ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·1d ago · 6 min readMapping a Web App’s Attack SurfaceBefore any serious security testing begins, skilled penetration testers spend a surprising amount of time simply looking. Long before an exploit is fired off, an attacker is quietly reading URLs, para00
JAJoyce Abijaincybersage.hashnode.dev·2d ago · 6 min readYou don't have to be important to be Hacked"I’m just an ordinary person, I don't work for the government or FBI. Why would anyone want to hack me?” This question reflects one of the biggest misconceptions people have about cybersecurity: the b00
KRKaustubh Raiinraikaustubh.com·2d ago · 5 min readThe BApp That Almost Worked: Building curl2repeater 🔧There's always that one extension everyone has installed and nobody's actually checked. For BurpSuite, mine was Paste cURL to Repeater. I'd had it installed for months before I bothered actually looki30
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·2d ago · 8 min readWhen the Safety System Becomes the Threat Model: A Case Study in Classifier Drift Field notes from 43 hours of legitimate security research, 35 false-positive blocks, and one support form. The setup I do authorized bug bounty work and CTF practice. My toolchain is unremarkable by d00
ASAbdulaziz Saadinblog.abdulaziz-d.com·4d ago · 10 min readThe $1000 Ticket IDOR: One Number Exposed National IDs and Government Staff PIISeverity: HighBounty: ~$949Program: Private Bug BountyPlatform: Bugbounty.sa This finding started with a very simple endpoint: GET /api/tickets-management/portal/history-by-ticket/<ticket_id> The end30
ASAbdulaziz Saadinblog.abdulaziz-d.com·5d ago · 12 min readFrom Editor to Owner: One Writable Field Was Enough to Take Over an OrganizationSeverity: HighBounty: ~$315Platform: Standoff365 This one came down to a single field that should never have been writable by an editor: Firm[user_id] The application had a clear permission model. An10
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 14 · 8 min readClient-Side Web Security EssentialsModern web apps aren’t just “pages in a browser”—they’re interactive systems where the client (browser) and the server continuously exchange data and decisions. If you’re learning web application secu10
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 11 · 8 min readMy AI Agent Captured the Flag. Then the Platform Refused to Accept It. Today was a good day and a weird day, in that order. The good part: the autonomous pentest agent I've been building — I call it HALO — went from "runs a bunch of tools and hopes" to an actual web-reco00
ASAbdulaziz Saadinblog.abdulaziz-d.com·Aug 7 · 12 min readA $2,000 API Key: Unauthorized Access to Paid Medical TranscriptionSeverity: HighBounty: $2,000Retest Reward: $150Total Awarded: $2,150Program: Private ProgramPlatform: HackerOne This finding started with a familiar Android testing problem: What secrets were shipped00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 6 · 3 min readClaude Code Just Hijacked My Workflow… and My Screen Started Glowing I asked Claude Code to do one of the most boring tasks imaginable. “Find the music file I made.” That’s it. No penetration testing. No coding marathon. No AI agent swarm coordinating across containers02S