> For the complete documentation index, see [llms.txt](https://w43l.gitbook.io/getting-started-cybersec-most-common-questions/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://w43l.gitbook.io/getting-started-cybersec-most-common-questions/phase-2/based-on-learning-about-vulnerabilities.md).

# Based on Learning about Vulnerabilities

“Being a hacker is lots of fun, but it’s a kind of fun that takes lots of effort. The effort takes motivation.”

<figure><img src="https://730872837-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FfLWOIoUdBepGX41NYnQM%2Fuploads%2FNE26oavTXASLAoxfbjw7%2Fimage.png?alt=media&amp;token=55b6723d-0c29-42ac-b709-006b8ff25a9f" alt=""><figcaption></figcaption></figure>

Now let’s start with the basic learning about InfoSec the first and really most important step would be to choose a proper initial path that you are going to start learning. Choosing the right path to start in Bug Bounty is very important. It totally depends upon your interest, like some people choose Web Application path first coz it’s easy to learn and go through than mobile and others… (Some of the resources are moved here from my old blog that’s I’m ***going to remove but these are updated and properly arranged by my experience***)\
\
I’ll focus on Web, & Mobile Here coz this is what my interest is.

Before I add anything else I’ll suggest You to actually go through\
\
**Hacker101 By** [**HackerOne**](https://www.hackerone.com/) <https://www.hacker101.com/>\
And\
[**Bugcrowd**](https://www.bugcrowd.com/) **University** <https://www.bugcrowd.com/hackers/bugcrowd-university/>\
\
Both of these contain a Huge list of resources and lectures that can help you in even a better way than many of us can’t but as you guys are following this as well so I decided to add them here also.

### **Web App Security:**

Before I Suggest you what to Learn first if you follow my suggested path l’ll like to tell you some ways you can practice your skills..

**CTF(Capture The Flag):**\
Now to practice for Bug Bounties you can participate in CTF challenges. Just like the name suggests “Capture The Flag” there are several challenges for you to solve which deals with real-world vulnerabilities. The more you practice on these challenges the more you will learn about the different technologies required to break into an application or a system.

For Web App, I’ll suggest you guys read the following books & guides first\
\
\><https://www.packtpub.com/networking-and-servers/mastering-modern-web-penetration-testing>\
\><https://www.amazon.com/Hackers-Underground-Handbook-secure-systems/dp/1451550189>\
\><https://leanpub.com/web-hacking-101>\
\><https://www.amazon.com/gp/product/1593275641/>\
\><https://www.amazon.com/gp/product/1512214566/>\
\><https://www.amazon.com/Tangled-Web-Securing-Modern-Applications-ebook/dp/B006FZ3UNI/>

Reading these books you will get good knowledge about Web App Penetration testing & Security testing in general and in-depth.\
\
In addition to these books, I’ll suggest you guys should really give good time reading and understanding OWASP Testing Guide & OWASP Top 10 Vulnerabilities from 2010-2017\
\
**OWASP Testing project:**\
\><https://www.owasp.org/index.php/OWASP_Testing_Project>

**OWASP Top 10 Project:**\
\><https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project#OWASP_Top_10_for_2010>\
\><https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project#OWASP_Top_10_for_2013>\
\><https://www.owasp.org/images/7/72/OWASP_Top_10-2017_%28en%29.pdf.pdf>

Adding a Few basic Pdfs for you guys to go through and save locally to you can keep it revised and keep learning from them. I’ll say they gonna help you almost a hundred percent of the time. So do give these a good time\
\
\> Kali Linux **Revealed** <https://docs.kali.org/pdf/kali-book-en.pdf>\
\> **Nmap Cheat Sheet** <https://s3-us-west-2.amazonaws.com/stationx-public-download/nmap_cheet_sheet_0.6.pdf>\
\> **Metasploit Cheat Sheet:** <https://www.sans.org/security-resources/sec560/misc_tools_sheet_v1.pdf>

Now by this point, I’ll say You have done Good enough research and given good time to practice and learn that you can jump into a Bug Bounty Program to test in real-life environment outside CTF, or test environments.\
So you can happily jump to the pages at\
\
<https://bugcrowd.com/programs>\
<https://hackerone.com/directory>

**PentesterLab**\
There’s only one way to properly learn web penetration testing: by getting your hands dirty. PentesterLab teaches how to manually find and exploit vulnerabilities and is a good resource to learn and practice all at once.

**Pentester Academy**

Another Great resource to practice using online labs and learn, they also provide certifications.

\
And Select a Program But I’ll suggest you read till the end.

Following all of them books, testing guides you might have an idea of vulnerabilities so i’ll name a few common ones and try to give good reference to learn them easily.

#### Cross-Site Request Forgery (CSRF)

Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they’re currently authenticated.\
\
**References to read:**\
\
\><https://www.imperva.com/learn/application-security/csrf-cross-site-request-forgery/?utm_campaign=Incapsula-moved>\
\><https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)>\
\><https://www.netsparker.com/blog/web-security/csrf-cross-site-request-forgery/>\
\
**Some POCs:**

* [CSRF Account Takeover famebit](https://medium.com/bugbountywriteup/account-take-over-vulnerability-in-google-acquisition-famebit-e93b1a0a7af9) by Hassan Khan
* [Hacking PayPal Accounts with one click (Patched)](http://yasserali.com/hacking-paypal-accounts-with-one-click/) by Yasser Ali
* [Add tweet to collection CSRF](https://hackerone.com/reports/100820) by vijay kumar
* [Facebookmarketingdevelopers.com: Proxies, CSRF Quandry and API Fun](http://philippeharewood.com/facebookmarketingdevelopers-com-proxies-csrf-quandry-and-api-fun/) by phwd
* [How i Hacked your Beats account ? Apple Bug Bounty](https://aadityapurani.com/2016/07/20/how-i-hacked-your-beats-account-apple-bug-bounty/) by @aaditya\_purani
* [Paypal bug bounty: Updating the Paypal.me profile picture without consent (CSRF attack)](https://hethical.io/paypal-bug-bounty-updating-the-paypal-me-profile-picture-without-consent-csrf-attack/) by Florian Courtial
* [CSRF Account Takeover](https://medium.com/bugbountywriteup/csrf-account-takeover-in-a-company-worth-1b-6e966813c262) by Vulnerables
* [Uber CSRF Account Takeover](https://ngailong.wordpress.com/2017/08/07/uber-login-csrf-open-redirect-account-takeover/) by Ron Chan
* [Messenger.com CSRF that show you the steps when you check for CSRF](https://whitton.io/articles/messenger-site-wide-csrf/) by Jack Whitton

#### **Cross-Site Scripting (XSS)**

XSS enables attackers to inject client-side scripts into web pages viewed by other users.

**References to read:**\
\
\><https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)>\
\><https://portswigger.net/web-security/cross-site-scripting>\
\><https://excess-xss.com/>\
\
**Some POCs:**

* [AirBnb Bug Bounty: Turning Self-XSS into Good-XSS #2](http://www.geekboy.ninja/blog/airbnb-bug-bounty-turning-self-xss-into-good-xss-2/) by geekboy
* [Uber Self XSS to Global XSS](https://httpsonly.blogspot.hk/2016/08/turning-self-xss-into-good-xss-v2.html)
* [How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)](https://medium.com/@marin_m/how-i-found-a-5-000-google-maps-xss-by-fiddling-with-protobuf-963ee0d9caff#.cktt61q9g) by Marin MoulinierFollow
* [Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities](https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/) by Brett
* [XSSI, Client Side Brute Force](http://blog.intothesymmetry.com/2017/05/cross-origin-brute-forcing-of-saml-and.html)
* [postMessage XSS Bypass](https://hackerone.com/reports/231053)
* [XSS in Uber via Cookie](http://zhchbin.github.io/2017/08/30/Uber-XSS-via-Cookie/) by zhchbin
* [Stealing contact form data on www.hackerone.com using Marketo Forms XSS with postMessage frame-jumping and jQuery-JSONP](https://hackerone.com/reports/207042) by frans
* [XSS due to improper regex in third party js Uber 7k XSS](http://zhchbin.github.io/2016/09/10/A-Valuable-XSS/)
* [XSS in TinyMCE 2.4.0](https://hackerone.com/reports/262230) by Jelmer de Hen
* [Pass uncoded URL in IE11 to cause XSS](https://hackerone.com/reports/150179)
* [Twitter XSS by stopping redirection and javascript scheme](http://blog.blackfan.ru/2017/09/devtwittercom-xss.html) by Sergey Bobrov
* [Microsoft XSS and Twitter XSS](http://blog.wesecureapp.com/xss-by-tossing-cookies/)
* [Google Japan Book XSS](http://nootropic.me/blog/en/blog/2016/09/20/%E3%82%84%E3%81%AF%E3%82%8A%E3%83%8D%E3%83%83%E3%83%88%E3%82%B5%E3%83%BC%E3%83%95%E3%82%A3%E3%83%B3%E3%82%92%E3%81%97%E3%81%A6%E3%81%84%E3%81%9F%E3%82%89%E3%81%9F%E3%81%BE%E3%81%9F%E3%81%BEgoogle/)
* [Flash XSS mega nz](https://labs.detectify.com/2013/02/14/how-i-got-the-bug-bounty-for-mega-co-nz-xss/) – by frans
* [Flash XSS in multiple libraries](https://olivierbeg.com/finding-xss-vulnerabilities-in-flash-files/) – by Olivier Beg
* [xss in google IE, Host Header Reflection](http://blog.bentkowski.info/2015/04/xss-via-host-header-cse.html)
* [Years ago Google xss](http://conference.hitb.org/hitbsecconf2012ams/materials/D1T2%20-%20Itzhak%20Zuk%20Avraham%20and%20Nir%20Goldshlager%20-%20Killing%20a%20Bug%20Bounty%20Program%20-%20Twice.pdf)
* [xss in google by IE weird behavior](http://blog.bentkowski.info/2015/04/xss-via-host-header-cse.html)
* [xss in Yahoo Fantasy Sport](http://dawgyg.com/2016/12/07/stored-xss-affecting-all-fantasy-sports-fantasysports-yahoo-com-2/)
* [xss in Yahoo Mail Again, worth $10000](https://klikki.fi/adv/yahoo2.html) by Klikki Oy
* [Sleeping XSS in Google](https://blog.it-securityguard.com/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/) by securityguard
* [Decoding a .htpasswd to earn a payload of money](https://blog.it-securityguard.com/bugbounty-decoding-a-%F0%9F%98%B1-00000-htpasswd-bounty/) by securityguard
* [Google Account Takeover](http://www.orenh.com/2013/11/google-account-recovery-vulnerability.html#comment-form)
* [Sleeping stored Google XSS Awakens a $5000 Bounty](https://blog.it-securityguard.com/bugbounty-sleeping-stored-google-xss-awakens-a-5000-bounty/) by Patrik Fehrenbach
* [RPO that lead to information leakage in Google](http://blog.innerht.ml/rpo-gadgets/) by filedescriptor
* [God-like XSS, Log-in, Log-out, Log-in](https://whitton.io/articles/uber-turning-self-xss-into-good-xss/) in Uber by Jack Whitton
* [Three Stored XSS in Facebook](http://www.breaksec.com/?p=6129) by Nirgoldshlager
* [Using a Braun Shaver to Bypass XSS Audit and WAF](https://blog.bugcrowd.com/guest-blog-using-a-braun-shaver-to-bypass-xss-audit-and-waf-by-frans-rosen-detectify) by Frans Rosen
* [An XSS on Facebook via PNGs & Wonky Content Types](https://whitton.io/articles/xss-on-facebook-via-png-content-types/) by Jack Whitton
  * he is able to make stored XSS from a irrelevant domain to main facebook domain
* [Stored XSS in \*.ebay.com](https://whitton.io/archive/persistent-xss-on-myworld-ebay-com/) by Jack Whitton
* [Complicated, Best Report of Google XSS](https://sites.google.com/site/bughunteruniversity/best-reports/account-recovery-xss) by Ramzes
* [Tricky Html Injection and Possible XSS in sms-be-vip.twitter.com](https://hackerone.com/reports/150179) by secgeek
* [Command Injection in Google Console](http://www.pranav-venkat.com/2016/03/command-injection-which-got-me-6000.html) by Venkat S
* [Facebook’s Moves – OAuth XSS](http://www.paulosyibelo.com/2015/12/facebooks-moves-oauth-xss.html) by PAULOS YIBELO
* [Stored XSS in Google Docs (Bug Bounty)](http://hmgmakarovich.blogspot.hk/2015/11/stored-xss-in-google-docs-bug-bounty.html) by Harry M Gertos
* [Stored XSS on developer.uber.com via admin account compromise in Uber](https://hackerone.com/reports/152067) by James Kettle (albinowax)
* [Yahoo Mail stored XSS](https://klikki.fi/adv/yahoo.html) by Klikki Oy
* [Abusing XSS Filter: One ^ leads to XSS(CVE-2016-3212)](http://mksben.l0.cm/2016/07/xxn-caret.html) by Masato Kinugawa
* [Youtube XSS](https://labs.detectify.com/2015/06/06/google-xss-turkey/) by fransrosen
* [Best Google XSS again](https://sites.google.com/site/bughunteruniversity/best-reports/openredirectsthatmatter) – by Krzysztof Kotowicz
* [IE & Edge URL parsin Problem](https://labs.detectify.com/2016/10/24/combining-host-header-injection-and-lax-host-parsing-serving-malicious-data/) – by detectify
* [Google XSS subdomain Clickjacking](http://sasi2103.blogspot.sg/2016/09/combination-of-techniques-lead-to-dom.html)

#### SQL Injection

SQL injection, is a common attack vector that uses malicious SQL code for backend database manipulation to access information that was not intended to be displayed.

**References to read:**\
\
\><https://www.owasp.org/index.php/SQL_Injection>\
\><https://portswigger.net/web-security/sql-injection>\
\><https://www.imperva.com/learn/application-security/sql-injection-sqli/>\
\><https://www.w3schools.com/sql/sql_injection.asp>

**Some POCs:**

* [SQL Injection Vulnerability nutanix](https://blog.securitybreached.org/2018/09/08/sqli-bootcampnutanix-com-bug-bounty-poc/) by Muhammad Khizer Javed
* [Yahoo – Root Access SQL Injection – tw.yahoo.com](http://buer.haus/2015/01/15/yahoo-root-access-sql-injection-tw-yahoo-com/) by Brett Buerhaus
* [Multiple vulnerabilities in a WordPress plugin at drive.uber.com](https://hackerone.com/reports/135288) by Abood Nour (syndr0me)
* [GitHub Enterprise SQL Injection](http://blog.orange.tw/2017/01/bug-bounty-github-enterprise-sql-injection.html) by Orange
* [SQL injection in WordPress Plugin Huge IT Video Gallery in Uber](https://hackerone.com/reports/125932) by glc
* [SQL Injection on sctrack.email.uber.com.cn](https://hackerone.com/reports/150156) by Orange Tsai

#### Remote Code Execution (RCE)

In RCE an attacker’s able to execute arbitrary commands or code on a target machine or in a target Machine.

**References to read:**\
\
\><https://www.netsparker.com/blog/web-security/remote-code-evaluation-execution/>\
\><https://en.wikipedia.org/wiki/Arbitrary_code_execution>

**Some POCs:**

* [How we broke PHP, hacked Pornhub and earned $20,000](https://www.evonide.com/how-we-broke-php-hacked-pornhub-and-earned-20000-dollar/) by Ruslan Habalov
  * *Alert*, God-like Write-up, make sure you know what is ROP before clicking, which I don’t =(
* [RCE deal to tricky file upload](https://www.secgeek.net/bookfresh-vulnerability/) by secgeek
* [WordPress SOME bug in plupload.flash.swf leading to RCE in Automatic](https://hackerone.com/reports/134738) by Cure53 (cure53)
* [Read-Only user can execute arbitraty shell commands on AirOS](https://hackerone.com/reports/128750) by 93c08539 (93c08539)
* [Remote Code Execution by impage upload!](https://hackerone.com/reports/158148) by Raz0r (ru\_raz0r)
* [Popping a shell on the Oculus developer portal](https://bitquark.co.uk/blog/2014/08/31/popping_a_shell_on_the_oculus_developer_portal) by Bitquark
* [Crazy! PornHub RCE AGAIN!!! How I hacked Pornhub for fun and profit – 10,000$](https://5haked.blogspot.sg/) by 5haked
* [PayPal Node.js code injection (RCE)](http://artsploit.blogspot.hk/2016/08/pprce2.html) by Michael Stepankin
* [eBay PHP Parameter Injection lead to RCE](http://secalert.net/#ebay-rce-ccs)
* [Yahoo Acqusition RCE](https://seanmelia.files.wordpress.com/2016/02/yahoo-remote-code-execution-cms1.pdf)
* [Command Injection Vulnerability in Hostinger](http://elladodelnovato.blogspot.hk/2017/02/command-injection-vulnerability-in.html?spref=tw\&m=1) by @alberto\_\_segura
* [RCE in Airbnb by Ruby Injection](http://buer.haus/2017/03/13/airbnb-ruby-on-rails-string-interpolation-led-to-remote-code-execution/) by buerRCE
* [RCE in Imgur by Command Line](https://hackerone.com/reports/212696)
* [RCE in git.imgur.com by abusing out dated software](https://hackerone.com/reports/206227) by Orange Tsai
* [RCE in Disclosure](https://hackerone.com/reports/213558)
* [Remote Code Execution by struct2 Yahoo Server](https://medium.com/@th3g3nt3l/how-i-got-5500-from-yahoo-for-rce-92fffb7145e6)
* [Command Injection in Yahoo Acquisition](http://samcurry.net/how-i-couldve-taken-over-the-production-server-of-a-yahoo-acquisition-through-command-injection/)
* [Paypal RCE](http://blog.pentestbegins.com/2017/07/21/hacking-into-paypal-server-remote-code-execution-2017/)
* [$50k RCE in JetBrains IDE](http://blog.saynotolinux.com/blog/2016/08/15/jetbrains-ide-remote-code-execution-and-local-file-disclosure-vulnerability-analysis/)
* [$20k RCE in Jenkin Instance](http://nahamsec.com/secure-your-jenkins-instance-or-hackers-will-force-you-to/) by @nahamsec
* [JDWP Remote Code Execution in PayPal](https://www.vulnerability-lab.com/get_content.php?id=1474) by Milan A Solanki
* [XXE in OpenID: one bug to rule them all, or how I found a Remote Code Execution flaw affecting Facebook’s servers](http://www.ubercomp.com/posts/2014-01-16_facebook_remote_code_execution) by Reginaldo Silva
* [How I Hacked Facebook, and Found Someone’s Backdoor Script](http://devco.re/blog/2016/04/21/how-I-hacked-facebook-and-found-someones-backdoor-script-eng-ver/) by Orange Tsai
* [How I Chained 4 vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE!](http://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html) by Orange Tsai
* [uber.com may RCE by Flask Jinja2 Template Injection](https://hackerone.com/reports/125980) by Orange Tsai
* [Yahoo Bug Bounty – \*.login.yahoo.com Remote Code Execution](http://blog.orange.tw/2013/11/yahoo-bug-bounty-part-2-loginyahoocom.html) by Orange Tsai (in Chinese)
* [Google App Engine RCE](https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce) by Ezequiel Pereira
* [Exploiting ImageMagick to get RCE on Polyvore (Yahoo Acquisition)](http://nahamsec.com/exploiting-imagemagick-on-yahoo/) by NaHamSec
* [Exploting ImageMagick to get RCE on HackerOne](https://hackerone.com/reports/135072) by c666a323be94d57
* [Trello bug bounty: Access server’s files using ImageTragick](https://hethical.io/trello-bug-bounty-access-servers-files-using-imagetragick/) by Florian Courtial
* [40k fb rce](https://github.com/ngalongc/bug-bounty-reference/blob/master/4lemon.ru/2017-01-17_facebook_imagetragick_remote_code_execution.html)
* [Yahoo Bleed 1](https://scarybeastsecurity.blogspot.hk/2017/05/bleed-continues-18-byte-file-14k-bounty.html)
* [Yahoo Bleed 2](https://scarybeastsecurity.blogspot.hk/2017/05/bleed-more-powerful-dumping-yahoo.html)
* [Microsoft Apache Solr RCE Velocity Template](https://blog.securitybreached.org/2020/03/31/microsoft-rce-bugbounty/) By Muhammad Khizer Javed

#### Insecure Direct Object Reference (IDOR)

In IDOR an application provides **direct** access to **objects** based on the user-supplied input. As a result of this vulnerability, attackers can bypass authorization and access resources in the system directly.

**References to read:**\
\
\><https://www.bugcrowd.com/blog/how-to-find-idor-insecure-direct-object-reference-vulnerabilities-for-large-bounty-rewards/>\
\><https://www.owasp.org/index.php/Testing_for_Insecure_Direct_Object_References_(OTG-AUTHZ-004)>\
\><https://www.secjuice.com/idor-insecure-direct-object-reference-definition/>

**Some POCs:**

* [DOB disclosed using “Facebook Graph API Reverse Engineering”](https://medium.com/@rajsek/my-3rd-facebook-bounty-hat-trick-chennai-tcs-er-name-listed-in-facebook-hall-of-fame-47f57f2a4f71#.9gbtbv42q) by Raja Sekar Durairaj
* [Change the description of a video without publish\_actions permission in Facebook](http://philippeharewood.com/change-the-description-of-a-video-without-publish_actions-permission/) by phwd
* [Response To Request Injection (RTRI)](https://www.bugbountyhq.com/front/latestnews/dWRWR0thQ2ZWOFN5cTE1cXQrSFZmUT09/) by ?, be honest, thanks to this article, I have found quite a few bugs because of using his method, respect to the author!
* [Leak of all project names and all user names , even across applications on Harvest](https://hackerone.com/reports/152696) by Edgar Boda-Majer (eboda)
* [Changing paymentProfileUuid when booking a trip allows free rides at Uber](https://hackerone.com/reports/162809) by Matthew Temmy (temmyscript)
* [View private tweet](https://hackerone.com/reports/174721)
* [Uber Enum UUID](http://www.rohk.xyz/uber-uuid/)
* [Hacking Facebook’s Legacy API, Part 1: Making Calls on Behalf of Any User](http://stephensclafani.com/2014/07/08/hacking-facebooks-legacy-api-part-1-making-calls-on-behalf-of-any-user/) by Stephen Sclafani
* [Hacking Facebook’s Legacy API, Part 2: Stealing User Sessions](http://stephensclafani.com/2014/07/29/hacking-facebooks-legacy-api-part-2-stealing-user-sessions/) by Stephen Sclafani
* [Delete FB Video](https://danmelamed.blogspot.hk/2017/01/facebook-vulnerability-delete-any-video.html)
* [Delete FB Video](https://pranavhivarekar.in/2016/06/23/facebooks-bug-delete-any-video-from-facebook/)
* [Facebook Page Takeover by Manipulating the Parameter](http://arunsureshkumar.me/index.php/2016/09/16/facebook-page-takeover-zero-day-vulnerability/) by arunsureshkumar
* [Viewing private Airbnb Messages](http://buer.haus/2017/03/31/airbnb-web-to-app-phone-notification-idor-to-view-everyones-airbnb-messages/)
* [IDOR tweet as any user](http://kedrisec.com/twitter-publish-by-any-user/) by kedrisec
* [Classic IDOR endpoints in Twitter](http://www.anandpraka.sh/2017/05/how-i-took-control-of-your-twitter.html)
* [Mass Assignment, Response to Request Injection, Admin Escalation](https://seanmelia.wordpress.com/2017/06/01/privilege-escalation-in-a-django-application/) by sean
* [Trello bug bounty: The websocket receives data when a public company creates a team visible board](https://hethical.io/trello-bug-bounty-the-websocket-receives-data-when-a-public-company-creates-a-team-visible-board/) by Florian Courtial
* [Trello bug bounty: Payments informations are sent to the webhook when a team changes its visibility](https://hethical.io/trello-bug-bounty-payments-informations-are-sent-to-the-webhook-when-a-team-changes-its-visibility/) by Florian Courtial
* [Change any user’s password in Uber](https://hackerone.com/reports/143717) by mongo
* [Vulnerability in Youtube allowed moving comments from any video to another](https://www.secgeek.net/youtube-vulnerability/) by secgeek
  * It’s *Google* Vulnerability, so it’s worth reading, as generally it is more difficult to find Google vulnerability
* [Twitter Vulnerability Could Credit Cards from Any Twitter Account](https://www.secgeek.net/twitter-vulnerability/) by secgeek
* [One Vulnerability allowed deleting comments of any user in all Yahoo sites](https://www.secgeek.net/yahoo-comments-vulnerability/) by secgeek
* [Microsoft-careers.com Remote Password Reset](http://yasserali.com/microsoft-careers-com-remote-password-reset/) by Yaaser Ali
* [How I could change your eBay password](http://yasserali.com/how-i-could-change-your-ebay-password/) by Yaaser Ali
* [Duo Security Researchers Uncover Bypass of PayPal’s Two-Factor Authentication](https://duo.com/blog/duo-security-researchers-uncover-bypass-of-paypal-s-two-factor-authentication) by Duo Labs
* [Hacking Facebook.com/thanks Posting on behalf of your friends! ](http://www.anandpraka.sh/2014/11/hacking-facebookcomthanks-posting-on.html)by Anand Prakash
* [How I got access to millions of \[redacted\] accounts](https://bitquark.co.uk/blog/2016/02/09/how_i_got_access_to_millions_of_redacted_accounts)
* [All Vimeo Private videos disclosure via Authorization Bypass with Excellent Technical Description](https://hackerone.com/reports/137502) by Enguerran Gillier (opnsec)
* [Urgent: attacker can access every data source on Bime](https://hackerone.com/reports/149907) by Jobert Abma (jobert)
* [Downloading password protected / restricted videos on Vimeo](https://hackerone.com/reports/145467) by Gazza (gazza)
* [Get organization info base on uuid in Uber](https://hackerone.com/reports/151465) by Severus (severus)
* [How I Exposed your Primary Facebook Email Address (Bug worth $4500)](http://roy-castillo.blogspot.hk/2013/07/how-i-exposed-your-primary-facebook.html) by Roy Castillo

#### Unrestricted File Upload

As in name unrestricted file upload allows user to upload malicious file to a system to further exploit to for Code execution

**References to read:**\
\
\><https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/unrestricted-file-upload/>\
\><https://www.owasp.org/index.php/Unrestricted_File_Upload>\
\><https://www.hackingarticles.in/5-ways-file-upload-vulnerability-exploitation/>

**Some POCs:**

* [File Upload XSS in image uploading of App in mopub](https://hackerone.com/reports/97672) by vijay kumar
* [RCE deal to tricky file upload](https://www.secgeek.net/bookfresh-vulnerability/) by secgeek
* [File Upload XSS in image uploading of App in mopub in Twitter](https://hackerone.com/reports/97672) by vijay kumar (vijay\_kumar1110)
* [Unrestricted File Upload to RCE](https://blog.securitybreached.org/2017/12/19/unrestricted-file-upload-to-rce-bug-bounty-poc/) by Muhammad Khizer Javed

#### XML External Entity Attack (XXE)

XXE is an attack against an application that parses XML input. This attack occurs when XML input containing a reference to an external entity is processed by a weakly configured XML parser.

**References to read:**\
\
\><https://portswigger.net/web-security/xxe>\
\><https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Prevention_Cheat_Sheet>\
\><https://phonexicum.github.io/infosec/xxe.html>

**Some POCs:**

* [XXE through SAML](https://seanmelia.files.wordpress.com/2016/01/out-of-band-xml-external-entity-injection-via-saml-redacted.pdf)
* [XXE in Uber to read local files](https://httpsonly.blogspot.hk/2017/01/0day-writeup-xxe-in-ubercom.html)
* [XXE by SVG in community.lithium.com](http://esoln.net/Research/2017/03/30/xxe-in-lithium-community-platform/)
* [How we got read access on Google’s production servers](https://blog.detectify.com/2014/04/11/how-we-got-read-access-on-googles-production-servers/) by detectify
* [Blind OOB XXE At UBER 26+ Domains Hacked](http://nerdint.blogspot.hk/2016/08/blind-oob-xxe-at-uber-26-domains-hacked.html) by Raghav Bisht

### Local File Inclusion (LFI)

The File Inclusion vulnerability allows an attacker to include a file, usually exploiting a “dynamic file inclusion” mechanisms implemented in the target application. The vulnerability occurs due to the use of user-supplied input without proper validation.

**References to read:**\
\
\><https://www.owasp.org/index.php/Testing_for_Local_File_Inclusion>\
\><https://www.netsparker.com/blog/web-security/local-file-inclusion-vulnerability/>\
\><https://medium.com/@Aptive/local-file-inclusion-lfi-web-application-penetration-testing-cc9dc8dd3601>

**Some POCs:**

* [SSRF to LFI](https://seanmelia.wordpress.com/2015/12/23/various-server-side-request-forgery-issues/)
* [Disclosure Local File Inclusion by Symlink](https://hackerone.com/reports/213558)
* [Facebook Symlink Local File Inclusion](http://josipfranjkovic.blogspot.hk/2014/12/reading-local-files-from-facebooks.html)
* [Gitlab Symlink Local File Inclusion](https://hackerone.com/reports/158330)
* [Gitlab Symlink Local File Inclusion Part II](https://hackerone.com/reports/178152)
* [Multiple Company LFI](http://panchocosil.blogspot.sg/2017/05/one-cloud-based-local-file-inclusion.html)
* [LFI by video conversion, excited about this trick!](https://hackerone.com/reports/226756)

#### Subdomain Takeover

A process of registering a non-existing domain name to gain control over another domain.

**References to read:**\
\
\><https://blog.securitybreached.org/2017/10/11/what-is-subdomain-takeover-vulnerability/>\
\><https://0xpatrik.com/subdomain-takeover-basics/>\
\><https://github.com/EdOverflow/can-i-take-over-xyz>

**Some POCs:**

* [Hijacking tons of Instapage expired users Domains & Subdomains](http://www.geekboy.ninja/blog/hijacking-tons-of-instapage-expired-users-domains-subdomains/) by geekboy
* [Reading Emails in Uber Subdomains](https://hackerone.com/reports/156536)
* [Slack Bug Journey](http://secalert.net/slack-security-bug-bounty.html) – by David Vieira-Kurz
* [Subdomain takeover and chain it to perform authentication bypass](https://www.arneswinnen.net/2017/06/authentication-bypass-on-ubers-sso-via-subdomain-takeover/) by Arne Swinnen
* [UBER Wildcard Subdomain Takeover ](https://blog.securitybreached.org/2017/11/20/uber-wildcard-subdomain-takeover/)by Muhammad Khizer Javed
* [Lamborghini Subdomain Takeover Through Expired Cloudfront Distribution](https://blog.securitybreached.org/2017/10/10/subdomain-takeover-lamborghini-hacked/) by Muhammad Khizer Javed
* [Subdomain Takeover via Unsecured S3 Bucket Connected to the Website](https://blog.securitybreached.org/2018/09/24/subdomain-takeover-via-unsecured-s3-bucket/) by Muhammad khizer Javed

#### Server Side Request Forgery (SSRF)

by SSRF the attacker can abuse functionality on the server to read or update internal resources.

**References to read:**\
\
\><https://medium.com/@madrobot/ssrf-server-side-request-forgery-types-and-ways-to-exploit-it-part-1-29d034c27978>\
\><https://www.owasp.org/index.php/Server_Side_Request_Forgery>\
\><https://www.netsparker.com/blog/web-security/server-side-request-forgery-vulnerability-ssrf/>\
\><https://blog.detectify.com/2019/01/10/what-is-server-side-request-forgery-ssrf/>

**Some POCs:**

* [ESEA Server-Side Request Forgery and Querying AWS Meta Data](http://buer.haus/2016/04/18/esea-server-side-request-forgery-and-querying-aws-meta-data/) by Brett Buerhaus
* [SSRF to pivot internal network](https://seanmelia.files.wordpress.com/2016/07/ssrf-to-pivot-internal-networks.pdf)
* [SSRF to LFI](https://seanmelia.wordpress.com/2015/12/23/various-server-side-request-forgery-issues/)
* [SSRF to query google internal server](https://www.rcesecurity.com/2017/03/ok-google-give-me-all-your-internal-dns-information/)
* [SSRF by using third party Open redirect](https://buer.haus/2017/03/09/airbnb-chaining-third-party-open-redirect-into-server-side-request-forgery-ssrf-via-liveperson-chat/) by Brett BUERHAUS
* [SSRF tips from BugBountyHQ of Images](https://twitter.com/BugBountyHQ/status/868242771617792000)
* [SSRF to RCE](http://www.kernelpicnic.net/2017/05/29/Pivoting-from-blind-SSRF-to-RCE-with-Hashicorp-Consul.html)
* [XXE at Twitter](https://hackerone.com/reports/248668)
* [Blog post: Cracking the Lens: Targeting HTTP’s Hidden Attack-Surface](http://blog.portswigger.net/2017/07/cracking-lens-targeting-https-hidden.html)

Some Other Interesting POCs:\
\
A huge collection at <https://github.com/djadmin/awesome-bug-bounty>

**Deserialization**

* [Java Deserialization in manager.paypal.com](http://artsploit.blogspot.hk/2016/01/paypal-rce.html) by Michael Stepankin
* [Instagram’s Million Dollar Bug](http://www.exfiltrated.com/research-Instagram-RCE.php) by Wesley Wineberg
* [(Ruby Cookie Deserialization RCE on facebooksearch.algolia.com](https://hackerone.com/reports/134321) by Michiel Prins (michiel)
* [Java deserialization](https://seanmelia.wordpress.com/2016/07/22/exploiting-java-deserialization-via-jboss/) by meals

#### Race Condition

* [Race conditions on Facebook, DigitalOcean and others (fixed)](http://josipfranjkovic.blogspot.hk/2015/04/race-conditions-on-facebook.html) by Josip Franjković
* [Race Conditions in Popular reports feature in HackerOne](https://hackerone.com/reports/146845) by Fábio Pires (shmoo)

#### Business Logic Flaw

* [Facebook simple technical hack to see the timeline](http://ashishpadelkar.com/index.php/2015/09/23/facebook-simple-technical-bug-worth-7500/) by Ashish Padelkar
* [How I Could Steal Money from Instagram, Google and Microsoft](https://www.arneswinnen.net/2016/07/how-i-could-steal-money-from-instagram-google-and-microsoft/) by Arne Swinnen
* [How I could have removed all your Facebook notes](http://www.anandpraka.sh/2015/12/summary-this-blog-post-is-about.html)
* [Facebook – bypass ads account’s roles vulnerability 2015](http://blog.darabi.me/2015/03/facebook-bypass-ads-account-roles.html) by POUYA DARABI
* [Uber Ride for Free](http://www.anandpraka.sh/2017/03/how-anyone-could-have-used-uber-to-ride.html) by anand praka
* [Uber Eat for Free](https://t.co/MCOM7j2dWX) by

#### Authentication Bypass

* [OneLogin authentication bypass on WordPress sites via XMLRPC in Uber](https://hackerone.com/reports/138869) by Jouko Pynnönen (jouko)
* [2FA PayPal Bypass](https://henryhoggard.co.uk/blog/Paypal-2FA-Bypass) by henryhoggard
* [SAML Bug in Github worth 15000](http://www.economyofmechanism.com/github-saml.html)
* [Authentication bypass on Airbnb via OAuth tokens theft](https://www.arneswinnen.net/2017/06/authentication-bypass-on-airbnb-via-oauth-tokens-theft/)
* [Uber Login CSRF + Open Redirect -> Account Takeover at Uber](http://ngailong.com/uber-login-csrf-open-redirect-account-takeover/)
* \[<http://c0rni3sm.blogspot.hk/2017/08/accidentally-typo-to-bypass.html?m=1](Administrative> Panel Access) by c0rni3sm
* [Uber Bug Bounty: Gaining Access To An Internal Chat System](http://blog.mish.re/index.php/2017/09/06/uber-bug-bounty-gaining-access-to-an-internal-chat-system/) by mishre
* [User Account Takeover via Signup](https://blog.securitybreached.org/2020/01/22/user-account-takeover-via-signup-feature-bug-bounty-poc/) by Muhammad Khizer Javed

#### HTTP Header Injection

* [Twitter Overflow Trilogy in Twitter](https://blog.innerht.ml/overflow-trilogy/) by filedescriptor
* [Twitter CRLF](https://blog.innerht.ml/twitter-crlf-injection/) by filedescriptor
* [Adblock Plus and (a little) more in Google](https://adblockplus.org/blog/finding-security-issues-in-a-website-or-how-to-get-paid-by-google)
* [$10k host header](https://sites.google.com/site/testsitehacking/10k-host-header) by Ezequiel Pereira

### Email Related

* [This domain is my domain – G Suite A record vulnerability](http://blog.pentestnepal.tech/post/156959105292/this-domain-is-my-domain-g-suite-a-record)
* [I got emails – G Suite Vulnerability](http://blog.pentestnepal.tech/post/156707088037/i-got-emails-g-suite-vulnerability)
* [How I snooped into your private Slack messages \[Slack Bug bounty worth $2,500\]](http://blog.pentestnepal.tech/post/150381068912/how-i-snooped-into-your-private-slack-messages)
* [Reading Uber’s Internal Emails \[Uber Bug Bounty report worth $10,000\]](http://blog.pentestnepal.tech/post/149985438982/reading-ubers-internal-emails-uber-bug-bounty)
* [Slack Yammer Takeover by using TicketTrick](https://medium.com/@intideceukelaire/how-i-hacked-hundreds-of-companies-through-their-helpdesk-b7680ddc2d4c) by Inti De Ceukelaire
* [How I could have mass uploaded from every Flickr account!](https://ret2got.wordpress.com/2017/10/05/how-i-could-have-mass-uploaded-from-every-flickr-account/)

### Money Stealing

* [Round error issue -> produce money for free in Bitcoin Site](https://hackerone.com/reports/176461) by 4lemon

### Others

* [Payment Flaw in Yahoo](http://ngailong.com/abusing-multistage-logic-flaw-to-buy-anything-for-free-at-hk-deals-yahoo-com/)
* [Bypassing Google Email Domain Check to Deliver Spam Email on Google’s Behalf](http://ngailong.com/bypassing-google-email-domain-check-to-deliver-spam-email-on-googles-behalf/)
* [When Server Side Request Forgery combine with Cross Site Scripting](http://ngailong.com/what-could-happen-when-server-side-request-forgery-combine-with-cross-site-scripting/)
* [SAML Pen Test Good Paper](http://research.aurainfosec.io/bypassing-saml20-SSO/)
* [A list of FB writeup collected by phwd](https://www.facebook.com/notes/phwd/facebook-bug-bounties/707217202701640) by phwd
* [NoSQL Injection](http://blog.websecurify.com/2014/08/hacking-nodejs-and-mongodb.html) by websecurify
* [CORS in action](http://www.geekboy.ninja/blog/exploiting-misconfigured-cors-cross-origin-resource-sharing/)
* [CORS in Fb messenger](http://www.cynet.com/blog-facebook-originull/)
* [Web App Methodologies](https://blog.zsec.uk/ltr101-method-to-madness/)
* [XXE Cheatsheet](https://www.silentrobots.com/blog/2015/12/14/xe-cheatsheet-update/)
* [The road to hell is paved with SAML Assertions, Microsoft Vulnerability](http://www.economyofmechanism.com/office365-authbypass.html#office365-authbypass)
* [Study this if you like to learn Mongo SQL Injection](https://cirw.in/blog/hash-injection) by cirw
* [Mongo DB Injection again](http://blog.websecurify.com/2014/08/hacking-nodejs-and-mongodb.html) by websecrify
* [w3af speech about modern vulnerability](https://www.youtube.com/watch?v=GNU0_Uzyvl0) by w3af
* [Web cache attack that lead to account takeover](http://omergil.blogspot.co.il/2017/02/web-cache-deception-attack.html)
* [A talk to teach you how to use SAML Raider](https://www.usenix.org/conference/usenixsecurity12/technical-sessions/presentation/somorovsky)
* [XSS Checklist when you have no idea how to exploit the bug](http://d3adend.org/xss/ghettoBypass)
* [CTF write up, Great for Bug Bounty](https://ctftime.org/writeups?tags=web200\&hidden-tags=web%2cweb100%2cweb200)
* [It turns out every site uses jquery mobile with Open Redirect is vulnerable to XSS](http://sirdarckcat.blogspot.com/2017/02/unpatched-0day-jquery-mobile-xss.html) by sirdarckcat
* [Bypass CSP by using google-analytics](https://hackerone.com/reports/199779)
* [Payment Issue with Paypal](https://hackerone.com/reports/219215)
* [Browser Exploitation in Chinese](http://paper.seebug.org/)
* [XSS bypass filter](https://t.co/0Kpzo52ycb)
* [Markup Impropose Sanitization](https://github.com/ChALkeR/notes/blob/master/Improper-markup-sanitization.md)
* [Breaking XSS mitigations via Script Gadget](https://www.blackhat.com/docs/us-17/thursday/us-17-Lekies-Dont-Trust-The-DOM-Bypassing-XSS-Mitigations-Via-Script-Gadgets.pdf)
* [X41 Browser Security White Paper](https://browser-security.x41-dsec.de/X41-Browser-Security-White-Paper.pdf)
* [Improper Input Validation | Add Custom Text and URLs In SMS send by Snapchat](https://blog.securitybreached.org/2020/01/26/improper-input-validation-add-custom-text-and-urls-in-sms-send-by-snapchat-bug-bounty-poc/) By Muhammad Khizer Javed
* [Exploiting Insecure Firebase Database!](https://blog.securitybreached.org/2020/02/04/exploiting-insecure-firebase-database-bugbounty/) By Muhammad Khizer Javed
* [Using Inspect Element to Bypass Security restrictions](https://blog.securitybreached.org/2020/06/30/using-inspect-element-to-bypass-security-restrictions-bug-bounty-poc/) By Muhammad Khizer Javed

### Information Disclosure

* [Hacking SMS API Service Provider of a Company |Android App Static Security Analysis](https://blog.securitybreached.org/2020/02/19/hacking-sms-api-service-provider-of-a-company-android-app-static-security-analysis-bug-bounty-poc/) By Muhammad Khizer Javed
* [Vine User Private information disclosure](https://bugbountypoc.com/vine-user-private-information-disclosure/)
* [The feature works as intended, but what’s in the source?](https://medium.com/@zseano/the-feature-works-as-intended-but-whats-in-the-source-d29f9401bcf6) By zseano
* [How Our Co-Founder Earned $10.6K in just 10 Hours](https://medium.com/@tensecure/how-our-co-founder-earned-10-6k-in-just-10-hours-ea323e2f06b1) By Tensecure Systems

So these were some common issues that one should get a grip on and learn more and more about Following is a list of some Attacks Topics that You Should do some research and read the Blogs/reports on them.

* [**SQL Injection Attack**](http://securityidiots.com/Web-Pentest/SQL-Injection)
* [**Hibernate Query Language Injection**](https://medium.com/@SecurityBender/exploiting-a-hql-injection-895f93d06718)
* [**Direct OS Code Injection**](http://www.hackingarticles.in/beginner-guide-os-command-injection/)
* [**XML Entity Injection**](https://depthsecurity.com/blog/exploitation-xml-external-entity-xxe-injection)
* [**Broken Authentication and Session Management**](https://hdivsecurity.com/owasp-broken-authentication-and-session-management)
* [**Cross-Site Scripting (XSS)**](https://brutelogic.com.br/blog/)
* [**Insecure Direct Object References**](https://www.bugcrowd.com/how-to-find-idor-insecure-direct-object-reference-vulnerabilities-for-large-bounty-rewards/)
* [**Missing Function Level Access Control**](https://blog.detectify.com/2016/07/13/owasp-top-10-missing-function-level-access-control-7/)
* [**Cross-Site Request Forgery (CSRF)**](https://www.incapsula.com/web-application-security/csrf-cross-site-request-forgery.html)
* [**Using Components with Known Vulnerabilities**](https://www.owasp.org/index.php/Top_10-2017_A9-Using_Components_with_Known_Vulnerabilities)
* [**Unvalidated Redirects and Forwards**](https://www.tutorialspoint.com/security_testing/unvalidated_redirects_and_forwards.htm)
* [**ClickJacking Attacks**](https://www.forcepoint.com/cyber-edu/clickjacking)
* [**DNS Cache Poisoning**](https://www.networkworld.com/article/2277316/tech-primers/tech-primers-how-dns-cache-poisoning-works.html)
* [**Symlinking**](https://prezi.com/0pxge8u_4iov/symlinking-an-insider-attack/)
* [**Remote Code Execution Attacks**](https://hackernoon.com/exploiting-electron-rce-in-exodus-wallet-d9e6db13c374)
* [**Remote File inclusion**](https://www.owasp.org/index.php/Testing_for_Remote_File_Inclusion)
* [**Local file inclusion**](https://www.owasp.org/index.php/Testing_for_Local_File_Inclusion)
* [**Denial oF Service Attack**](https://www.cloudflare.com/learning/ddos/glossary/denial-of-service/)
* [**PHPwn**](https://samy.pl/phpwn/)
* [**NAT Pinning**](https://github.com/allodoxaphobia/natpinning/wiki/What-is-NAT-pinning)
* [**XSHM**](https://www.owasp.org/index.php/Cross_Site_History_Manipulation_\(XSHM\))
* [**HTTP Parameter Pollution**](https://www.owasp.org/index.php/Testing_for_HTTP_Parameter_pollution_\(OTG-INPVAL-004\))
* [**Tabnabbing**](https://www.owasp.org/index.php/Reverse_Tabnabbing)
* [**LDAP injection**](https://www.owasp.org/index.php/LDAP_Injection_Prevention_Cheat_Sheet)
* [**Log Injection**](https://www.owasp.org/index.php/Log_Injection)
* [**Path Traversal**](https://portswigger.net/web-security/file-path-traversal)
* [**Reflected DOM Injection**](https://www.owasp.org/index.php/Reflected_DOM_Injection)
* [**Repudiation Attack**](http://www.ids-sax2.com/Knowledgebase/NetworkSecurity/Repudiation-Attack.htm)
* [**Resource Injection**](https://www.owasp.org/index.php/Resource_Injection)
* [**Server-Side Includes (SSI) Injection**](https://portswigger.net/kb/issues/00101100_ssi-injection)
* [**Session fixation**](https://www.owasp.org/index.php/Session_fixation)
* [**Session hijacking attack**](https://www.owasp.org/index.php/Session_hijacking_attack)
* [**Session Prediction**](https://www.owasp.org/index.php/Session_Prediction)
* [**Setting Manipulation**](https://www.owasp.org/index.php/Setting_Manipulation)
* [**Special Element Injection**](https://www.owasp.org/index.php/Special_Element_Injection)
* [**SMTP injection**](https://www.owasp.org/index.php/Testing_for_IMAP/SMTP_Injection_\(OTG-INPVAL-011\))
* [**Traffic flood**](https://www.owasp.org/index.php/Traffic_flood)
* [**XPATH Injection**](http://projects.webappsec.org/w/page/13247005/XPath%20Injection)\
  \
  **You’ll find a lot more write-ups at** [h](https://pentester.land/list-of-bug-bounty-writeups.html)[ttps://pentester.land/list-of-bug-bounty-writeups.html](https://pentester.land/list-of-bug-bounty-writeups.html)

#### **BLOGS!** You should read.

Lets get towards Blogs! There are plenty of blogs Shared by Hackers on daily basis that you can read to learn more and more…

* <https://blog.it-securityguard.com/>
* [https://blog.innerht.ml/](https://l.facebook.com/l.php?u=https%3A%2F%2Fblog.innerht.ml%2F\&h=ATOHxyKfWaJCxgH9yN0wnleX3WusTZgN9hspDVhTSnFGE8wz1XrfIS4hUZgdJ-x-34VvTe4-L7EPnDXJQC0PhhjoTas2vThQkAe-iv2E8ElPZOQpWSAUtJsfvxziGNiNzvANaoJ4JoNC)
* [http://brutelogic.com.br/blog/](https://l.facebook.com/l.php?u=http%3A%2F%2Fbrutelogic.com.br%2Fblog%2F\&h=ATN21fxHYwdh7HbPmLepHzsv_pXXiNTTFzcmfx9X0h_qNwzR5N158i44KtA-Do2Q1KNzEYtCkGf1PJKllXtsxBeiakBkfAmk1n5rNml76sxzOrRtpfsOpsDtSpnfplriHv7KlMlsxGnH)
* [https://klikki.fi/](https://l.facebook.com/l.php?u=https%3A%2F%2Fklikki.fi%2F\&h=ATOQsJ2nDeXdhzNATVh7GkH5WWLKDIU4vh0-dN1zMqroUBkby7AY1sSlJyjqU_c9HuN9kr3AJqVw72F3hClLJ-9pgWgzvywgZHWfu4Rpj9OSOiYxWWsRirEMDSecnpNeHxZBMBAebc_C)
* [http://philippeharewood.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fphilippeharewood.com%2F\&h=ATPJqZPSTY5FhRzRJ1tJTUyRf1deUF2vwE0KpG4ejz9obOu_U4s7MB58xkLROd7kYMahhLOgrwqiqXomyNDb18gQRDLyD95lsllPsVlN6TdIcskLR9ayoxewczZWDzFuiA44Rigo414f)
* <https://seanmelia.wordpress.com/>
* [https://respectxss.blogspot.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Frespectxss.blogspot.com%2F\&h=ATMiSw21fW4i8qvZZ68mU6mqlm9CUr6EO1HbcNPUmHT0JwKmLFDEGSomqRuwSlaBxIJZ8-PXAdjfnq9lIf1qAE0RCFTh0AB7n-4k6Yqo-mEW5hbpKUrPX7wt0d9uAzqOSR8VG4_yurSv)
* [https://www.gracefulsecurity.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.gracefulsecurity.com%2F\&h=ATOhJCPG1dMebUvbcH6jAR2LzmwmK3QkiM-NDl1IbEK_ZUuI4pyUTO-06X-Q1U1JisxzrPgNyPuEgwxcRwkmqD5F2u8q1g1CMk_OOB8x2nYxlJKBBFEWfiOP4XiqocyjCascDJS5LyH5)
* [https://whitton.io/](https://l.facebook.com/l.php?u=https%3A%2F%2Fwhitton.io%2F\&h=ATNUBqvaI0a5JNs8G4HsN1kGzmw1uH11641gW5XxX8BHsXE-zZBZDq7npGBGbzdxvWTkCvgwh0JsM3hwcRzrDGFcE2r9F2g7iABWxq30vjHfIlzF30-tBh6F5oneibm1yojrXw-o14ivG6iWnSQJrJCQ4w)
* [https://tisiphone.net/](https://l.facebook.com/l.php?u=https%3A%2F%2Ftisiphone.net%2F\&h=ATMe6ZTd40i6EW8GcLnVbRXAmF1RAFU-9mGHB66w3jCx8s2NexZ4EKOPnZqvElUsSOBOrt8izVXeo9mlNzFGUve9FIw_GDC13b6nCKALRRVPvJuKHEm2FK_uVF8trRoa_r8vl0mmJtRF)
* [http://archive.nahamsec.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Farchive.nahamsec.com%2F\&h=ATMyMRXcw8BwQm20vo8bJ3E0KosnGD8nKu6FebP3uXwBS1_-HK1x4MelVeahKvhgdnHVxMPoYHRtRoS-fTySgYqPw13T2Re9Y4eX2R2d6N4pcmMRjEIXIa6ujL-hmYIjBMZ1cDpfJoEp)
* <https://www.hackerscreed.org/>
* [http://danlec.com/blog](https://l.facebook.com/l.php?u=http%3A%2F%2Fdanlec.com%2Fblog\&h=ATMxa8PbuZYrFcPB8bq0taLmCk9aF_SHXFx1GaGfoUMV-zXeVOegYMVyKWGzzj8VHXQWkYlfMSgAf1uz42v7ztz_8Maz893ao3dSFWSu72NQUos1kz99-DWaY6nyjHmffXOltRz_BIyZ)
* [https://wehackpeople.tumblr.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fwehackpeople.tumblr.com%2F\&h=ATPwyeIU87vaUbxyEU7QMUdyBqa-iBAUmUhxQ71Ag-i3LSpAI1O6uwlfhAcBXu1dw-POatLvA2Hy0HHS9hG9SvmXu6XgkB6o6kFHIrGIexfw3eWFF2Fi75tczxZrnrGMe3bsmzGSJLZ-)
* [https://bitquark.co.uk/blog/](https://l.facebook.com/l.php?u=https%3A%2F%2Fbitquark.co.uk%2Fblog%2F\&h=ATON4r9z_6xZRxRow5iFhHGL_GJ8yEGu0tSvDYDBh7LzEdaJdKX6DmFG7E8CHyz5dr3b9QEEPHUNT0GA-JJnC4_GSMo8PODxGxXVCw0vaydMbpy8ZbgzvRPPcLmRH5ctLGkkZWmH-HFn)
* [https://www.arneswinnen.net/](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.arneswinnen.net%2F\&h=ATPb30sZlAQYlV1N2ML4662Tk7mGF4LgeH6QlKJfkz82xPgRrNW-FuHUPqmAPFCs_yaa2B7OS0PoebSXCruqPos-TZQEBICTxy-m5P7VtejMemLZLdJwyH-PxIs7AsMQOtGTr0Twlu7l)
* [http://bugbountypoc.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fbugbountypoc.com%2F\&h=ATNMw3Y7odmgJbL6AiL91T7y9y3OH_YpinsZ2lq6rHyjAHHdRCZt4dLLWbnQ08ramrrfGmnhbAjWZBsVht7cr04NkJKztAeWUG7tdtopXe763q0xMLGcUf4x4bEl61s5dRI8fcwhrAQh)
* [https://medium.com/@arbazhussain/](https://l.facebook.com/l.php?u=https%3A%2F%2Fmedium.com%2F%40arbazhussain%2F\&h=ATOjzVbsDI_RKYsf-bjydyCTUfR6AocBqo5sgud93BfuUspNK6bATKJArgBDSeCRJRMc1Pms-Pi7qwnq2LR2dlzUwcWoQ3mBK9yu_c0YjS2P0IapePZnIMxoPTLB1xE0LDC2Zww3khB3)
* [http://www.shawarkhan.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.shawarkhan.com%2F\&h=ATPEiqIEoD6PdB-KB4VVxmNfywoKMtwOPoPgqiBu3v04mSRca6K_Q0m97y6325MGk6qw9oJHWLQKZ18dkeHmEFR62kgG0xS6cJlseruJ1Hr2amhe0BMJWuIAXicB5u36IjE3qfihGLZe)
* [https://blog.detectify.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fblog.detectify.com%2F\&h=ATOvSluQwg6K1oXPCpTd8uCmiYswHKgx6V2Y4xCWmgVxWWbyIjS4Xmg1YwFwVyQQrocKmGw7WZiTm6LVsQeMtaEZRZYBkaOuZvTqy0iyVlnQuoZBICLghjGng1P-OvK1L-2R-PsxtLGm)
* [http://www.rafayhackingarticles.net/…](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.rafayhackingarticles.net%2F\&h=ATN2nw16NkLIq-zHUNmhDFrr7-LPp0DfGkLsPYp3SRVVAK6HQSD_w-v7RIQWXdT4NoJkVtD_CRPhdQOzKymQWpiygAsph5BsYUiAmmqVEp57nc1eFjKWxSjL55iQQuTT3jRqTimSjzE6)
* [https://forum.bugcrowd.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fforum.bugcrowd.com%2F\&h=ATNFdPZr5I0XutYC2_ybmAmYMbOM1jy0eCsNyKTvOaHXl8Rw_gGE4pxxOVTYqT5bHc9sOpdeGIQX536VZB1UJEuxLJ2MgnAYHAN9LDNU0jaFF3pelUHGF3Ie_d35L9D3_Y8lx_AaeeoM)
* [https://securitywall.co/](https://l.facebook.com/l.php?u=https%3A%2F%2Fsecuritywall.co%2F\&h=ATNMXE64dHpWRYVzkUkd2K1G--sTSd2mCpS4Nr-CHZ-yPpt2vdlgJzoD-3Ksch8-ZiBbX8pBV8qGt0cHrkeQ7hrvM-ZXSa13OAYCAgecVxQOEWWLNf5Sff8-c7J2KEnTC1CQzaN1hOrF)
* [https://www.hackerone.com/blog](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.hackerone.com%2Fblog\&h=ATNQC0BgXgi_-8u5M0bKnvK0mVk9SsEDCb1LbaLS5cgRW6bawSKvHJZSwOknowoWs5Qx5DRJ9oKNoGF2OkfhgVFDBGi1jYd2RCenmk7WZrU1toG_jWTdiBNFlQIVfa-LoHjiOqzTflnz)
* [http://www.securitytube.net/](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.securitytube.net%2F\&h=ATManyXe2-6w_Eh2wmmn6ahXVdCchmHL8um3rDYReuAFfqKMTOi1klt3irc_LGOXEogBNpiHpuNFlDsjtmcITGI4PhhyFX-WAAh7Vm1LZUXoy4n-6qWyGwU466TGejhPcNjteHF9nBPQ)
* [https://hackasia.org/](https://l.facebook.com/l.php?u=https%3A%2F%2Fhackasia.org%2F\&h=ATOUwJq851_jByLR-rvpADH0WCauyCOzyLkensdIeoH53ff-mz0qMcsHyXKCB5Jzvd987z45Pkd-lbGodQdnq8gaV1A3WthrKlkY_JLhq1PANGQvnQ03VQyzl3Kkap9myxBZ94gqVhwT)
* [http://www.gangte.net/](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.gangte.net%2F\&h=ATMltzqh3Nm3kv11nkFRB1BE2hOkuV31uXW40o_tfH8eQ_CcmFE6Cs0a1WG9tsVBA1LImwSOMKtRe8JwbrZ1iDyhkkHjZFsae5CJ7gZ7EvFOdMrPecL2qW9msbP10nQU9ECPaXxWZ_sx)
* [https://mukarramkhalid.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fmukarramkhalid.com%2F\&h=ATNefYNf4aFyyg1j7tn6OxPDx3fK1zlyFgO1wcYkXwFqg7TBuhRNCO0V0Eabo09lRu840Ef_-BJu7j9rrxJRPL7v98rIP3aAP3zRYAFWb1sDx4XU76lVXF7RGtZXOjawzrBKGn6Pw3wo)
* [https://securitytraning.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fsecuritytraning.com%2F\&h=ATOI0-e0AQvI-0uGZ31cSi-i0dlcFe8vndSOdwrnW9pGZyzGihuo2zKqiTAzWAQfIOk2cAF9zCq4Knrl4nEH8dGvlGUraENkO6-VmCJ-F05AcTMX2kTVeN2Efg_WW_E3xZ5y5tlnfWeL)
* [https://jubaeralnaziwhitehat.wordpress.com/…](https://l.facebook.com/l.php?u=https%3A%2F%2Fjubaeralnaziwhitehat.wordpress.com%2F\&h=ATMqnVaGxhu8DLn9lQ21IwP6FEYnZId1lqEzKQmMM6TVN17rZfxTSQByR9dBHxQ1GYRfMyl-RKQCaYSK4yjGnxi35lVm9fU-xZEpFXoubeYemVRWChqNwiiQMVy6ujAkagWBw26KXyu3)
* [http://hackaday.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fhackaday.com%2F\&h=ATNcWpOmzwM8FDzCyoccbCrOQ7Pz5A846OGFDBuOOCRS3oGQUBZwf8x3VAQe8nzSuON1bVYilgsU0Gk6PDXZMwt06mpiJmsYfx98_7-Hn0vQ_oGjzpKXNEvYpTTUyw1RuC5qhTzvkniw)
* [http://www.securityfocus.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.securityfocus.com%2F\&h=ATPBP8vy30QcHfTU7XrcjjJ4qq9RmyDGcpC92W0E5QhZSUAiAIkd4AVuclviAKRchXloxpwVWzyebKGufAWjcSIwePcM4qlNb4FcQLxB2-FX65x-RsxHR5TO2JhvK7AfIkk45yna1LWm0iYM0mGSIRfQ0w)
* [https://packetstormsecurity.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fpacketstormsecurity.com%2F\&h=ATNINYq9sAr_Ty2PCqJaCKnmTLSE7tSPudVwLoYaT6Y43OZit88CqOJsotTj0DyNZZ54Rhrd0wbTkco7BeFb5wZC9IvTSPXixNiWB9UlbC6HY3MVVkKTdZduWgVQsYGJ2UmgON5hoFLS)
* [http://www.blackhat.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.blackhat.com%2F\&h=ATO8ySZCRTmfmFWctsNPajHreUZA2liLTCT7_ZV9DwLGFhQoG9mHDQo-u4NeM9OlPFgTlDgduMuAy8Pcou-maW1mzK-W_pvQm7AyExHbGI7SmPUl28WC3Ax2UPi8MwDQjczQm-_n3D8R)
* [https://www.metasploit.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.metasploit.com%2F\&h=ATPydDvQtiKEjwWpBe9UX-cCAOyF-W4WOXKOYveXdacpXKBWu_9ej2tIfOwErR7RykYgAC6AqYzTHS_yEO6z-W-7QWJVUOPFPBaeYyuyQwxlHTz0PN9u285VplGVoWh6GwTav1rWkdag)
* [http://sectools.org/](https://l.facebook.com/l.php?u=http%3A%2F%2Fsectools.org%2F\&h=ATN0b3xQkgTwB3FxtTPDdzgDEmkQiOk-YoZg7UWP5JXZRVL7eJ8nN2xpZTciAUFp_OrAfJawO2R00RqIUx0yORCsdelHgTyEnZvAHpaY_JVXjoeqCFdDcnct6qjwHp7j-OvZ4v3qdWJI)
* [https://labs.detectify.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Flabs.detectify.com%2F\&h=ATMgAp_vxmSVaeA5XX31UyWiCRHmvII87T4v64FCnqu06sV2KNOQZmvl6vsRJh4imf4JPRorl6BcNuwQ2W-dnkxuYuBup9ENxVHt5MKERDc3Atf1dWOZysfRe85hlOYYm9s28tl3Gb0S)
* [https://blog.rubidus.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fblog.rubidus.com%2F\&h=ATNC0jdvuCCGGYyg5dJQO-NrVaOGCbOn9HT06m0Ad95QHUbIpLUpJHJlMvbmz8JhNqo1f65zVH7rTdb6DPN3TW5X2xbnNJGyfNAP5yA-xrQrnn_9PkmY3oYQYn-DjvBoGhJd9rYI5ogb)
* [http://www.securityidiots.com/](https://l.facebook.com/l.php?u=http%3A%2F%2Fwww.securityidiots.com%2F\&h=ATMqKhLRQ_iw1CY3g8XpHBLDFTetno5eR_tgdjooJCYPbuXwoDzAIabdZ_iLllPr24DnLW2T7ycOP0np3Vu9gHX0Ag76wQW4AxrGbdctSdMb3vFT5w7dWaIQr3Fkyb7aIGEWA993N1sc)
* [https://hackernoon.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fhackernoon.com%2F\&h=ATNJcgp3N6PzGeXYAYfI6B1yXSqHMn0JcN_e7eHG_KXf2Z6rg7gt3E5WqQFb78VQ6nif3MOuefX8YhXV_fyBk_DNlaOpGyEGSABIXwNPPgDWGq8WFqTlAroDVLoqylXeehpwBRrB1etO)
* [https://sqli-basic.blogspot.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fsqli-basic.blogspot.com%2F\&h=ATM4v_5BMgvAjSCevDLp28DQ5smzg7ETgRvBJbsg6z69h8WLb8pyicnKKSnVYCgYxmvCOJiJWy0gecw-a3cgLLdv78bKPG1Rnbzyzzr98RZQSXr90HCmA2ZB0W2GvVT8RJvMFzuKQwo-)
* [https://bugbaba.blogspot.in/](https://l.facebook.com/l.php?u=https%3A%2F%2Fbugbaba.blogspot.in%2F\&h=ATMstvXqiLCsoo2Ui-A0qSrUIKxknu7nJTPyKmJKDfCFggqHIsmk5zp9Gy8v2n-Taaau2p3IFpObL4OmIyBCLiY_YwVmhzPHJCBlt2UzUVae7x3zw_2UUJDpXGhVXeFwZqoEnP46cntt)
* [https://vulnerability-lab.com/](https://l.facebook.com/l.php?u=https%3A%2F%2Fvulnerability-lab.com%2F\&h=ATN9nmEZ3ieEMuT7gegO7_dvr2a1U54q6Zz-46LBJFTt3scBoim08GqYOVUDrvHzxw8AabuS27yavBqCOL0pd9pePXgj1j8sYp0YEzbCFZUamph7PlCrS1Qv32Tucvxc2YNw5j5J-rWc)
* <https://medium.com/@know.0nix/>
* <https://medium.com/@codingkarma/>

These are some Of the Websites That I like to Visit regularly to b updated and Read Their Articles………. There are Plenty of Other Blogs, Websites That are Missing from This List so be sure to add them In comments.

#### **YouTube Channels!** You should follow.

Now Lets get Towards YouTube Channel Links… These Channels are Shared By Hackers where They Upload their Video POCs.. Watching them u can actually understand how to demonstrate these type of attacks …\
\
[https://www.youtube.com/channel/UCP…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCPPAYs04kwfXcHnerm_ueFw\&h=ATNQDVlKetle_Mkhwwk5KBxkEhzFhXt4unCxLXesbjG4vrruJk5z0CPXH38o0ZAYELff2OJ2xxv52w-N5RuBV1of-I9h5xU0EcaTX586DP8x3EUQktQ9HQ6xCZjpx5bnF6tq1qNql_u5)\
[https://www.youtube.com/channel/UCJ…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCJ6q9Ie29ajGqKApbLqfBOg\&h=ATPsP-uGbtPkrVSIeU_z21HwWcan8VCAbmThlVOHKhp59BvvtEGFciS4MglXs-VyaTuS6KIh0OoFnF10oQA0V1i9-yzXv-wEp0awF1bltY5l7pm031ZBorgrePQDnbRYtoOY_TyB-ShT)\
[https://www.youtube.com/channel/UCR…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCRFG_j0cgLWtJOG6fl_-rxQ\&h=ATMxqmGkTMNQPI9frMJTVfQWveVXpkW0XMmt8OM_JkQqzwXz07dQ8dfVsLECgsvrA_TaKL_3JXDgtdFQdXxPh3blCNEFS8W0y2x2yYJmBLHxHjb3oz_BEnCpLSHIUoNY33oW1VkpYewO)\
[https://www.youtube.com/channel/UCY…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCYTK8lk8oLLaA330rqd0qgA\&h=ATNd36z0teHM7Mai8DS1erq_IPg1kCOX2rVkYpB5p8rQo_9R1AbtmWFvMCaD_ybDhhLXNMhJtnhEZDnA41-v7D3Nc_CFkvij8moxFZFzbzThWxdFR0SLgNg9JIcaKQ_f9wO4hFk3i_Sp)\
[https://www.youtube.com/channel/UCw…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCwfYw-C2xqemqrXq0IKF_Mg\&h=ATONF1t3ptYAzAyhbEX3CgVvgYmgjKyph0rdYp95oqyyha8wYIbH1c80YNZ6zntRjshxB4MjpYcQWy4deICg85S1p_QdhC5tqSli0JjoqfZVBkDj5pj1LWudKBXgHoBKfy_mXm9lJ1f2)\
[https://www.youtube.com/channel/UCa…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCa0tvIaVilNAshcI-24AFdg\&h=ATPSRL4NsRHik8t_r0hXNvuYQ_GYdMLlOB_b8f70oMmbcUvrSra9RSHF91mLSKoAUahMeRNOeuHt1TgbQQr88OFs73RJjav_6Yv9B5cBMkmvMZEfd8mbSnuBfs6Mygga7CHUdW_YbDA1)\
[https://www.youtube.com/channel/UCt…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCtLT_s49tKrcJEfnYX-qJAg\&h=ATNfu-hdPiIYwl3PQA3ScVdcUM86jF6NzQZtR3C75F0zAbxVB4Fe5vNCh4qqyIv3RR9ObDiqwKnv244fXu8gKXiGRh9F3l7_hVhlnPLgP1ivBwYDn91fzxLSOYbFhE9oIiW2L7aUrRxa)\
[https://www.youtube.com/channel/UC5…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUC59IHQcCmgNw4GIvsXeLnDQ\&h=ATN81FtLoefPCXtTZBaXXoPyRRwv_l0p4rJ6KsRRcn8YMFUNX4L04lfQPWeGdX8mHKgm7MfOG3CyId9j6kAxCMgG3d5MJvSL_3q7jESccP8-ovOQwMMG8-2LqOrjSqhGJ0IjzDMXIuqs)\
[https://www.youtube.com/channel/UCM…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCMb5eIyahPJS0YgQc_Kf1vQ\&h=ATNMMz7Uh9Aau1rXcKdw5WQcEKQBLXjaZG-XQxl3aTTZfGjaWLVD27itTq2GzC8aUuyfZD654xnSQxUmPcpfBDlpWvvg3gJtQWbfPVDyUyggNgB3al2_oD12fO3T8cLX04jTedTUuv5g)\
[https://www.youtube.com/channel/UC\_…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUC_jNs1biBixcQeSUoJxvNLw\&h=ATNAw0NCg2ys-GcTOTkzMDG-4YFhVApctvajl89UaUXj3GXw6Xmbbty1QlFLsiWII1In8vv5c1fxPLFgSvqHcSjYHWcGHbDWY4FArDjUm8yXHtmkE8u-N62d_T6w0GeidHk8o1KWFj3t)\
[https://www.youtube.com/channel/UCq…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCqH9rDGM_5LMFwx96PUXmRA\&h=ATMc6_VcQWNlHZKACce1Ba0bsfJ5ghi2meFL_luT6Fn94yNmmGSkraMO2eB5Z9EyqsuyYcfj0W4IN9Oo-K_rsvFtFH3dRITjxh7I5QQWORRz3t7QsXw8BMBqmfcEP9dsCfWs28ZAYgOL)\
[https://www.youtube.com/channel/UCV…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCV89UhUtxqwP0j4o9tMipsA\&h=ATOSHbLDxswkwE149Qql7AfHk1QkicBWRvdKRySbWReTBhRhKT8Vve1trTPv2HpiRHGVh8wV2nyQk7V7DHKK2WlEfAaXhKbpMedpR6nH-ErtwzNKEa2kDvxQulODDBDORPhBuA2xtYI-)\
[https://www.youtube.com/channel/UCs…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCsgzmECky2Q9lQMWzDwMhYw\&h=ATPeT5sRWTeOILrCmlCxp6jghkVkWqoExY2RqZFJ3TN6dTeoVa8B2I9ZDmKnaso3kx6klBVAtB0G8Gi0DqZ_xZVJQLJacis3DFcJ7cUVo8jUOvASdKhytlW5amOXgLzGOxE4MlssvU4l)\
[https://www.youtube.com/channel/UCa…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCaftcKRiJJW0AJHmR1E5MAQ\&h=ATPTWzZR6xxVjP3MqTKTF-yUKiCkEG6OVicaMg4hsElejdDCAOt0WzUVTFBmCxIbBoI-IhwrfX3I0qtTI_YvXEYYDu75KN4m44SJ4Cj8ZziowF5zh-OXLXCDWNsIkrCDyqIwjikAUfYG)\
[https://www.youtube.com/channel/UCP…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCPxJLZCoIRJHs1VebWeaByA\&h=ATPsFvSeNDxACjYn33kYybYaRDgExSJ0igqSLTTUJmtz_hfXniapAu5mxr5kbO6y-mXwTM2BtnCh8TX-ki8Ey1r1c-5L02-n-pNPJeo-CnBxa8_1fndEmph0XM4IjcMW0SsdOIwj5jBr)\
[https://www.youtube.com/channel/UCX…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCXsjr2nPZ1zMFlgqb1zwKpA\&h=ATMU_7Va9AEamYGwO6rmlSbuFBbMGaAdpghai2V8zqNX3nYPge8gDts5mazti_ISF9rHkhCWR0Pad7GQ1ruaGb_w_hAdFNOOJaNRlhsUBm32ErRC6GQnoOBst2bitSqQEJ_1ronQWq_hagpfi8wH8X8OYA)\
[https://www.youtube.com/channel/UC4…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUC4QJ7X4nnkAYXsnFQpdytcA\&h=ATMt3ZmUznvSzgv9GkSwZ16QmdRCrNPUzwMKuGSDYAh92GljGmoRb6NRay34kX5Os3AhdXsYTs_aez3-huCu_EIroM77cBZ2xW-UlgiPALWoqyc77OdZEpYHGhXE71PPgC-0vtl6LzAYUYMQ3PPC5asQAQ)\
[https://www.youtube.com/channel/UCs…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCs2NmJGRecw_huNzvQNf2_A\&h=ATPUl777znCvLtX80X9yPZQL6M2mmX_bjKKXW0iiozNYurWXXmqLwav2LQHoT4T15p81x1DkFxV38JEg2CRvHj3vi73CKEQd_rKN9g1TIfEsKt5KywwmEXn0vCfcM4RuUoaVV3B8gH_0)\
[https://www.youtube.com/channel/UCo…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCo1NHk_bgbAbDBc4JinrXww\&h=ATMbfJII7XSdOqsQDzDZMvEVkTEkbkkVZ9rXDexxgEvoKPhPPrtP7zVXBjDZAxjdctUtaSHP0v5hDubQCNla7LqzNSfO2FHELCRXmURnYTTmgR5ZLvf6G2wtxlFD506AcP4aHGXy5zgI)\
[https://www.youtube.com/channel/UCy…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCyRTTbb7I4GdDCAoGpjoqdg\&h=ATNZAtFje221FBYvawcFsQfuXQ1fKG2X_AakOTlvG0PVWvk-uKFNH3zq608fojmO69LEx3fFlAj0bEmAI6qitsIA3lbxMQg60V-9fNHK42p7fNVKKT54sQk2b2I9dRu-Z7nlpHubFKb9)\
[https://www.youtube.com/channel/UCS…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCS0y5e-AMsZO8GEFtKBAzkA\&h=ATOvingxqMm0-GgUPbNYFHXLiQM7iJXwcNqiGTCpWNxZMezJtJu7hV3wE_WJKdKfRnblDuvWFtqwZ5gLrdMv7GY38AF20IIgzun4zJHtiivzjiSmUpUMlrRCK9jNdpWX7g6WM2voJA2O)\
[https://www.youtube.com/channel/UCO…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCOQtLXVJduZ4-YUFOi5EzIA\&h=ATOSwkoywbP4Q9Xa_oa1nt5sdLHenji0TSa5mWfWZ-yQq4jQXU8CUhsITNcy0LWwIhpqnvuK-erLELJqqlpBfjNjjXIydAqv0E858kT6rSFbqqGBtP4v0TEilHrUQ_t8-vVJsfxmrtch)\
[https://www.youtube.com/channel/UCh…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCh5MTJLt3LYr_rkwcOQJNWg\&h=ATOKivULHD9WUu6LQXY6KK13InD1GNParhmlYG-3jPwk9NPo7ToG6Nyb-RXIlF0dFwYYwQo34GG9DXXMch3JJJcTwAgF7j9rE_CblV9ACeGBtPI1vpCa1wYcZ-mZBlCg4Z6goZq8P99A)\
[https://www.youtube.com/channel/UCo…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCou-7r8Mk4oQcBmazxp5uwg\&h=ATNYkCk4NLcVYPBMVZQXI4oJS6LuMNsCPT2ZQ-nZ7mjqjT9n2A7IRNyLcr7bXSSSU2IJIA2V_WQFVeunhdh7PWqpOhPFzrJ3RKqlF1KOiMZLB6DRfQopApsFakxDd0sREXplZB8cN8_q)\
[https://www.youtube.com/channel/UC9…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUC9gcFaGnsI9nEh0CmTfFPCg\&h=ATOS_Qajifodd3D5fzTLCEsrvYqFRY66R_YbhxNbNmkEf3yDCLAR8fmXohNAhyXb5MzvieAPy8ZX_MdCEYgMBwhMwCvvnb1leFzbil8fkD7H5jgIQTBX7CItxNzhFaNLhDx5YYNvncEa)\
[https://www.youtube.com/channel/UCe…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCen55zu4U3XaSUuXSWPwjIA\&h=ATPC3CqpxVm7cemX1HExaijTBYBDz8WVLPqzG0d69ME2Hv1nFJ8ZdvuNlE_80r6kwXuqBqNW1_jDTtl1mmEdjzMOw1VPhMCloGtQOVA_-0f9xDqmFcnt-thQZjtuYUZHAxtj1ZeE4O4c)\
[https://www.youtube.com/channel/UC2…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUC286ntgASMskhPIJQebJVvA\&h=ATMnQt9LR2Z4YlvrKAfW8emTYUnKzsfM2yx06KzrlV85P8CV9975GsuhgwTmcc-ilXbYjbXlvO7oN4WSqrh5WF92EA16j6xxlf-cuICBNdmaUXBwNEjFFCM6yxWm0Ivzv9jh8MDWUrER)\
[https://www.youtube.com/channel/UCP…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCPSPMTol8NmmJrEFyHaVgfg\&h=ATOynMGasCjk2q5znCHEEVbV5gSxdqSq4eBv6wfKJtktVLYJYfPvwpKk95ziBR1ZBm7kOtmG1Tw8LHWLV5DYqwUQV_LL6tZEaJAhbJxPADXGw7w_j-mWuKB1Kc39yOZdzYyAwchYSezr)\
[https://www.youtube.com/channel/UCz…](https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.youtube.com%2Fchannel%2FUCzSAhv3ZpXfRsZJuysN3ECw\&h=ATPRAMJN2VRbgwaSitAuUl_0qzhR4fspXaPizYenx2kkAGyTzt0Sbi5zZSwjAD2RyRv5Fd-EGLZFrUrrE3n6IatKET8NDjtLYUrOSMWY7WAr79WWowSOaf9k8vJ2y8Gbm6ZqbnwNpSwF)

<https://www.youtube.com/channel/UCq9IyPMXiwD8yBFHkxmN8zg>\
\
Any Channel Link Missing? Kindly add it in Comments

Another advice…… Regularly follow <http://h1.nobbd.de/> to b updated with [HackerOne](https://hackerone.com/) Public Bug reports You can learn alot from them

Alternatively, You can Join Slack Community for Hackers\
<https://bugbounty-world.slack.com/>\
<https://bugbountyforum.com/>

#### **Tools**! You should try out.

dnscan <https://github.com/rbsec/dnscan>\
Knockpy <https://github.com/guelfoweb/knock>\
Sublist3r <https://github.com/aboul3la/Sublist3r>\
massdns <https://github.com/blechschmidt/massdns>\
nmap [https://nmap.org](https://nmap.org/)\
masscan <https://github.com/robertdavidgraham/masscan>\
EyeWitness <https://github.com/ChrisTruncer/EyeWitness>\
DirBuster <https://sourceforge.net/projects/dirbuster/>\
dirsearch <https://github.com/maurosoria/dirsearch>\
Gitrob <https://github.com/michenriksen/gitrob>\
git-secrets <https://github.com/awslabs/git-secrets>\
sandcastle <https://github.com/yasinS/sandcastle>\
bucket\_finder <https://digi.ninja/projects/bucket_finder.php>\
GoogD0rker <https://github.com/ZephrFish/GoogD0rker/>\
Wayback Machine [https://web.archive.org](https://web.archive.org/)\
waybackurls <https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050> Sn1per <https://github.com/1N3/Sn1per/>\
XRay <https://github.com/evilsocket/xray>\
wfuzz <https://github.com/xmendez/wfuzz/>\
patator <https://github.com/lanjelot/patator>\
datasploit <https://github.com/DataSploit/datasploit>\
hydra <https://github.com/vanhauser-thc/thc-hydra>\
changeme <https://github.com/ztgrace/changeme>\
MobSF <https://github.com/MobSF/Mobile-Security-Framework-MobSF/> Apktool <https://github.com/iBotPeaches/Apktool>\
dex2jar <https://sourceforge.net/projects/dex2jar/>\
sqlmap <http://sqlmap.org/>\
oxml\_xxe <https://github.com/BuffaloWill/oxml_xxe/>\
XXE Injector <https://github.com/enjoiz/XXEinjector>\
The JSON Web Token Toolkit <https://github.com/ticarpi/jwt_tool>

[Playing with JSON Web Tokens for Fun and Profit](https://blog.securitybreached.org/2020/04/04/playing-with-json-web-tokens-for-fun-and-profit/)\
ground-control <https://github.com/jobertabma/ground-control>\
ssrfDetector <https://github.com/JacobReynolds/ssrfDetector>\
LFISuit <https://github.com/D35m0nd142/LFISuite>\
GitTools <https://github.com/internetwache/GitTools>\
dvcs-ripper <https://github.com/kost/dvcs-ripper>\
tko-subs <https://github.com/anshumanbh/tko-subs>\
HostileSubBruteforcer <https://github.com/nahamsec/HostileSubBruteforcer> Race the Web <https://github.com/insp3ctre/race-the-web>\
ysoserial <https://github.com/GoSecure/ysoserial>\
PHPGGC <https://github.com/ambionics/phpggc>\
CORStest <https://github.com/RUB-NDS/CORStest>\
retire-js <https://github.com/RetireJS/retire.js>\
getsploit <https://github.com/vulnersCom/getsploit>\
Findsploit <https://github.com/1N3/Findsploit>\
bfac <https://github.com/mazen160/bfac>\
WPScan <https://wpscan.org/>\
CMSMap <https://github.com/Dionach/CMSmap>\
Amass <https://github.com/OWASP/Amass>\
\
Any Import Tool Missing Add in comments…

This was as much as I can think about sharing with you guys related to Web app Security in tools and vulns i have added a few things about mobile apps but the following sections contain some references you should definitely go through if you gonna join the mobile app security gang as well.

### **Mobile Application Security**.

So hello to Mobile App Security section now let me clear this first i’m a complete noob at this section so it won’t be as detailed as the web app one.

Now The best and the very first thing I would suggest is to actually learn about the development phase of an app mainly my focus is Android APPs ( doesn’t necessarily mean that you should go for learning to develop an android but at least get to know. For this, You can go through the following Android App development tools. (My suggestion is you should actually give basic time to these)\
\
[Android SDK](https://developer.android.com/sdk/index.html) \~ The Android software development kit (SDK) includes a comprehensive set of development tools. These include a debugger, libraries, a handset emulator based on QEMU, documentation, sample code, and tutorials\
\
[ADT Bundle](https://developer.android.com/sdk/index.html) \~ The Android Developer Tools(ADT) bundle is a single download that contains everything for developers to start creating Android Application\
\
Root Tools \~ RootTools provides rooted developers with a standardized set of tools for use in the development of rooted applications.

Now if you have gone through them let’s get towards Mobile app security vulnerabilities For this I’ll suggest you first go towards [OWASP Mobile Top 10](https://www.owasp.org/index.php/Mobile_Top_10_2016-Top_10) Giving them a good overview will definitely worth it.\
\
I’ll also Highly suggest these two Books specifically for Android & IOS app testing\
\
[The Mobile Application Hacker’s Handbook](https://www.amazon.com/gp/product/1118958500/)\
[iOS Application Security: The Definitive Guide for Hackers and Developers](https://www.amazon.com/gp/product/159327601X/)

For Mobile Applications, I’ll share Two of the Best places I’m currently following to learn and I would highly recommend you guys to have a look at them and giving them a proper read will definitely help you

**Application Security Wiki**:

**Application Security Wiki** is an initiative to provide all Application security-related resources to Security Researchers and developers in one place.\
\
[**https://appsecwiki.com/#/**](https://appsecwiki.com/#/)

**Learn IOS Security**:

IOS Security Guide to learn and test by [Prateek](https://twitter.com/prateekg147)\
\
<http://damnvulnerableiosapp.com/#learn>

**owasp-workshop-android-pentest:**

[Learning Penetration Testing of Android Applications](https://github.com/OWASP-Ruhrpott/owasp-workshop-android-pentest)

**Mobile Application Penetration Testing Cheat Sheets**

[**The Mobile App Pentest cheat sheet**](https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet)

[**Mobile penetration testing android command cheatsheet**](https://github.com/mirfansulaiman/Command-Mobile-Penetration-Testing-Cheatsheet)

[Getting Started in Android Apps Pen-testing](https://blog.securitybreached.org/2020/03/17/getting-started-in-android-apps-pentesting/)

Summing up Phase #02 of this blog I think by following these resources at and giving them good time one can get pretty good at Bug Hunting.\
\
Here are some Websites or Places where you can play CTF Challenges and practice the skills that you have learned.

* **Hacker 101** <https://ctf.hacker101.com/>
* **Hack the box** <https://www.hackthebox.eu/>
* **OvertheWire wargames** <http://overthewire.org/wargames/>
* **Pwnable.tw** <https://pwnable.tw/>
* **Vulnhub** <https://www.vulnhub.com/>
* **Troy Hunt “*****Hack Yourself*****&#x20;First”** <https://hack-yourself-first.com/>
* **Hack.Me** <https://hack.me/>
* **Hacksplaining** <https://www.hacksplaining.com/lessons>
* **Penetration Testing Practice Labs** <https://www.amanhardikar.com/mindmaps/Practice.html>
* **Bug Bounty Hunter** <https://www.bugbountyhunter.com/>

### **Other Resources:**

I saw a few friends of mine shared some really interesting and important tools, & resources so I decided to add them here as well because I’m giving some good time to them nowadays.

[**Tools used for Penetration testing / Red Teaming.**](https://github.com/OpenSourcePentest/tools)

[**List-pentest-tools: A curated list of network penetration testing tools.**](https://github.com/GoVanguard/list-pentest-tools)

[**Password lists for use in penetration testing situations, broken up by TLD.**](https://github.com/lavalamp-/password-lists)

[**Penetration tests cases, resources and guidelines.**](https://github.com/Voorivex/pentest-guide)

[**Penetration Testing notes, resources and scripts**](https://github.com/AnasAboureada/Penetration-Testing-Study-Notes)

[**A collection of hacking / penetration testing resources to make you better!**](https://github.com/vitalysim/Awesome-Hacking-Resources)

[**RedTeam-Pentest-Cheatsheets**](https://github.com/b1n4ry4rms/RedTeam-Pentest-Cheatsheets)

[**Collection of OSCP study material && tools.**](https://github.com/executeatwill/OSCP-Treasure-Cave)

[**Kali Linux Offensive Security Certified Professional Survival Exam Guide**](https://github.com/Elinpf/OSCP-survival-guide)

[**Penetration Testing / OSCP Biggest Reference Bank / Cheatsheet**](https://github.com/OlivierLaflamme/Cheatsheet-God)

[**An archive of everything related to OSCP**](https://github.com/CyDefUnicorn/OSCP-Archives)

[**GitBook: OSCP RoadMap**](https://github.com/nairuzabulhul/RoadMap)

[**OSCP Cheatsheets, Pentesting / Red Teaming Tools and Techniques**](https://github.com/mantvydasb/Offensive-Security-OSCP-Cheatsheets)

[**How to prepare for OSCP complete guide**](https://github.com/mohitkhemchandani/OSCP-Complete-Guide)

[**OSCP All Tools are Here …!!**](https://github.com/anandkumar11u/OSCP-60days)\
**Courses at** [**https://academy.tcm-sec.com/**](https://academy.tcm-sec.com/)
