- Whoami
- Methodologies - Checklists
- Web-AppSec
- Industry Based Checklist
- Services Based Pentest Checklist
- Features Abuse Checklist
- 2FA
- Ban Feature
- CAPTCHA
- Commenting
- Contact us
- File-Upload
- Inviting Feature
- Messaging Features
- Money-Related Features
- Newsletter
- Email Change
- Password Change
- Change Name Feature
- Change Phone Numbers
- Logout Feature
- Registration
- Reset Password
- Review
- Rich Editor/Text
- Social Sharing
- Addresses Management
- Integrations - Webhooks
- API Key Management
- Reconnaissance
- Improper Authentication
- OAUTH Misconfigurations
- Broken Access Control
- XSS-HTML Injection
- WEB3 RoadMap By Co-Founder of SolidityScan
- Auth0 Misconfigurations
- Broken Link Injection
- Command Injection
- CORS
- CRLF
- CSRF
- Host Header Attacks
- HTTP request smuggling
- JSON Request Testing
- LFI
- No Rate Limit
- Parameters Manual Testing
- Open Redirect
- Registration & Takeover Bugs
- Remote Code Execution (RCE)
- Session Fixation
- SQL Injection
- SSRF
- SSTI
- Subdomain Takeover
- Web Caching Vulnerabilities
- WebSockets
- XXE
- Cookie Based Attacks
- CMS
- XSSI (Cross Site Script Inclusion)
- NoSQL injection
- Local VS Remote Session Fixation
- Protection
- Hacking IIS Applications
- Dependency Confusion
- Attacking Secondary Context
- Hacking Web Sockets
- IDN Homograph Attack
- DNS Rebinding Attack
- Bypass URL Filtration
- Cross-Site Path Traversal (CSPT)
- PostMessage Security
- Prototype Pollution
- Tools-Extensions-Bookmarks
- WAF Bypassing Techniques
- SSL/TLS Certificate Lifecycle
- Serialization in .NET
- Client-Side Attacks
- Bug Bounty Platforms/Programs
- DNS Dangling / NS Takeover
- X-Correlation Injection
- DoS - Exploiting WAF Request Size Limits
- Next.js middleware CP - DOS
- Cache Poisoning Test Plan for Next.js
- Nuxt CP - DOS
- Next.js Middleware Bypass
- Exploiting Parser Flaws for Access Bypasses
- Session Puzzling Attack
- ASP.NET Security Testing
- AI Security
- API-Sec
- GraphQL API Security Testing
- The Basics
- GraphQL Communication
- Setting Up a Vulnerable GraphQL Server
- GraphQL Hacking Tools
- GraphQL Attack Surface
- RECONNAISSANCE
- GraphQL DOS
- Information Disclosure
- AUTHENTICATION AND AUTHORIZATION BYPASSES
- Injection Vulnerabilities in GraphQL
- REQUEST FORGERY AND HIJACKING
- VULNERABILITIES, REPORTS AND EXPLOITS
- GraphQL Hacking Checklist
- API Recon
- API Token Attacks
- Broken Object Level Authorization (BOLA)
- Broken Authentication
- Evasive Maneuvers
- Improper Assets Management
- Mass Assignment Attacks
- SSRF
- Injection Vulnerabilities
- Excessive Data Exposure
- OWASP API TOP 10 MindMap
- Scanning APIs with OWASP ZAP
- GraphQL API Security Testing
- Android-AppSec
- Android App Pentesting Checklist
- Intercepting Cellular Android Traffic via Mobile Data and Ngrok
- Setup Android App Pentesting environment on Arch
- Setup Android App Pentesting environment on Mac M4
- Genymotion - Proxying Android App Traffic Through Burp Suite
- Setup Android Pentesting Environment on Debian Linux
- Android App Fundamentals
- Android App Components Security Cheatsheet
- SSL Pinning Bypass
- Decompile a Hermes React Native Binary
- Get APK for Target
- ADB Commands
- APK structure
- Android Permissions
- Exported Activity Hacking
- BroadcastReceiver Hacking
- Content Provider Hacking
- Signing the APK
- Reverse Engineering APK
- Deep Links Hacking
- Drozer Cheat Sheet
- SMALI
- Intent Redirection Vulnerability
- Janus Vulnerability (CVE-2017-13156)
- Task Hijacking
- Frida Cheat Sheet
- Magisk & LSPosed Modules
- IOS-AppSec
- iOS Device/Simulator Setup
- Understanding iOS Security Basics
- iOS Pentesting Environment Setup
- Configuring Xcode iOS Simulator with Burp Suite for Pentesting on macOS
- How to GET/PULL/Install IPA
- Common SSH and libimobiledevice Commands
- Intercepting Network Traffic with Burp Suite
- Automatic Static Analysis
- IOS Reverse Engineering
- Network-Sec
- Desktop AppSec
- Cloud Sec
- Programming
- Operating Systems
- Write-Ups
- Discord OAuth Misconfig → ATO, Pre-ATO & 2FA Bypass
- How to Use Claude Code for Bug Hunting — For Free (A Beginner's Guide)
- From Recon to Reward: My Bug Bounty Methodology when Hunting on Public Bug Bounty Programs
- Exploring Subdomains: From Enumeration to Takeover Victory
- 0-Click Account Takeover via Insecure Password Reset Feature
- How a Simple Click Can Lead to Account Takeover: An OAuth Insecure Implementation Vulnerability
- The Power Of IDOR even if it is unpredictable IDs
- Unlocking the Weak Spot: Exploiting Insecure Password Reset Tokens
- AI Under Siege: Discovering and Exploiting Vulnerabilities
- Inside the Classroom: How We Hacked Our Way Past Authorization on a Leading EdTech Platform
- How We Secured Our Client’s Platform Against Interaction-Free Account Thefts
- Unchecked Privileges: The Hidden Risk of Role Escalation in Collaborative Platforms
- Decoding Server Behavior: The Key to Mass Account Takeover
- Exploiting JSON-Based CSRF: The Hidden Threat in Profile Management
- How We Turned a Medium XSS into a High Bounty by Bypassing HttpOnly Cookie
- How Monitoring Target Updates Helped Me Earn Bounties in Bug Bounty
- Semi-Automating My Android Bug Hunting Flow with apkX
- Using N8N To Orchestrate Web and Mobile Bug Hunting
- Hacking Android Labs