xx$@Mxx @yoursSam076
Joined February 2017-
Tweets2K
-
Followers22
-
Following308
-
Likes3K
@lostsec_ @th3cyb3rc0p I have been using both in same way .. its working pretty good..
@mdp_sec Hi , AI agents can register/login pull otps, verification emails too.. how ??
Alright so to end 2025 I am going to post something that people have been requesting for quite some time.. As alot know, I have made over $1 million dollars from SSRF vulnerabilities alone. #ssrftips Below I will provide some information on some of the ways that I beat the blacklists/deny lists and cashed in. Any method I post below has worked for me personally in the past. I am not claiming that any of these ways are 'my' discoveries, and in no way am I trying to claim other's work as my own. Simply answering a question that gets asked of me almost daily. #bugbounty #bugbountytips #togetherwehitharder #ittakesacrowd #hackers #hacking #NewYearsEveBountyTips So lets get into it: Encoding: Everyone knows (or should know) about the ability to encode IP addresses. What alot of people dont know is that you can combine encoding types on a single IP. SO instead of encoding the entire IP, encode single octets etc. Example: Changing the Metadata IP to: 0251.254.169.254 this octal encodes the 1st octet only, leaving the rest of the IP the same. This is the exact method that allowed for my $180,000 from the Yahoo Bug Bounty Program in Oct 2018 Redirects: Alot of SSRF vulnerable functionality will follow redirects. What many people dont consider is multiple redirects. Never stop at just one. I have found many instances where an SSRF followed all redirects, and would properly block the final redirect to the target internal service (internal ip/metadata server). DO NOT STOP AT 1 REDIRECT! Instead of a single redirect, setup a simple php redirect script that will redirect the request back to the same end point multiple times before finally sending to the target IP/host. I have had many instances in the past where the target properly checks the response of the first 1,2, 3 ....6 redirects then magically on the 7th it no longer performs any valdiation and allows you to hit the metadata. I can't explain why this happens, but its happened enough that this is one of the very first things i test for when it comes to SSRF testing. TOCTOU: This is one of my fav's because it almost always can be used to bypass the initial fixes for an SSRF vulnerability. TOCTOU stands for: Time of Check Time of Use. When you pass a url to an SSRF vuln end point, the backend will take the host of this, resolve it (if its not already an IP), check against the allow/block list, then take action. Many frameworks will not cache the DNS lookup response that happens during the initial validation phase. When they forget to do this, having a subdomain properly setup for a TOCTOU check can allow for tricking their checks to allow for hitting banned resources. How it works: Server resolves aws.dawgyg.net to 1.1.1.1 and does their checks to make sure its not a blocked IP. After passing these checks the domain is passed to the function that will actually make the call. If the server did not cache the previous response, it will then resolve the host again as part of the flow to make the request. If you have a properly setup nameserver for this attack, then the instance they make the 1st DNS call, your server quickly changes the DNS entry and points it to the target IP (Metadata/Internal), so that when it gets to the function that makes the request, it resolves the host again and makes the request. HTTP 2 vs HTTP/1.1 vs HTTP/1.0 vs HTTP/0.9 Several have had success with this in the past. And again, I am not sure why this works sometimes. But if the request is using HTTP/2 and blocks your attempt, try and change it to an older version. I have had success with each of the above at least once (most of the time on Yahoo, but others as well). Simple/more common things: dns rebinding, create a hostname on your domain pointing to localhost or an internal IP. simplify the IP. example: 127.0.0.1 is blocked, so try 127.1, or 0.0.0.0, 0 etc. Theres tons of other ways that you can get creative and do things like this. This post is just sharing some of the more fun/more unique ways that I have had success in the past. This is not ment to be an exhaustive list of things to try, and is only ment to start your brain working to come up with weird/random/fun ways to beat the black lists. If you like the information, drop a like/comment/follow and let me know which of the above you have tried in the past, or are looking forward to trying out in 2026. If you end up having success with these, let me know as well!
Reduce Noise in Burp Suite with This Simple Trick! 🔥 💡 Just add the following patterns in Burp Suite under Proxy > Options > TLS Pass Through: .*\.google\.com .*\.gstatic\.com .*\.googleapis\.com .*\.pki\.goog .*\.mozilla\..* #bugbounty #bugbountytip
Alright web cache deception is fun ! here how to get started 1. watch this youtube.com/watch?v=70yyOM… 2. read this portswigger.net/research/gotta… 3. solve these labs 4. after this I have created a small delimiters and URL manipulation payloads here for more fun gist.github.com/freyxfi/96c8b0…
Security Tweet - Day 102 Use uncover to find third degree subdomains uncover -q 'org:"DoD Network Information Center"' | httpx -silent | nuclei -silent -severity low,medium,high,critical #cybersec #Awareness #bugbounty #Mindset #valueable #Tweet
BeeXSS is an automated tool to detect Blind XSS vulnerabilities in web applications. It injects payload, bypasses WAFs, and identifies backend execution flaws. Check it out here: github.com/AnonKryptiQuz/… #CyberSecurity #BlindXSS #Pentesting #BugBounty #hackingtools #redteam
Ghauri the undervalued SQL Injection Exploitation Tool. It Is Tested on varius applications, and it’s more effective than SQLmap. It will be added today in this tool: github.com/0xJin/awesome-… #BugBounty #BugBountytips
an XSS payload with Alert Obfuscation, for bypass RegEx filters <img src="X" onerror=top[8680439..toString(30)](1337)> <script>top[8680439..toString(30)](1337)</script> #infosec #cybersec #bugbountytip
Security Post - Day 84 #cybersec #infosec #securitycode #bugbounty #bugbountytip #SecurityDays
Security Post - Day 60 #BugBounty #BugBountytips #tipoftheday #tipster #Focus #CyberSecurity #streak
Security Post - Day 59 #CyberSecurity #scripts #codes #Tweet #natural #Tips #streak #bugbountytip
Security Post - Day 58 #CyberSecurity #scripts #posts #Tweet #security #bugbountytip #streak
XSS Payload confirm?.(1) Add to your List by knoxss #bugbounty #bugbountytips
p3n73st3r @p3n73st3r
1K Followers 1K Following #WebAppSecurityResearcher #Pentester #Sql_Injector #eWPTX eWPTX Holder, Now going for Other eLearnSecurity Certifications 😍
Amadi Charity @charityam1
159 Followers 2K Following Am a simple and easy going person. Love traveling
testtest @testte9022
70 Followers 3K Following
Sitalu @Sitalu7
0 Followers 1K Following
zoha @enilbarq
3 Followers 186 Following
VIBHU RASTOGI @RastogiVib22398
163 Followers 1K Following
Htet Aung Win @justambivertboy
5 Followers 410 Following
Nguyễn Trung Kiên @K1enNT
6 Followers 595 Following
ITPAT @IttipatJitrada
75 Followers 247 Following
NILESH MORE @nilesh_mor3
10 Followers 562 Following
Deandra @DeandraSec
735 Followers 4K Following Security Researcher | Bug Bounty🎯, Web&Mobile Apps Security | Red Team🔥 | Offensive Security
Anurag Kumar @anurag7676581
128 Followers 305 Following
Serge EYENGA @SergeEYENGA1
3 Followers 11 Following
Cyber Threat Hub @CyberThreatHub
7K Followers 4K Following Providing the Latest #Infosec #News, #Tools, and #Exploits #BugBounty
Cympire @CympireLtd
566 Followers 4K Following Disruptive Cyber Simulation #cyber #cybersecuritytraining #SOC #infosec #cyberrange #cyberresilience #security #blueteam #redteam #SIEM
0x221B @0x221B
476 Followers 2K Following Various infosec ramblings from the UK. https://t.co/M9QwzV8hfV
r00tz 🇮🇳 @yaser_s
2K Followers 2K Following 🚀CFP & Speaker Ops @BugBountyDefcon🏅@Hacker0x01 Brand Ambassador Canada🎖️@Bugcrowd Hacker Advisory Board 🏆Top Spots-US DoD🥈H1 Hack the Airforce7'22🥇HackUS
Axoss Cybersecurity A... @AxossAcademy
834 Followers 4K Following #HumanwareHardening 🐞 #CISSP #CCSP #CSSLP #Security #Training #ISC2 #SoftwareSecurity #CloudSecurity #devsecops
Abhi @AbhiX10010
2K Followers 910 Following Penetration Tester 💻 | Cybersecurity 🔑 Finding what others miss 🔍 Software Developer 👨💻 📩 DM for collaborations & paid promotions
Coffin @lostsec_
32K Followers 223 Following ʜᴇʟᴘɪɴɢ ᴏʀɢᴀɴɪᴢᴀᴛɪᴏɴꜱ ꜱᴛᴀʏ ꜱᴇᴄᴜʀᴇ ᴛʜʀᴏᴜɢʜ ʙᴜɢ ʜᴜɴᴛɪɴɢ, ᴏꜱɪɴᴛ ᴀɴᴅ ꜱᴇᴄᴜʀɪᴛʏ ʀᴇꜱᴇᴀʀᴄʜ | ᴡʀɪᴛᴇᴜᴘꜱ: https://t.co/39DXITYobD | ᴄᴏᴍᴍᴜɴɪᴛʏ: https://t.co/otIBnWOeua
Tabassum @ehtabbu
3K Followers 213 Following Security Researcher | Certified Penetration Tester| Coder 👩💻
drop @dropn0w
3K Followers 591 Following Offensive Security Consultant | HackerOne Ambassador for 🇧🇪 Belgium | Security Researcher | Views are my own
Aditya BISHT @cherry4akuma
713 Followers 5 Following 17 yo || Google ranked #1034 , MICROSOFT Recognised Ranked top 1%ile hackerone | 14k usd || Intigriti || Bugcrowd Open Source: Project Discovery Contributor
Ayush Bawariya @AyushBawariya1
262 Followers 107 Following Security researcher @synack || OSCP || Red teaming || Bug bounty hunter || Android Penetration tester || Pro Hacker HTB || CTF creator
obscaries ❘ AppSec @obscaries
4K Followers 1K Following ✦ Application Security Researcher ✦ Breaking the modern web stack ✦ Focused on client-side security ✦ Impact-driven tactics ⚡ 🌿 Open to collaborations
Jessie Ho @j3ssie
5K Followers 1K Following A passionate security engineer working on improving security automation with @OsmedeusEngine and @Vigolium
Moon 🌙 | Digital A... @Moonbrush___
93 Followers 52 Following Custom anime style art 🎨 | Commissions open 💌 | Visit and support on Patreon 💖
Rojan Rijal @mallocsys
956 Followers 50 Following Offensive security research & building @OphionSecurity
Jayesh Madnani @Jayesh25
14K Followers 507 Following Researcher in charge @ Ethical InfoSec Services | HackerOne Top 10 | https://t.co/JSX03Wv1vl
Omkar Mali🇮🇳 @OMK4RM4LI
2K Followers 324 Following • Yogosha Strike Force • Red Team at @pentabug• CEH• CPENT• LPT• CTF Player ⛳• Gamer🎮• Security Researcher
x1337loser @x1337loser
4K Followers 47 Following A 24-year-old Hacker, Gamer, Eater, Trainer, programmer(python, go, bash) Hungry learner, Noob at bug bounty😪😪
Mr.Hacker @mr_hacker0007
3K Followers 474 Following Bug Hunter @intigriti | Ex Bugcrowd | @TeamBounters | Time is precious. Waste it wisely :)
0x0Asif🇧🇩 @0x0asif
5K Followers 880 Following Security Researcher aka Bug Bounty Hunter | HackerOne|BugCrowd|Yogosha #bugbounty #whitehathacker || Follow me on social media @0x0asif
Godfather Orwa 🇯�... @GodfatherOrwa
28K Followers 2K Following Hacker | Bug Hunter | Cooker | Top 5 P1 Warrior On https://t.co/dzFQH75OWj | LevelUpX Champion | 10+ 0Days/CVEs
Tuan Anh Nguyen⚡️... @haxor31337
16K Followers 2K Following 30 y/o Bug Bounty Hunter and Red Team Lead at Viettel Cyber Security. Brand Ambassador @Hacker0x01 - Researcher Spotlight @Bugcrowd
Het Mehta @hetmehtaa
43K Followers 2K Following Security Engineer | Content Creator | I talk about Cybersecurity, Tech, Privacy, AI & Startups | Building @Sentynio @100xSecurity
ProjectDiscovery @pdiscoveryio
42K Followers 144 Following Real, exploitable vulnerabilities. No noise. Nuclei scans fast. Neo closes the loop. @pdnuclei × @neo_ai_engineer
Deepak Dhiman🇮🇳 @Virdoex_hunter
8K Followers 376 Following bbhunter-virdoexhunter^ | Top 10 on hackenproof | Top 5 as Indian | X-Bounty Hunter Inspiration:Stok,Aditya
Joseph Thacker @rez0__
74K Followers 1K Following christian. father. hacker. founder. advisor. podcast: https://t.co/1aFavJN2h8 blog: https://t.co/JBPT1CJWJH products: 🤖 https://t.co/EVhQl8HTlp $200/mo 📚 https://t.co/MMmhw0cnaz $0/mo
Gunnar Andrews @G0LDEN_infosec
5K Followers 938 Following Hack Stuff | Code Stuff | Fitness | Kaizen OSCP | OSWA | OSWE https://t.co/4lgaVGZxd0 https://t.co/db6Gmb2ImT https://t.co/uY8NkPXaqA
Sunil Yedla @sunilyedla2
9K Followers 259 Following Trying to make Internet a safer place 👨🏼💻 by helping companies find security loopholes.
𝚖𝚎𝚛𝚝 🦧 @mertistaken
8K Followers 600 Following hacker / bug bounty hunter / worldwide #1 on critical-high submissions https://t.co/djEccIleby
Ashutosh mishra @ashutoshmish_ra
838 Followers 113 Following SDE | Cyber Security Researcher | Bugcrowd MVP 🏆
RyotaK @ryotkak
12K Followers 652 Following Security researcher? | Icon: @MelvilleTw | Private: @RyotaK_Private | Misskey: https://t.co/63E5Rpv2pk | Blog: https://t.co/c7NFQXhV90
Iman Gurung @ImanGurung13
8K Followers 451 Following Computer Engineer, Ethical Hacker, Tatoo Lover, Blind xss king
Nicolas Grégoire @Agarri_FR
28K Followers 628 Following Web hacker and Burp Suite Pro trainer Refer to https://t.co/D5tRH7U2hg for trainings Follow @MasteringBurp for free tips and tricks
ashish_r_padelkar @engi_arp
2K Followers 127 Following Bug Bounties, HackerOne Top 25 Worldwide. Follow me on Insta ashishrpadelkar
Kuldeep Pandya @kuldeepdotexe
5K Followers 358 Following OSINT | Web | Binary | [email protected] | @SynackRedTeam Envoy && Hero
MiDo 🇵🇸 @mido0x0x
3K Followers 1K Following Cyber security consultant Bug hunter: https://t.co/JmsdNFvbbX #Zamalek ❤️
Vanessa @nesshaxs
3K Followers 889 Following #Hacking, #Lifestyle, #Fitness | (She/Her) Cybersecurity Profesh
Valerio Brussani @val_brux
3K Followers 1K Following Hacker / Bug Bounty | https://t.co/5GqSRkDoOW | @Hacker0x01 Ambassador | @SynackRedTeam SRT | Lead Pentester @Cobalt_io | @BugCrowd
Th3Pr0xyB0y @Th3Pr0xyB0y
1K Followers 534 Following Cyber Security Researcher | Bug Bounty Hunter | Developer | Building SaaS @cyberxplore @bxsshunter
Saajan Bhujel ❄ @saajanbhujel
2K Followers 853 Following Bug Bounty Hunter 👨💻 | Personal Site: https://t.co/1CACfWmu94 | HackerOne Profile: https://t.co/V9XNfq4qel
xor @equat0rium
4K Followers 258 Following reverse engineer, game & engine security researcher -- https://t.co/KtVIixRLnb
























