LockFlux

60 posts

LockFlux banner
LockFlux

LockFlux

@LockFlux404

Fluxing auth gates—one 403 at a time.

Sumali Kasım 2025
23 Sinusundan2 Mga Tagasunod
Naka-pin na Tweet
LockFlux
LockFlux@LockFlux404·
Started my bug bounty journey today as a beginner. Working toward my first valid bug and my first bounty. Watching @4osp3l’s journey pushed me to finally start mine. If you’ve been in the field, I’m open to guidance — let’s grow. I’ll be sharing my progress here. #BugBounty
English
0
0
1
32
LockFlux nag-retweet
Youssef mohamed (Tyrion)
Youssef mohamed (Tyrion)@Youssef12142311·
ًWrite-up is now available you can read it here @youssefmohamedsaadhelal1214/from-zero-auth-to-admin-access-c303c0dbe4f8" target="_blank" rel="nofollow noopener">medium.com/@youssefmohame… Follow Me to Stay updated with more Findings
Youssef mohamed (Tyrion)@Youssef12142311

Alhamdulillah This my Last Activity in Bug Hunting First Critical = First Accepted 🔥 I have been rewarded with $$$$ from AT&T and $$$ From Yahoo Write-up Coming soon stay tuned

English
10
23
235
12.1K
LockFlux nag-retweet
obscaries ❘ AppSec
obscaries ❘ AppSec@obscaries·
🔥 If you’re serious about bug bounty, this repo is pure gold. 📦 Bug Bounty Reference by @ngalongc 🔗 github.com/ngalongc/bug-b… 📌 Why it’s a game-changer: ✅ Real-world disclosed reports — not just theory ✅ Organized by bug class: XSS, SSRF, IDOR, RCE, you name it ✅ Peek inside the actual hacker mindset 🧠 ✅ Connect the dots across different targets & reports 🚀 Pro-level way to use it: Pick a vulnerability class Read 5+ reports in that category Map out sources → sinks → attack chains Apply those patterns to live targets ⚠️ Stop memorizing payloads. Start recognizing patterns. #BugBounty #InfoSec #CyberSecurity #EthicalHacking #WebSecurity #HackerMindse
English
0
80
330
14K
LockFlux nag-retweet
Koupon
Koupon@Shabosec·
I found this Admin portal using Y-Dork site:Target.com inurl:login | inurl:admin | inurl:login | inurl:logon | inurl:sign-in | inurl:signin | inurl:signup | inurl:sign-up | inurl:dash | inurl:portal | inurl:panel | inurl:register | inurl:administrator 🔥🔥🔥🔥🔥
Koupon@Shabosec

F**CK Admin Account Takeover 😲😲😋 Tips Username:Admin Password:QWERTY1234$ 🔥🔥🔥 Big up @GodfatherOrwa @badcrack3r @4osp3ll Patient is Virtue 🚀🚀🚀🚀

English
4
20
171
12.6K
LockFlux nag-retweet
obscaries ❘ AppSec
obscaries ❘ AppSec@obscaries·
An absolute goldmine for bug bounty hunters 👀💥 A massive collection of real, disclosed HackerOne reports — organized by vulnerability type, impact, and target 🎯 If you want to go beyond theory and actually understand how real-world exploits work… this is it. Study patterns. Learn impact. Hack smarter. 🚀 🔗 Source: github.com/reddelexc/hack… #BugBounty #InfoSec #CyberSecurity #EthicalHackin
English
3
124
591
24.2K
LockFlux nag-retweet
zack0x01
zack0x01@zack0x01_·
When using claude or other AI , Don't ask it : find me an ssrf !! Ask: List me parameters that are pulling data from the server, then test manually or give it to nuclei templates or ask it to confirm it , don't be 100% dependent on the AI !
English
4
14
192
6.1K
LockFlux nag-retweet
DinDinDin
DinDinDin@comores_11·
🔥 XSS Tip: Unicode Normalization Don't give up if <, >, " or ' are filtered ! Many apps normalize Unicode after the WAF/security layer. Some bypass variants (URL-encoded): 🔹 < ➔ %EF%BC%9C 🔹 > ➔ %EF%BC%9E 🔹 " ➔ %EF%BC%A2 🔹 ' ➔ %EF%BC%87 🔹 ` ➔ %EF%BD%80 For example, inject %EF%BC%9Cscript%EF%BC%9E and check if it reflects as