secshad0w1 @TechRubin
Cyber Security | OSCP Gujarat, India Joined February 2018-
Tweets266
-
Followers14
-
Following312
-
Likes143
man I was reading some articles about sqli exploitation with WAF bypass and I found this crazy good article idk about u but I found it so impressive, professional pentesters owns BB hunters lets just say this vaadata.com/blog/exploitin…
X-Forwarded-Host isn't dead. You're just testing it wrong. Try these variations that bypass WAFs ⚡ • X-Forwarded-Host: target.com, evil.com • X-Forwarded-Host: target.com:@evil.com • X-Forwarded-Host: tаrget.com (Cyrillic 'а') Double-parse vulnerabilities are everywhere.
WAF bypass techniques to achieve IDOR New short course out too youtu.be/X3Wu5_GcEY0 #bugbounty
Success in bug bounty requires immense discipline. If you can overcome the distractions and focus hard enough, train hard enough, commit hard enough to find success, you can do anything you put your mind to.
Top 100 bug bounty tips: Always diff JavaScript files – new endpoints hide in subtle variable or function additions. Search for prototype pollution sinks – especially merge, extend, cloneDeep, or custom deep merge logic. Inject Unicode homoglyphs to bypass naive blacklist filters. Force-desync with TE.CL payloads to reveal hidden internal routing. Fuzz for HTTP/2 anomalies – many servers improperly downgrade to HTTP/1.1. Brute-force hidden GraphQL fields using __schema misconfigurations. Inject 2nd-order SQL payloads into logs, exports, or analytics fields. Use non-ASCII whitespace to bypass WAF regex patterns. Probe for /api/v1/export?format= endpoints for RCE via unsafe CSV/Excel exports. Check forgotten CRON endpoints – they often require only a timestamp parameter. Look for internal-only S3 buckets exposed via presigned URL misconfigs. Send invalid JWT algorithms such as alg:none or forged RS256→HS256 key swaps. Exploit file upload “mime-only” validation using polyglot payloads. Use X-Original-URL and X-Rewrite-URL headers to bypass path-based ACL rules. Abuse cache poisoning by injecting %2F, %2e, %2F%2e normalizations. Check for dangling DNS → S3 / Azure / Heroku subdomain takeovers. Smuggle hidden parameters using ;param=value between path segments. Test for PDF-based XSS through annotation JavaScript or embedded Launch actions. Look for weak Origin validation (e.g., *.evil.com matches reallyevil.com). Replay expired password-reset tokens—many APIs fail to invalidate old ones server-side. Inject caching keys with emojis – many CDNs normalize inconsistently. Perform race attacks using 200–500 parallel requests to bypass inventory or money checks. Exploit weak UUIDv4 assumptions – some apps use predictable UUIDv1 timestamps. Test GraphQL batching abuse to bypass rate limits. Look for misconfigured gRPC endpoints reachable via plaintext HTTP/2. Leverage IDOR in PUT/PATCH methods — often forgotten in access checks. Search JS bundles for Sentry DSNs, then check for exposed error logs with PII. Check WebSockets for hidden actions using custom opcodes or internal events. Use JSON smuggling (true, [], "") via Content-Type: application/json; charset=x variants. Try HTTP parameter pollution in both body + query simultaneously. Use intentional UTF-7 mis-detection to force XSS in ancient parsers. Tamper with encryption padding to detect padding-oracle leaks. Try null-byte injection in emails to override routing or create aliases. Search for admin-only HTTP verbs like SEARCH, COPY, PROPFIND. Check for timing attacks on password checks using high-precision RTT measurements. Use CRLF injection to poison logs → chained into 2nd-order exploits. Try OAuth PKCE downgrade attacks by forcing code_challenge_method=plain. Check API diff between mobile and web clients – mobile often has more privileges. Upload GIF polyglots as SVG to bypass extension checks. Attempt XXE via DOCX/PPTX – they’re just ZIPs containing XML. Bruteforce 6-digit TOTP backup codes when rate limiting is only on the UI. Check password reset flows for multi-step state confusion. Abuse template engines like Twig/Jinja2 via SSTI markers {{7*7}}. Replay OAuth id_tokens across subdomains. Many trust them blindly. Abuse Flask debug cookies leaked via JS or logs. Force XML parsers into Billion Laughs to detect XXE-lite behaviors. Check for unsafe YAML parsers enabling object deserialization. Search Burp history for hidden verbs (OPTIONS reveals CORS secrets). Abuse default Kubernetes endpoints if the company exposes dev clusters. Check CSR generation endpoints for key-injection. Use browser quirks: Safari’s weird handling of application/x-www-form-urlencoded. Try serving JS with mixed encodings to bypass CSP. Fingerprint backend tech with subtle error messages via malformed JSON. Test storage bucket CORS policies – many allow * on Authorization. Fuzz chunked encoding boundaries for request smuggling. Check if password reset tokens work cross-site (web ↔ mobile). Probe WAF for bypasses using %c1%9c UTF-8 overlong sequences. Modify JS prototype chains at runtime to change server-validated fields. Test for CSP nonce reuse – reused nonces = instant script injection. Use HEAD requests on internal endpoints to leak metadata. Abuse internal message queues (RabbitMQ/Kafka) if reachable over HTTP bridges. Try DNS rebinding on dev or staging panels. Check image processing libs for RCE via EXIF. Test X-Forwarded-Host manipulation for password-reset link poisoning. Look for insecure MD5 hashes in signatures. Check for WebView bridge injection in mobile apps. Attempt double-JSON wrappers ({"data":"{\"a\":1}"}) to access undocumented parsing. Look for SSRF via IPv6 literals ([::], [::1], IPv6 short forms). Check for open firebase / firestore DBs in mobile apps. Try serving malicious .wasm files to bypass client-side filters. Look for regex DoS on user-supplied fields. Fuzz XXE via SVG upload even when images are "sanitized." Try HTTP downgrade attacks via Upgrade-Insecure-Requests header tampering. Use 0 or null values in request bodies to break logic. Abuse URL parsing inconsistencies (@, #, ?, ;). Look for unsafe server-side PDF generation → template injection. Try "shadow" parameter names using user[0], user[], user (space). Fuzz ETags for cache key manipulation. Exploit SMTP header injection via contact forms. Use binary payloads to find parsers expecting JSON by mistake. Check whether backups leak via /~user home directories. Test GraphQL depth/limit abuse for DoS. Use browser polyglots HTML/SVG/MathML for XSS bypasses. Bruteforce short-lived JWTs when entropy is low or non-random. Test for user enumeration via subtle timing differences. Check for legacy API versions still accepting privileged calls. Try TRACE requests to leak headers and session cookies. Test WebSocket compression (permessage-deflate) for CRIME-style leaks. Inspect Android manifest for exported activities that leak auth tokens. Look for CRLF in redirect URLs for header injection. Fuzz HTML sanitizers for attribute mutations (). Exploit protobuf message fields by adding unexpected nested elements. Bypass filters with malformed XML entities (&;lt;). Bruteforce hidden localStorage flags shielding beta features. Test for insecure direct SQL queries via BI/analytics dashboards. Use timing-based probing on server-side crypto. Look for admin panels under /v2/internal/ or /v1beta/admin. Fuzz for unsafe SSRF via Gopher/FTP schemes. Try poisoning DNS resolvers via malicious NS record responses. Always inspect every binary file — firmware, WASM, mobile libs hide gold.
New bug bounty resource 🚀 The Cache Poisoning Bible - Part 1: Advanced Fundamentals Everything I wish I knew when I started: • Cache key architectures • CDN comparison guide • Advanced detection methods • Real-world patterns medium.com/@Aacle/the-cac…
A few months ago, I began studying bug bounties extensively. I've made my list public, and you can submit links to help expand it! docs.google.com/spreadsheets/d…
Find the full article here ⤵️ yeswehack.com/learn-bug-boun…
Use NextJS? Recon ✨ A quick way to find "all" paths for Next.js websites: DevTools->Console console.log(__BUILD_MANIFEST.sortedPages) javascript:console.log(__BUILD_MANIFEST.sortedPages.join('\n')); Cred = linkedin.com/in/0xsojalsec?… #infosec #cybersec #bugbountytips
@malekmesdour Fantastic write-up! I gained so much insight from this!
A fun NoSQL vuln that caused DOS: I sent a PUT request of {"field":"last_name","value":{"$ne":null}} which persisted and crashed the Teams/Admin UI for all users within the organization LOL #bugbounty #infosec Normal request body was: {"field":"last_name","value":"mason"} Changed it to: {"field":"last_name","value":{"$ne":null}} which caused the backend to store an object instead of a string, so downstream code that expected last_name to be a string caused Teams/Admin UI crashed org-wide.
2015: - Clash of Clans - Subway Surfers - Pokémon - Shadow fight 2 2019: - PUBG - Minecraft - Fortnite - GTA V 2025: - X - GitHub - VS Code - ChatGPT - Cursor
Tip: When testing, try injecting a null byte (\u0000) into unexpected parameters. You never know how the backend will handle it — sometimes a small injection can completely break features like the invitation system. #BugBounty #BugBountytips #Hacking #Cybersecurity
Have you checked out @hadriansecurity's subwiz? It's a recon tool that uses ML to predict and resolve subdomains👇
New Hackyx Version 🚀🚀 hackyx.io - AI Search Mode - New dashboard to manage content - Automatically fetch new write-ups, bug reports and articles - RSS feed crawler - A queue system to handle jobs - Content with embeddings for better search - Filtered content to avoid garbage articles More to come soon, stay tuned
This email domain confusion technique from @garethheyes is so cool! Some really weird behavior can be found between different mail agents and the right characters/symbols 🤔
Sometimes you can control the href value in HTML tag<a>. So it's a good place for XSS payload! We've created a scheme how to use various encodings in href to bypass filters. gist.github.com/hackerscrolls/… @XssPayloads #BugBountyTip #Bypass
I'm thrilled to finally share my research on HTML parsing and DOMPurify at @grehack 2024 📜 The research article is available here: mizu.re/post/exploring… The slides are available here: slides.com/kevin-mizu/gre… 1/3
UzunDz @xUzunDz
182 Followers 520 Following
ElsiePullan @xSQ7U432NNPy7tH
49 Followers 3K Following
octodi @0ctodi
9 Followers 163 Following
Rakesh Kirola @rakesh_2311
209 Followers 2K Following Learner | Cricket lover | eWPT | eMAPT | CAP. Views are personal. RT's are not endorsements!!
نواف الحربي @nawaff_alharbii
48 Followers 501 Following
Hardik Rathod ⚡ @imhardikrathod
308 Followers 1K Following Penetration Tester | Bug Bounty Hunter | CTF Player | Intigriti | Detectify | Yogosha | CVE-2022-2775
Aaditya.ai 🤖 @itstheaadii
1K Followers 3K Following 24 | Learner | AI Agents | Gen AI | Automation | Startups | Community Builder | Open-source | RAG | AI Researcher | Artist by choice, Engineer by default🤓
GrowfSec @GrowfSec
233 Followers 5K Following Chief Disinformation Officer. Unemployed, views are exclusively my own and not my non-existent employer.
Kalpesh Jha @jha_kalpesh
109 Followers 398 Following web app pen-testing/bug bounty hunter/ Security infosec
Ashwin Raghavan @GripFangWolf
21K Followers 1K Following Full time trader | Ex PM & Founding Engineer @PhonePe | @bitspilaniindia Hyd Alum | Serendipity, Intuition and Conscientiousness 🙂 | No paid advisory / courses
Anthropic @AnthropicAI
1.4M Followers 2 Following We're an AI safety and research company that builds reliable, interpretable, and steerable AI systems. Talk to our AI assistant @claudeai on https://t.co/FhDI3KQh0n.
Harrison Green @hgarrereyn
2K Followers 280 Following PhD student @S3DatCMU @CyLab | Reverse Engineer @DiceGangCTF | Senior Otter @osec_io | prev. @Margin_Research, @MayhemSec, @LabDurrant
Sunderdeep - Volklub @volklub
67K Followers 4K Following Auto Commentator | Engineer | Web Developer GLA 220D | T-Roc | Slavia | Polo Introvert | 90K+ UpWork Hours Car Consultation & PDI - 90418 37377 or Click ↓
sudi @sudhanshur705
6K Followers 801 Following If there's non zero chance, the effort is infinite, anything is possible
Ahmad Shuja @0xElement
966 Followers 425 Following Security Engineer | Team Lead @cobalt_io | Red Team @synack | Learner
BattleAngel @battleangel09
1K Followers 207 Following OSCP | ASCP | Red Teamer | Author | Speaker | Bug Bounty Hunter @SynackRedTeam | whitehat @Immunefi | Level 5 SRT | Synack Acropolis | Synack Envoy
Sabarmati Riverfront ... @SRFDCL
3K Followers 26 Following Official Twitter Handle for updates on the Sabarmati Riverfront Development Corporation Ltd.-Reconnecting Ahmedabad to its River.
Ahmed Elheny @Ahmex000
930 Followers 934 Following Security Researcher | BUG HUNTER. eJPT | eWAPTX | OSCP♻️
Tuan Anh Nguyen⚡️... @haxor31337
16K Followers 2K Following 29 y/o Bug Bounty Hunter and Red Teamer at Viettel Cyber Security. Brand Ambassador @Hacker0x01 - Researcher Spotlight @Bugcrowd
Vitor Falcão "busfac... @busf4ctor
5K Followers 636 Following Full-Time Bug Bounty Hunter | 🥈 2x Google bugSWAT 2nd Place | 🥇 1x Google bugSWAT Best AI VRP Researcher
Alisa Esage Шевч�... @alisaesage
41K Followers 99 Following Independent hacker and researcher, owner of Zero Day Engineering @zerodayalpha
Daniel Kokotajlo @DKokotajlo
31K Followers 275 Following
UzunDz @xUzunDz
182 Followers 520 Following
Evan Graham @LuaKTT
60 Followers 599 Following
Jayson Grace @Jayson_Grace
344 Followers 807 Following Purple Team Lead, automater of infra, and tool dev. Opinions (which I hardly voice on here) are my own and not my employers’
arthur aires @arthurair_es
4K Followers 393 Following Bug Hunter at HackerOne ex-Medical Student at the Federal University of Amapá [email protected]
paramil @m0ram1de
719 Followers 205 Following Cybersecurity Student & Bug Hunter @SynackRedTeam GFACT | GSEC | GCIH | GWAPT
Blaklis @Blaklis_
12K Followers 80 Following Security researcher - my researchs will be on https://t.co/2PnyCvqAIm Mostly inactive, soon replicated from BSKY.
BRute Logic @BRuteLogic
65K Followers 285 Following #CyberSec #AI | #XSS #SQLi #SSRF | #Bypass #Recon | @KN0X55 | https://t.co/u13UVOyMLH | https://t.co/9vBkBKbtTw | https://t.co/rPNLkkPaWM | https://t.co/NjpWguuoov
ProjectDiscovery @pdiscoveryio
42K Followers 144 Following Real, exploitable vulnerabilities. No noise. Nuclei scans fast. Neo closes the loop. @pdnuclei × @neo_ai_engineer
Gunnar Andrews @G0LDEN_infosec
5K Followers 935 Following Hack Stuff | Code Stuff | Fitness | Kaizen OSCP | OSWA | OSWE https://t.co/4lgaVGZxd0 https://t.co/db6Gmb2ImT https://t.co/uY8NkPXaqA
Ynoof @YnoofAssiri
2K Followers 958 Following https://t.co/hWlG50y2rH | https://t.co/APE1ZQzOy8 | https://t.co/Ih7QCur7lE
Masonhck357 @Masonhck3571
17K Followers 819 Following 🔍 Top 100 Bug Bounty Hunter @ Bugcrowd | 🇩🇴 Dominican | Ethical hacking fanatic | 🎮🎵 Lover | Keeping the digital world safe. opinions are that of my own
Youssef Sammouda (sam... @samm0uda
41K Followers 590 Following Security Researcher/Hacker 1st in Meta bug bounty program for 6 years Opinions are my own and not my employer's.
Chavda Zeel @ChavdaZeel
601 Followers 4K Following Pentester | @synack | Web Security | Learner | My tweets are my own
zonduu @zonduu1
6K Followers 284 Following Founder: @exposureintel & https://t.co/zw1tbhhmWj — Bug bounty hacker 🇦🇷 https://t.co/dMI1g4s8Gv — Side-Project: https://t.co/HChp37Z7s3
mem0 @mem0ai
18K Followers 22 Following Memory Layer for your AI agents. Open source: https://t.co/HqLHhUMUpN
PlexTrac @PlexTrac
2K Followers 821 Following #1 AI-Powered Pentest and Vulnerability Data Management Platform 💥 https://t.co/Qte4s76JvZ
XSS Report @XssReport
897 Followers 135 Following The official X account for the https://t.co/aVdNMc0ZRW project. Please use the link on the website as a contact
Barracks @BarracksArmy
378 Followers 40 Following Beyond the Lab rut. A Security Talent Intelligence Platform powered by proprietary behavioral Algorithms mapping a Candidates' Cognitive patterns.
Paku @ItPaku
109 Followers 289 Following जय श्री राम 🙇🏻♂️🚩. | BSCP | Cybersecurity Student | Learning and Exploring the World of Security.


































