Web appOpen in Telegram
HHacking Blogs Group

Hacking Blogs Group

@HackingBlogsGroup · group · Tech · indexed since 2026-07-12
1 360members
820messages in the index
Z
Photo
click to show
Photo
click to show
Photo
click to show
Z
Photo
click to show
Photo
click to show
Photo
click to show
Z
Link
click to show
🚨💀FREE NOTES API-HACKING DAY 3: Finding Anyones’s Location In crAPI Using EDE & Bola Bugs The API returns sensitive data to the client by design. This data is usually filtered on the client side before being presented to the user. An attacker can easily sniff the traffic and see the sensitive data. Understanding Excessive Data Exposure Bug When an API endpoint returns more data than is required or meant for the user, this is known as an Excessive Data Exposure problem. This usually occurs when the API answer contains sensitive or unnecessary information that the requester shouldn’t be able to access. As an illustration, suppose you are requesting information on an author via an API call. The API returns sensitive information like the author’s phone number, email address, and other private information, even though it should only return basic information like the author’s name and biography. The system is exposing more data than is necessary for the particular operation in this clear instance of excessive data exposure. The API is unintentionally returning significantly more data than is required for the request, which is an obvious sign of an Excessive Data Exposure problem. Such a response should never reveal sensitive information, such as the email address or VIN number, as it may be used maliciously. Response {"id":"8YG2mv35HKqsQPGw5emNzk","title":"the stew","content":"agbadalasiminue","author":{"nickname":"fisway","email":"[email protected]","vehicleid":"1fa3df1e-5625-471f-b47b-9ca8d66b43d4","profile_pic_url":"","created_at":"2025-05-27T21:36:01.255Z"},"comments":[],"authorid":2326,"CreatedAt":"2025-05-27T21:36:01.255Z"}, The complete set of notes are uploaded here 👉🏻 https://hackingblogs.com/free-notes-api-hacking-day-3-finding-location/ Telegram group for free resources and daily news on cybersecurity 👉🏻 https://t.me/HackingBlogsGroup API-Hacking WhatsApp group 👉🏻https://chat.whatsapp.com/KRvLRD8wN4V18PoirP7x8u
Z
Photo
click to show
Photo
click to show
Photo
click to show
Photo
click to show
Z
Link
click to show
💀Hack a Locked Linux Laptop in Minutes with This Little-Known Initramfs Glitch Greetings, Hackers! Dipanshu here and indeed, I’m back at last after a long break. But believe me, I’m not leaving this time. Today, we’re exploring an often overlooked yet highly impactful issue: a lesser-known vulnerability in Linux that enables attackers to take control of encrypted systems all through a debug shell concealed within the initramfs. Although you have activated full-disk encryption, Secure Boot, and bootloader passwords, your system might still be at risk. In only a few minutes of physical access and a USB drive, an attacker can gain a root shell, alter your boot files, and implant persistent malware without requiring a password. Let’s analyze precisely how this operates, what enables it, and crucially how you can safeguard yourself and learn Hack a Locked Linux Laptop in Minutes. To Read this detailed article along with PoC 👉🏻 https://hackingblogs.com/hack-a-locked-linux-laptop-in-minutes/ Join Telegram channel to Receive Daily Cybersecurity News and Content 👉🏻 https://t.me/HackingBlogsGroup Join This Free API Hacking WhatsApp Group 👉 https://chat.whatsapp.com/KRvLRD8wN4V18PoirP7x8u?mode=r_t
Z
Photo
click to show
Photo
click to show
Photo
click to show
Photo
click to show
Z
Link
click to show
🚨Breaking News: Chess.com is Hacked in Massive 2025 Breach The online chess world gets a shock when Chess.com is hacked. Recently, the biggest online chess community platform in the world disclosed a major hacking attack that affected thousands of individuals. This hack revealed the personal information of over 4,500 people, raising concerns about internet safety and privacy. Hackers kept access unnoticed for almost two weeks during the event, which occurred between June 5 and June 18, 2025. It is unclear how widespread the problem may be because this attack coincides with the discovery of serious vulnerabilities in well-known file transfer programs like Wing FTP and CrushFTP. https://hackingblogs.com/chess-com-is-hacked-data-breach-2025/ Join Hackingblogs Official Telegram channel https://t.me/HackingBlogsGroup
Z
Photo
click to show
Photo
click to show
Z
Link
click to show
🚨Think adult videos are safe? RatOn malware is using them to hack phones, steal banking info, and wipe out crypto RatOn malware is purposefully pushed via fake apps and websites with sexually explicit content. These websites and apps are often little more than malicious loaders and pop-up advertisements that spread infection. As the initial step in spreading the RatOn malware, several of these domains had names like “TikTok18+” and hosted the dangerous dropper application directly. RatOn Malware works in stages, similar to many modern banking trojans for Android. It initially attacks the victim using a dropper app, which is essentially a fake installation posing to be harmless software. After installation, the dropper requests authorization from the user to install programs from unknown sources. https://hackingblogs.com/raton-malware-adult-video-attack/ Join India's Best Cybersecurity Telegram channel https://t.me/HackingBlogsGroup
Z
Photo
click to show
Photo
click to show
Photo
click to show
Photo
click to show

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count