rashahacks

How I Got Multiple Privilege Escalations - The Easy Trick?

Hello hackers! Today, I'll describe a way through which I got multiple privilege escalations. Background: It's a vast application with tenants and user roles. For testing basic privilege escalations first, I created two accounts: admin user and least privilege user. Least privilege user is the user

Soft Deletion of Resources - [Privacy Violation]

Introduction Soft deletion is the process of showing that an entry is removed but not actually removed from the databases. Is it GDPR compliant? No. As per GDPR (General Data Protection Regulation), unauthorized access and unlawful processing of personal data protection must be there. I am Inderjeet Singh aka encodedguy,

API Excessive Data Exposure: Why Devs? Why?

API Excessive Data Exposure When the API sends extra response to the client than required, it is called as API Excessive Data Exposure. In layman's terms, client wants x but API sends x+y. Is x+y a bug? I am not saying x+y is a bug,

Slides: GraphQL Hacking

Why Shift to Manual Hacking?

Hey everyone! Today, I am excited to share with you my insights into manual hacking. In this post, I will delve into hacking approaches, the reasons why I made the prefer manual hacking, discuss the mindset required for this approach and weigh its pros and cons. So, whether you are

rashahacks © 2026