H1Xploit

139 posts

H1Xploit

H1Xploit

@H1Xploit

Bug Hunter | Business : [email protected]

Wkwk Land เข้าร่วม Nisan 2021
5 กำลังติดตาม145 ผู้ติดตาม
Aanya
Aanya@xoaanya·
Which domain is best for seo? .com .st .ai .app .io
English
136
1
151
27.6K
GitLawb
GitLawb@gitlawb·
Claude code leaked mirrored to Gitlawb. will never be taken down in decentralized git platform. repo link in reply
English
32
200
3.6K
197.9K
sashko.eth🇺🇦
sashko.eth🇺🇦@d0rsky·
Okey, it was fast. We got first company who moved to fee-based submissions. Who will find it first, will get a coupon from me
sashko.eth🇺🇦 tweet media
sashko.eth🇺🇦@d0rsky

Paid submissions? Let’s talk We need to be honest about what’s happening to bug bounty right now We live in AI era, where submission volume is growing fast, but signal is not A lot of reports getting lost, delayed, or stuck in review loops And this hurts everyone - especially professional whitehats with real findings Over the last months, we’ve been trying to fix this step by step Reputation points system was first you submit spam → you get penalty points → you lose ability to submit simple incentive on quality Then - MCP Which helps teams triage faster, identify duplicates, reduce review time. Many companies already using it. And now we are introducing a new option - submission fees. We’ve been hearing this request from many companies and honestly, it feels like a next logical step to make the game more fair for everyone. This is optional, not default, and not something every company will enable. Fees going to be small ($1-$5), so this is not about monetization too This is about adding a bit of friction, so people think twice before submitting something they are not confident in Because today, there is almost no downside to spam. With $20 subscription, any user can generate thousands of reports even without understanding of them. At the same time, we fully understand concerns, whitehats are our biggest asset and we still want new researchers to join the space, so we added: • free credits for new users (via coupons) • support for high-signal researchers Goal is very simple - improve signal without losing important reports I will keep you in a loop once any of HackenProof clients will enable it Lets fix bug bounty together

English
8
3
45
7.5K
H1Xploit
H1Xploit@H1Xploit·
@HackenProof One bug in one week is considered easy but one bounty in one week is a bit difficult. 🤸🏻‍♀️
English
0
0
1
65
Vagner Andrei
Vagner Andrei@VagnerAndrei98·
Started to do some Bug bounties on @HackenProof 2 months ago and managed to get some find some issues for a big and complex orderbook dex , but wanted to also share my biggest one so far. Bug bounties are for sure interesting and I will do more for sure soon, I plan to get big this year. 🫡🫡🫡
Vagner Andrei tweet media
English
16
5
239
7.5K
chux
chux@chux13786509·
@a_k_h_i_l__K If the command of the server looks like: node --inspect=0.0.0.0 server.js So you will be able to connect from any simple chrome browser by typing chrome://inspect in the address bar :)
English
1
0
5
1.5K
H1Xploit รีทวีตแล้ว
chux
chux@chux13786509·
Bug Hunters 🔥 Ever stumbled upon this weird message? "WebSockets request was expected" If you did, congratz! You just found a NodeJS server in debug mode, ready to quickly move on to RCE via simple DevTools 💥💥💥 Search for this message in Censys/FOFA and your automation 🤑
chux tweet mediachux tweet media
English
7
96
542
34.9K
H1Xploit
H1Xploit@H1Xploit·
@k_firsov @grok Where to find information about a domain pointing to a specific IP address with a context like this post?
English
1
0
1
130
Kirill Firsov
Kirill Firsov@k_firsov·
4) We discover that grafana.fearsoff.net points to IP address 13.214.193.141 on AWS. But this IP is not directly accessible because the AWS security group only allows Cloudflare IP ranges.
Kirill Firsov tweet media
English
4
1
23
7.8K
Intigriti
Intigriti@intigriti·
You just received a new private program invite... 🤠 What's the first vulnerability type you look for? 😎
English
20
3
78
16.2K
H1Xploit รีทวีตแล้ว
chux
chux@chux13786509·
There were some awesome answers, well done 💥 The explanation: 🤓 NGINX looks for the explicit path "/secret", without caring about case sensitive. But, if we add an extra character to the path, NGINX will no longer block it cause it another path, an the request will be forwarded to the Flask backend. The magic comes when Flask removes certain characters, for example \xA0. So by requesting the path "/secret\xa0", we'll be able to bypass the NGINX rule and access our secret 🔥
chux@chux13786509

Hackers 🔥 I’ve set up this Nginx that forwards traffic to a Flask server and blocks access to /secret - throwing 403 🛑 Can you find a way to bypass this restriction and access /secret? 🥷 Drop your ideas or tricks in the replies — let’s see how creative you can get! ⚡️

English
1
16
86
7.1K
ZeUs.36
ZeUs.36@ZeUsVuln·
Apparently, if you get scammed or unfairly treated by a program on @yeswehack , support won’t help you — just “talk to the program team again.” No real protection for hackers. So… we’re on our own? #bugbounty #infosec #YesWeHack
ZeUs.36 tweet media
English
9
0
41
4K
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
Ready to take on #PayloadPlz? On June 27-28, @BitK_ challenges you to craft a single payload capable of breaking multiple web-based challenges 👀 🎉 Good news: this challenge isn’t just for @_leHACK_ attendees - it’ll also be open online to anyone who wants to give it a shot. Exclusive swag awaits the top 3 on site, as well as the online winner! More info: yeswehack.com/page/yeswehack… #YesWeRHackers #leHACK2025
YesWeHack ⠵ tweet media
English
4
3
26
4.7K
H1Xploit
H1Xploit@H1Xploit·
@jesssperez95 @yeswehack Have you ever made a withdrawal at YesWeHack? How long? I made a withdrawal on June 10th but haven't received the funds in my bank account.
English
0
0
0
63
H1Xploit
H1Xploit@H1Xploit·
@umycomofficial really care about the security in their environment especially the security of their users, do not hesitate to use their services.
Umy.com (Download Umy App|Get $150 bonus@umycomofficial

🔒 Big thanks to @H1Xploit! 👏 As a white-hat expert, he identified critical security issues that ensure Umy's system remains safe and stable. Your expertise and selfless contribution are vital in helping us deliver secure services to our users. 💪 At Umy.com, system security and user data protection are our top priorities. We are committed to continuously enhancing security features to create an industry-leading crypto travel platform, ensuring that every user's privacy and data are fully protected. 🛡️ A huge thank you to @H1Xploit for safeguarding our platform, allowing us to continue providing exceptional travel experiences to users worldwide! 🌐 Stay tuned for more updates coming soon. #Umy #DataSecurity #SystemSecurity #Web3Travel #UserExperience

English
0
0
1
15
H1Xploit รีทวีตแล้ว
Umy.com (Download Umy App|Get $150 bonus
🔒 Big thanks to @H1Xploit! 👏 As a white-hat expert, he identified critical security issues that ensure Umy's system remains safe and stable. Your expertise and selfless contribution are vital in helping us deliver secure services to our users. 💪 At Umy.com, system security and user data protection are our top priorities. We are committed to continuously enhancing security features to create an industry-leading crypto travel platform, ensuring that every user's privacy and data are fully protected. 🛡️ A huge thank you to @H1Xploit for safeguarding our platform, allowing us to continue providing exceptional travel experiences to users worldwide! 🌐 Stay tuned for more updates coming soon. #Umy #DataSecurity #SystemSecurity #Web3Travel #UserExperience
English
15
1
17
916