RSSAmplifier

Blog

jhaddix.com

jhaddix.com

jhaddix.comRSS feed ↗17 posts

Latest posts

The Anti-Recon Recon Club (using ReconFTW)

Recon is important, but some people hate it. I get it. When you're in the zone and ready to pounce on a target, you just want to start...

The 100+ Million Person Data Disclosure

Or, That time I hacked a whole country by accident! I have done consulting gigs all over the world for security testing, and I frequently...

The secrets of automation-kings in bug bounty

For those looking to make big money in the world of bug bounty, finding 1day (or 1month) web exploits that haven't made their way into...

Live Recon - Lily Clark

Live Recon discusses offensive security topics. This episode we got to chat with Lily Clark. Lilly has one of the most amazing stories...

Bounty Thursday - All things DNS w/ STOK and Codingo

Another week of co-hosting Bounty Thursdays with my good friend STOK and special guest Codingo! We talk a lot about DNS related to recon;...

The Medical Alert Hack

Not too long ago I put a whole city on high alert during a security assessment. A tale of caution. Read along to learn my approach ...

Live Recon - with @Yassineaboukir

I’m back again as a cohost in this episode of Live Recon. Catch Ben, myself, and Yassine chatting about his methodology to find bugs and...

A hackers guide to FINDING cybersecurity jobs

Getting your foot in the door or finding your next gig in cyber security is sometimes a daunting task. Just like hacking, a methodology...

The Complete Compromise of a Password Manager Site

Here's one of my stories about a security assessment I did on a password manager company. One of my teams and I could have accessed...

Penetrating a porn site

Another hacker story thread! === Penetrating a Porn Site === How I hacked access to the most sensitive areas of a porn site using...

ToolTime #2 - SSL Certificate Parsers for Recon

Exploring SSL Certificate parsers: https://github.com/projectdiscovery/httpx https://github.com/glebarez/cero https://github.com/hakluke/...

Bounty Thursdays w/STOK & Kugg - Content Discovery

Interview with HackTheBox machine creator and content creator ippsec

Bug-Bounty/Hacking Diary 4/8/22 - SQL Injection

Everyone is sick in the house but I had some running scans I needed to check up on. I found a SQL injection bug on a blog. Here's how I...

ToolTime #1 - FeroxBuster (content discovery)

A new series where i will do a video cast reviewing offensive security tools! Last week I took a look at a new favorite of mine,...

My Xmind Hunt Template for @hakluke

I get asked a lot for my XMIND mindmap template. I start with this and fill it out as I hunt =) Enjoy! Rename extension to .xmind

Stealing checks worth millions & pwning a bank

Another long (hacker) story of mine! Once upon a time contracted to do a penetration test on a bank… I spent the better part of a week...