rashahacks

How I fuzz and hack APIs?

Hello Hackers, In this post, I will explain how I fuzz APIs for bugs. This blog is more about how to understand your API and then about what tools I use and where to fuzz? 1. Understanding the API 2. Where to fuzz and how to fuzz? Understanding the API?

How I Pwned 10 Admin Panels and got rewarded 8000$+?

Hello Hackers, I am Inderjeet Singh aka encodedguy. Today, I will share one of my recent findings where I pwned 10 admin panels and the team rewarded me with $8000+. Background I was invited to a private HackerOne challenge this month. The total bounty pool for this challenge was $15K.

Exploiting GraphQL Aliases

Introduction GraphQL is an API query language that allows developers to write clean code, and get as much data as they want from a single query. GraphQL uses a single endpoint like /graphql or /api/graphql and HTTP method can be POST or GET. It have queries to read data

Reverse Whois - Increase Attack Surface Area

* Introduction to Whois * Whois Flow * What is Reverse Whois? * Reverse Whois Flow * Tools * 100 domains or 84615 domains? Introduction to Whois Whois, is used to query domain names, IP addresses, and  ASN (autonomous system numbers or IP blocks) for their registered information. In simpler terms, if a user owns a

My Favourite 10 Shodan Dorks

If you don't know what is Shodan, I would say just go to shodan.io first. It is one of the best search engines for hackers.

rashahacks © 2026