IIliyainblog.iliyadindar.site·3d ago · 8 min readIntigriti September 2026 Challenge, Critter GalleryVulnerability: Unauthenticated SQL injection (MySQL 8.0.46) in the base64-encoded pic parameter of /challenge.php, exploited with a single-column UNION SELECT to read the secret_vault table. TL;DR /c00
TFThe Flux Readinthefluxread.hashnode.dev·Sep 24 · 1 min readResearchers Used Claude to Hack OpenAI — Here’s How the Chain WorkedThree security researchers recently spent 72 hours using Claude (Opus 4.8 & Opus 5) to weaponize an unpatched forum bug, bypass OpenAI's SSO identity sandbox, and gain unauthorized access to internal 00
KPKrishn Patelinai-pentester.hashnode.dev·Sep 3 · 3 min readBuilding AI Pentester Week 3: Recon Got Better When I Stopped Treating It Like Output Collection This week I worked on recon, but the real problem was not adding more tooling. The real problem was making recon useful to the stages that come after it. At the start of the week, AI Pentester could a00
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 14 · 8 min readClient-Side Web Security EssentialsModern web apps aren’t just “pages in a browser”—they’re interactive systems where the client (browser) and the server continuously exchange data and decisions. If you’re learning web application secu10
KMkareem Mohamedinkmb.hashnode.dev·Aug 10 · 9 min readWeaponizing Time: An Elite Guide to Race ConditionsMost hackers look for flaws in the input, but what about looking for flaws in time?Imagine requesting a single $100 ATM withdrawal, but hitting the button ten times in the exact same millisecond and w00
BB0dj0xinb0dj0x.hashnode.dev·Jul 27 · 6 min readHow to Start Bug Bounty Hunting in 2026: The Complete Beginner's GuideEverything you need to know to find your first vulnerability, get paid, and build a real reputation in cybersecurity — without breaking any laws. If you've typed "how to start bug bounty hunting" int10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 18 · 7 min readFAM CTF : The Cloud writeupSummary The target exposed a webhook endpoint (/internal/webhook) meant to act as an internal-only proxy, blocking direct requests to private and link-local IP ranges. That blocklist checked resolved 00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Jul 17 · 4 min readHackTheBox : Void Whispers WriteupSummary The "Void Whispers" mail-settings panel passes the user-supplied sendMailPath field directly into shell_exec("which $sendMailPath") with no escaping. The app only filters literal whitespace, w00
Ssecurity_researcherinsecurity11.hashnode.dev·Jul 3 · 5 min readBreaking Through the Invisible Walls: How JS Recon and Parameter Pollution Exposed Sensitive KYC DataSome of the best vulnerabilities are hidden not in plain sight, but in the dark, forgotten corners of an application. This writeup details the discovery of a logical flaw chain within a project manage00
TVThuriaanandh Vinthuriaanandh-sec.hashnode.dev·Jun 13 · 6 min readPath Traversal: 6 Labs, 6 Times I Was Wrong Before I Was RightI just finished all six Path Traversal labs on PortSwigger's Web Security Academy, going from Apprentice to Practitioner level. Going in, I thought path traversal was simple — just throw ../../../etc/00