API and Web heavy hacking content for bug bounty hunters and security researchers.


Medusa

Hey hey! 👀
Been seeing y’all in the comments lately, really crazy!

We’re on the road to 15k now, and I’m tryna make the content even better.
So if you vibe with my stuff, share it around and let’s hit that goal together 🐍 🔥

1 week ago | [YT] | 90

Medusa

Hey guys, I was about to upload the new video but it’s delayed now cause of video project cooked, everything messed up. Working on it :) Thanks for your patience.

3 weeks ago | [YT] | 47

Medusa

Hey guys! My portfolio site is Up, check out. :)

portfolio.medusa0xf.com/

1 month ago | [YT] | 87

Medusa

Hey guys, I just want to thank you all for the recent support. I’ve been going through a lot lately, but I’m trying to stay consistent with uploading. Hope you understand. Thank you 🐍

1 month ago | [YT] | 84

Medusa

Hey guys, don’t forget to check the new Blog!

osintteam.blog/how-i-found-an-account-takeover-bug…

1 month ago | [YT] | 61

Medusa

Hey guys, all of my membership articles on Medium are FREE to read now!

Open any article and you will see a friend link there, enjoy ❣️

medusa0xf.medium.com/

2 months ago | [YT] | 57

Medusa

Hey there, hope y’all doing well. I’m on the journey to 10K subscribers and i need your help - share my channel with your friends, disc servers or on X(tag me) and let’s make this happen!

Also, let me know what topic the next video should be? Thank you!! ❣️

2 months ago | [YT] | 75

Medusa

Guys, I figured out Stage 10, the one I was struggling with in the last video (I was too tired to record more 😅).

So here's the deal:
In Stage 10, the "domain" part gets removed. Anything else you type still triggers a popup like alert(123), but the goal is to use document.domain.


To bypass this, I used something like document.domaidomainn. Here's how it works: I wrote "domai" first (not the full word), then added "domain" right after it, and then a character "n".

The backend strips out the "domain" part, leaving behind domai + n = domain. So you end up with a valid document.domain, which gives us a pop up!

3 months ago | [YT] | 54

Medusa

Howdie Hackers!

3 months ago | [YT] | 53

Medusa

Hey everyone, hope you're doing well! I always experiment with different styles, and from my last video, I received some more feedback. Based on the previous videos and the latest one, I'm taking those comments into account to improve even more. Hope you'll enjoy the new video! 💜

11 months ago | [YT] | 26