7 Articles

Bug Bounty Writeups

Real-world bug bounty writeups and vulnerability disclosures. Learn from actual security findings reported through responsible disclosure programs.

Hashcat Tutorial: Master Password Cracking with Hashcat
New

Hashcat Tutorial: Master Password Cracking with Hashcat

Unlock the power of Hashcat for password cracking. This deep dive covers setup, attack modes, and advanced techniques for pentesters, red teamers, and bug bounty hunters.

May 04, 2026
Reverse Shell Cheatsheet: Your Ultimate Pentesting Guide
New

Reverse Shell Cheatsheet: Your Ultimate Pentesting Guide

Master reverse shells with this ultimate cheatsheet for pentesters & bug bounty hunters. Get practical code examples, bypass techniques, and troubleshooting tips.

Apr 24, 2026
OWASP Top 10 Explained: A Pentester's Practical Guide
New

OWASP Top 10 Explained: A Pentester's Practical Guide

Dive deep into the OWASP Top 10 with practical insights, real-world examples, and hands-on advice for bug bounty hunters, red teamers, and AppSec engineers. Master critical web …

Apr 23, 2026
Wireshark Tutorial for Pentesters: Deep Dive into Packet Analysis
New

Wireshark Tutorial for Pentesters: Deep Dive into Packet Analysis

Master Wireshark for penetration testing and bug bounty hunting. This practical Wireshark tutorial covers installation, advanced filters, protocol analysis, and real-world scena…

Apr 21, 2026
Reading Uber’s Internal Emails [Uber Bug Bounty report worth $10,000]
Archive

Reading Uber’s Internal Emails [Uber Bug Bounty report worth $10,000]

After recent finding about one of the Uber’s subdomain takeover was publicly disclosed, I looked into Uber to find similar bugs. One of my colleagues Abhibandu Kafle, pointed ou…

2017
How I snooped into your private Slack messages [Slack Bug bounty worth $2,500]
Archive

How I snooped into your private Slack messages [Slack Bug bounty worth $2,500]

When researching about MX records of slack.com, I noticed that they used a 3rd party email service. In that service, however slack.com was already claimed. After a little more r…

2017
Bypassing Ebay XSS Protection to launch XSS by Nirmal Dahal
Archive

Bypassing Ebay XSS Protection to launch XSS by Nirmal Dahal

This is a small proof of concept regarding “Reflective Cross-Site Scripting [ R-XSS ]” which I had found on Ebay. I am not an active participant in bug bounty programs, but one …

2017