UBUday Bhaleinhackwithrudraub.hashnode.dev·18h ago · 7 min readPart 3: From Admin Panel to Remote Code ExecutionWe made it. After chaining IDOR → Information Disclosure → Weak Password Reset → Administrator Access, we finally reached the admin dashboard. But administrator access isn't the end of the attack. It'00
UBUday Bhaleinhackwithrudraub.hashnode.dev·1d ago · 5 min readWeak Password Reset Mechanism: From IDOR to Admin AccessThe IDOR from Part 1 gave us something much more valuable than just another user's profile. This is part 2 of the guided pen test lab. It gave us the administrator's email address. Now the question is00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Aug 2 · 5 min readGuided Pentest: Web (Part 1)From Reconnaissance to Discovering an IDOR Status: 🚧 Work in Progress This write-up documents my learning journey through the Guided Pentest: Web room. This is Part 1, covering reconnaissance, techn00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Jul 28 · 2 min read🏖️TryHackMe Hacker's Holiday 2026 | Day 2: Room 404 - Exposed Source Code"Sometimes the biggest vulnerability isn't hidden behind authentication. It's left in plain sight." The hint for this room was short but clear: Dump the exposed source code. Find the flag. That imme00
UBUday Bhaleinhackwithrudraub.hashnode.dev·Jul 27 · 2 min read🎄 TryHackMe Hacker's Holiday 2026 | Day 0: Following the Digital TrailWhat can a single image reveal? For Day 0 of TryHackMe's Hacker's Holiday 2026, the challenge introduced the fundamentals of Open Source Intelligence (OSINT). Starting with nothing more than a hotel b00