rashahacks

eLFI already solved it, better get going #BUGCROWD Challenge

In this Write-Up, I am going to walk you through the bugcrowd’s open challenge to hackers. * Note: In case you’re reading this Write-Up without trying out the challenge. I request you to first give it a try and check this blog if you’re stuck. 1.

Cheatsheet - 15 Methods to Bypass 2FA Mechanism

In 2-Factor Authentication, when a user enters his password with the intention to log in the web application sends a temporary code to the user’s verified email address and when the user enters the code only then he will be able to interact with his account. Many websites

How I fuzz and hack APIs?

Hello Hackers, In this post, I will explain how I fuzz APIs for bugs. This blog is more about how to understand your API and then about what tools I use and where to fuzz? 1. Understanding the API 2. Where to fuzz and how to fuzz? Understanding the API?

Exploiting GraphQL Aliases

Introduction GraphQL is an API query language that allows developers to write clean code, and get as much data as they want from a single query. GraphQL uses a single endpoint like /graphql or /api/graphql and HTTP method can be POST or GET. It have queries to read data

Reverse Whois - Increase Attack Surface Area

* Introduction to Whois * Whois Flow * What is Reverse Whois? * Reverse Whois Flow * Tools * 100 domains or 84615 domains? Introduction to Whois Whois, is used to query domain names, IP addresses, and  ASN (autonomous system numbers or IP blocks) for their registered information. In simpler terms, if a user owns a

rashahacks © 2026