rashahacks

Hacking GraphQL API Using Suggestions

Hello Hackers! I am Inderjeet Singh aka encodedguy from India. In this blog, I will introduce a way to hack GraphQL API using suggestions. At the end, I will also review one of my own finding where I was able to make a custom GraphQL query using suggestions and dump

Guide to Permutations Subdomain Enumeration

* What is a subdomain name? * What is permutation subdomain discovery? * Permutations Wordlist Generation * Tools for permutations * DNS Resolution * Tips and Conclusion Subdomain 101 In layman's terms, a subdomain name is a prefix before domain name that highlights a specific service. For example, google.com is a domain name.

Setting up Vulnerable REST API Penetration Testing Lab

VAmPI is a vulnerable API created with Flask (Python ) to demonstrate the top 10 vulnerabilities in APIs as outlined by OWASP Top 10 vulnerabilities. It allows you to test and evaluate the efficiency of security tools and can also be used for learning, testing skills and teaching purposes.

How I Pwned 10 Admin Panels and got rewarded 8000$+?

Hello Hackers, I am Inderjeet Singh aka encodedguy. Today, I will share one of my recent findings where I pwned 10 admin panels and the team rewarded me with $8000+. Background I was invited to a private HackerOne challenge this month. The total bounty pool for this challenge was $15K.

Change Any User Profile Details On Disney

The Walt Disney Company started its program on Hackerone in March 2022. Last week, I reported 3 highs and 1 critical on their program. This is the story of an IDOR report due to improper authorization. Authentication and Authorization Authentication: When a user logs into a site or app, this

rashahacks © 2026