Browsing Category
Books
65 posts
Database Exposure: A Guide to Common Misconfigurations and Defensive Strategies
Databases are the heart of any modern application, storing crucial information, from simple user preferences to highly sensitive…
Exploitation Phase: Targeting CMS, GitHub, and Subdomain Takeovers
According to a survey performed by W3Techs, 62% of the internet is run on a Content Management System…
The Exploitation Phase: Hacking Known Vulnerabilities in Bug Bounty
This guide focuses entirely on the exploitation phase of a bug bounty hunt. While the preceding phases—reconnaissance and…
Understanding HTML Injection: A Critical Look at Web Vulnerabilities
You’ve learned about many types of attacks and vulnerabilities that can plague a web application. Attackers often exploit…
Finding Command Injection Vulnerabilities
Command Injection vulnerabilities occur when a server running an application can be compromised using arbitrary operating system (OS)…
Hacking the Data Structure: Injecting Unintended XML
When performing a penetration test (pen test) on an application, especially one where the functionality relies on XML…
Understanding and Protecting Against Sender Policy Framework (SPF) Poisoning
What is Sender Policy Framework (SPF)? Sender Policy Framework (SPF) is a technical standard designed to provide a…
Unmasking the Weakness: How to Discover CSRF on Any Application
Introduction to Cross-Site Request Forgery (CSRF) As a penetration tester or bug bounty hunter, you will often be…
Top Bug Bounty Hunting Tools in 2025: Boost Coverage, Speed, and Success
The top bug bounty hunting tools are generally categorized into HTTP Proxies/Traffic Analyzers, Automated Scanners/Exploitation Tools, and Reconnaissance…
Top Learning Resources for Aspiring Bug Bounty Hunters
The most important habit for a bug bounty hunter is continuous learning. This is a challenging task, as…