space after admin
user=admin%00        # null byte injection
user=%61%64%6d%69%6e # 'admin' in hex
user=ad%6Din  # only 'm' is encoded
user=%2561%2564%256d%2569%256e  # double-encoded 'admin'
Case Sensitivity and Font Tricks Case or character-variant changes in strings (emails, usernames, paths) can let attackers bypass security checks or exploit improper validation.
Email: Test@Example.com  # Mixed case
Email: test@example.com   # Lowercase
Email: TEST@example.com   # Uppercase
Using Look-Alike Characters
Email: t3st@3xample.com   # '3' instead of 'e'
Email: t@est@example.com   # Replacing 'l' with 'I' or vice versa
Blank Characters Inserting spaces, null bytes, or invisible characters (e.g., TAB, CRLF) can bypass filters, break input validation, or exploit server input handling.
email=" test@example.com "  # Adding spaces at the beginning and end
email=test@example.com%20  # Adding a space encoded as %20
email=test@example.com%E2%80%8B  # Injecting a zero-width space
email=test@example.com%09  # Tab character
email=test@example.com%0A  # Newline character
#bugbounty #ratelimit

sticker.webp0.24 KB

*MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants* Security researchers just uncovered a serious oversight in Microsoft Teams that lets attackers bypass Microsoft Defender protections simply by using guest access. Here’s the catch - 🥸 When you join another company’s Teams space as a guest, you lose your own organization’s protections. Everything phishing safeguards, malware scanning, Safe Links, Safe Attachments all depends on their security setup, not yours. If their security is weak, you're weak. And attackers have figured out how to weaponize that. Why this matters Microsoft recently rolled out a new Teams feature letting users chat with anyone via email including people outside Teams. It’s turned on by default. That means attackers can now: * Create a cheap Microsoft 365 tenant with no Defender protections * Send Teams guest invitations straight to your inbox (the emails look fully legit because they come from Microsoft’s own servers) or even interview invites * Get you to join their tenant * Deliver phishing links or malware inside a “protection-free zone” where your company’s tools can't see anything * Because the invite comes from Microsoft infrastructure, it bypasses SPF, DKIM, and DMARC, so most email filters won’t flag it. Once you accept, your organization has zero visibility into what happens next. As Ontinue’s researchers put it: Your employer’s defenses “never trigger because the attack occurred outside their security boundary.” Why it works ⦁ Guest access = you follow the host tenant’s rules ⦁ A malicious host = no rules ⦁ Defender for Office 365 does not protect you once you cross into their environment ⦁ A low-cost Teams license is all an attacker needs to set up a trap ⦁ This is a textbook example of attackers abusing the “trust” in cloud collaboration. How organizations can protect themselves and experts recommendation to companies: ⦁ Restrict who can accept guest invites (only approved domains) ⦁ Tighten cross tenant access policies ⦁ Disable external Teams messaging if not needed ⦁ Train users to question unexpected chat invites (especially from unknown organizations) Because right now, a Teams invite could be the new phishing email. Source: https://thehackernews.com/2025/11/ms-teams-guest-access-can-remove.html?_m=3n%2e009a%2e3836%2ena0ao46jab%2e2vl4

🔥 TryHackMe Vouchers Back in Stock! 🔥 Get 1-Month Access for the LOWEST price in the market — only ₹350! ⚡ Fast Delivery ⚡ Limited Stock ⚡ Bulk Orders Welcome 👉 Contact: @sttexo 📞 +91 95581 80779

ssti. mind map
ssti. mind map

> Introduction-to-Exploit-Zero-Day-Discovery-and-Development Language : English Download link https://mega.nz/file/jhBUFAoI#MWniDd2_ZebbaI70XTiSIQiFcdwjUlOKG0JwSU6Qbt0

Open Source Intelligence (OSINT): Using Flowsint for Graph-Based Investigations Guide by _aircorridor: Install Create account
Open Source Intelligence (OSINT): Using Flowsint for Graph-Based Investigations Guide by _aircorridor: Install Create account and first investigation Running Transforms to Discover Relationships Chaining Transforms for Deeper Investigation https://hackers-arise.com/open-source-intelligence-osint-using-flowsint-for-graph-based-investigations/

🚀 VectorXO Get fast OSINT insights, smart lookups, and clean security data — all inside the channel and bot. More powerful API features are coming soon to make your research smoother and faster. 🔧 Currently, only the HITEK API is integrated — more APIs are on the way! 👉 Join now: https://t.me/VectorXO

https://www.pib.gov.in/PressReleasePage.aspx?PRID=2193695 Cyber Security Innovation Challenge (CSIC) 1.0 launched by Ministry of Electronics and Information Technology (MeitY) MeitY, Data Security Council of India (DSCI) and Centre for Development of Advanced Computing (C-DAC) Hyderabad unveiled the Cyber Security Innovation Challenge 1.0 for students and researchers under the ISEA Initiative The initiative exposes students to real-world cyber security challenges, positioning the field as a viable career path and strengthens India’s homegrown cyber resilience

❗️Mullvad servers are down ❗️ BREAKING NEWS: Detroit YN's crashed a hellcat into the Mullvad servers. Causing a massive outag
+1
❗️Mullvad servers are down ❗️ BREAKING NEWS: Detroit YN's crashed a hellcat into the Mullvad servers. Causing a massive outage in Detroit. It's alleged that the crash happened due to hands being greasy from KFC chicken that they stole. ➡News / PrivRDP / PrivRDP Bot

https://thexssrat.podia.com/capie-lesson-material-no-cert?coupon=CAPIEFREE Claim Free Certifications By Lexions Community Onl
https://thexssrat.podia.com/capie-lesson-material-no-cert?coupon=CAPIEFREE Claim Free Certifications By Lexions Community Only Limited Seats♥️

Charge your brains — 9 PM we go LIVE! ⚡ Hacking Vidhya is hosting a surprise night webinar today at 9 PM covering everything
Charge your brains — 9 PM we go LIVE! ⚡ Hacking Vidhya is hosting a surprise night webinar today at 9 PM covering everything you need to level up your cybersecurity journey. 🔥 Topics we’re breaking down: 🔹 Hacking Fundamentals 🔹 Bug Bounty Basics (BBP) 🔹 Cybersecurity Roadmap 🔹 Career-boosting Certifications Whether you're just starting or already grinding in cybersecurity, this session will give you clarity, direction, and hands-on insights. 📅 Today ⏰ Time: 9:00 PM 🎯 Hosted by: Hacking Vidhya Join in, learn live, and upgrade your skills. Don’t miss it — see you at 9 PM sharp! 🚀🔐