Hello... Go! Black Hat is another blog for Pure Black Hat Hacking Guides.

2 Stored XSS on Vodafone

+ No comment yet
Cross Site Scripting have been my favorite vulnerability for all time, as XSS is very common to find in any website. in fact XSS is very dangerous Vulnerability. on OWASP's Top 10 Vulnerabilities of 2013 it is on 3rd. usually developer doesn't  watch out for this vulnerability while building website.  recently i have found 2 stored XSS on Vodafone! actually on vodafoneappstar.com, Vodafone App Star is an annual contest by vodafone to encourage developers to build apps for mobile platform. it is an international level contest by Vodafone.
Read more

Vulnerablity on Truecaller

+ No comment yet
Truecaller is a global phone directory application for smartphones and feature phones, and accessible via a Web site, developed by True Software Scandinavia AB. It finds contact details globally given name or telephone number, and has an integrated caller ID service using Crowdsourcing to achieve call-blocking functionality and social media integration to keep the phonebook up-to-date with pictures and birthdays.performing 120 million searches of the telephone number database every month. As of January 22, 2013 Truecaller reached 10 million users.
Read more

Finding Security Bug on Shikha.com

+ No comment yet


according to wikipedia - "Shiksha.com caters to the educational requirements and queries of students. The portal is the brainchild of Info Edge India Ltd. Students can find information on educational institutes, programs, scholarships and admission notifications. More than 40,000 courses of numerous Indian and overseas institutes are listed on this site. Shiksha.com has 15 branches in 12 Indian cities. As of May 2012, the traffic share as per Comscore is 41%. In July"
Read more

Finding XSS on Asia's top tech blog

+ No comment yet
i am a very big fan of Amit Agarwal, he is runs a asia's top technology blog and which counts under top 100 tech blogs over the globe! and when i was new to XSS i keep on injecting parameters to different website's different fields and one day i was just spending my time for reading labnol's articles and looking over his blog i just injected XSS parameter and fortunately it did worked :)
Read more

how sometimes reporting security flaws may result into some job offers

+ No comment yet
sometimes reporting vulnerabilities can turn some job offers to you, one day i was just surfing on internet and i came upon to a website that website was organizing a contest in which they are getting live opinions from the public about there new small movie and as always, i just injected a piece of javascript fortunately, it worked and the homepage of the website, every time it got open or refreshed it is having a alert “hacked by @n3g4tiv3eLemEnt” and after few second they restored there webpage, but i was not sure they have fixed up this vulnerability or not. so i injected another alert of saying “http://about.me/parv_jain” and it was working again.
Read more

Bypassing e-bay XSS filters to redirect to any other page

+ 2 comments


Read more

Make a Facebook Page having lots of “likes” through e-whoring

+ 3 comments


Have you ever wondered that you can get likes for a page through “E-Whoring” ? what ? not ? OK! Have you ever wondered that you can get likes for a page through “E-Whoring” ? what ? not ? OK! so i will show you how to make a facebook page with lots of likes for facebook. believe me it’s the most effective techniques of getting the likes you might have heard till now! before i start with this topic, the thing which i want to tell you we will not use the lame techniques like commenting on other pages “Please like this page” or anything like that using the technique which i will be taught i have easily got 1200+ Likes in couple of weeks …
Read more