About Hacked & Secured: Pentest Exploits & Mitigations
If you know how attacks work, you’ll know exactly where to look—whether you’re breaking in as an ethical hacker or defending as a blue teamer.
Hacked & Secured: Pentest Exploits & Mitigations breaks down real-world pentest findings, exposing how vulnerabilities were discovered, exploited, and mitigated.
Each episode dives into practical security lessons, covering attack chains and creative exploitation techniques used by ethical hackers. Whether you're a pentester, security engineer, developer, or blue teamer, you'll gain actionable insights to apply in your work.
🎧 New episodes every month.
🌍 Follow & Connect → LinkedIn (https://www.linkedin.com/showcase/hacked-and-secured/about), YouTube (https://www.youtube.com/@HackedAndSecured), Twitter (https://x.com/HackedNSecured), Instagram (https://www.instagram.com/hackedandsecuredpod/), Website Link (https://hackedandsecured.buzzsprout.com/)
📩 Submit Your Pentest Findings → https://forms.gle/7pPwjdaWnGYpQcA6A (https://forms.gle/7pPwjdaWnGYpQcA6A)
📧 Feedback? Email Us → podcast@quailu.com.au (mailto:podcast@quailu.com.au)
This episode analyzes real-world pentest findings, specifically nOAuth account misbinding and assumed-breach leading to domain admin access, revealing how trust assumptions compromise systems.
28 Aug 2025
Ep. 12 – Timing Attacks & Mobile OAuth Hijack: When Microseconds and Misflows Betray You
Host [Host Name] interviews security researcher [Guest Name] about timing attacks and mobile OAuth hijacks that exploit microsecond delays and misconfigured flows.
24 Jul 2025
Ep. 11 – Account Takeover, Token Misuse, and Deserialization RCE: When Trust Goes Wrong
This episode explores real-world vulnerabilities like account takeover and token misuse that occur when trust between systems falters, leading to serious security breaches.
26 Jun 2025
Ep. 10 – Cookie XSS & Image Upload RCE: One Cookie, One File, Full Control
This episode analyzes how a cookie-controlled XSS and a malicious image upload led to full account and server compromise, revealing the dangers of subtle misconfigurations.
29 May 2025
Ep. 9 – Directory Traversal & LFI: From File Leaks to Full Server Crash
This episode analyzes directory traversal and local file inclusion exploits, revealing how attackers leverage trusted paths to escalate from data leaks to complete server compromise.
24 Apr 2025
Ep. 8 – OTP Flaw & Remote Code Execution: When Small Flaws Go Critical
A broken logout flow let attackers hijack accounts using just a user ID. A self-XSS and an IDOR exposed stored data. And a forgotten internal tool—running outdated software—ended in full Remote Code Execution. This episode is all about how small bugs, missed checks, and overlooked services can lead to serious consequences. Chapters: 00:00 - INTRO 01:22 - FINDING #1 - The Logout That Logged You In 07:12 - FINDING #2 - From Signature Field to Shell Access 14:40 - OUTRO Want your pentest discov...
10 Apr 2025
Ep. 7 – IDOR & SSTI: From File Theft to Server-Side Secrets
A predictable ID exposed private documents. A crafted name leaked backend files. In this episode, we break down two high-impact flaws—an IDOR that let attackers clone confidential attachments, and an SSTI hidden in an email template that revealed server-side files. Simple inputs, big consequences. Learn how they worked, why they were missed, and how to stop them. Chapters: 00:00 - INTRO 01:28 - FINDING #1 – IDOR to Steal Confidential Files with Just an Attachment ID 09:05 - FINDING #2 – Serv...
A single uppercase letter unlocked an admin panel. One malformed request hijacked user sessions. In this episode, we break down two real-world exploits—a 403 bypass and a request smuggling attack—that turned small oversights into full system compromise. Learn how they worked, why they were missed, and what should have been done differently. Chapters: 00:00 - INTRO 01:18 - FINDING #1 – The 403 Bypass That Led to Full Admin Control 08:17 - FINDING #2 – Smuggling Requests, Hijacking Responses 1...
13 Mar 2025
Ep. 5 – Stored XSS & SQL Injection: Small Flaws, Big Breaches
A simple filename triggered stored XSS, hijacking accounts and stealing API keys. A SQL injection bypassed a web firewall, dumping an entire database in one request. Both attacks exploited basic security flaws—flaws that should have been caught. Learn how these exploits worked, why they were missed, and what should have been done differently. Want your pentest discovery featured? Submit your creative findings through the Google Form in the episode description, and we might showcase your findi...
27 Feb 2025
Ep. 4 – Exposed Secrets & Silent Takeovers: How Misconfigurations Open the Door to Attackers
Exposed secrets, overlooked permissions, and credentials hiding in plain sight—each one leading to a critical breach. In this episode, we break down three real-world pentest findings where a forgotten file, a misconfigured setting, and a leaked credential gave attackers full control. How did they happen? How can you find similar issues? And what can be done to stop them? Listen now to learn how attackers exploit these mistakes—and how you can prevent them. Want your pentest discovery featured...
13 Feb 2025
Ep. 3 – One Request, One URL, One Bluetooth Hack: Three Takeovers That Shouldn’t Have Happened
How can attackers take over accounts, networks, and devices—without credentials? In this episode, we break down three real-world security flaws that prove authentication alone isn’t enough: Account Takeover – A single request bypassed email verification, locking out store owners.Internal Network Compromise – A hidden admin URL and hardcoded access key gave attackers full control.Smart Device Hijack – A community-submitted finding reveals how Bluetooth vulnerabilities allowed remote command ex...
What if you could take over an account—not by cracking a password, but by chaining two overlooked vulnerabilities? What if a single CSRF exploit let attackers reset security questions and hijack accounts? And what if manipulating an authorization token could escalate privileges? In this episode of Hacked & Secured: Pentest Exploits & Mitigations, we break down three real-world pentest findings that prove creative exploitation turns small flaws into critical security risks: Chaining ID...
30 Jan 2025
Ep. 1 – Breaking OTP Security, Exploiting Static Domains & Privilege Escalation via Role Misconfigurations
What if your OTP security wasn’t secure at all? What if a static domain—something most people ignore—could lead to full account takeover? And what if flawed role management allowed admins to escalate privileges? In this episode of Hacked & Secured: Pentest Exploits & Mitigations, we break down three real-world security failures that turned minor oversights into critical exploits: Leaking OTPs in API responses – Breaking authentication at the source.Static domain to account takeover – ...
30 Jan 2025
Intro to Hacked & Secured: Pentest Exploits & Mitigations – What to Expect!
If you know how attacks work, you’ll know exactly where to look—whether you’re breaking in as an ethical hacker or defending as a blue teamer. Welcome to Hacked & Secured: Pentest Exploits & Mitigations—the podcast that breaks down real-world pentest findings and exposes critical security flaws before attackers do. Red team tactics – How vulnerabilities are found and exploited. Blue team defenses – How to detect, mitigate, and prevent attacks. Real pentest insights – Lessons...
Reach and audience
Public platform figures. Ratings count people who left a rating, not total listeners.
YouTube views
239
Score snapshot 15 Sept 2025
Podcast Authority Score: 38 / 100
A composite of feed quality, social presence, YouTube performance and engagement. Read the methodology.
Pod Engine is an independent podcast discovery and analytics service and is not affiliated with or endorsed by this podcast. Artwork and show content belong to their owners. Full legal notice.
Explore this show Podcast research with Pod Engine