pwnx0's profile picture.

Pwnr

@pwnx0

Pinned

"I still believe that one day I will reach my dream, my self, what I want." ~M.D


I will never understand how someone can look at the endless signs of the Creator in this world and still deny His existence. I hope I never lose that sense of faith.


Pwnr reposted

Just posted an addendum to 'Funky chunks' with a couple of bonus smuggling techniques. Check it out: w4ke.info/2025/10/29/fun…


Pwnr reposted

🚨 Doing a giveaway for my Blind XSS Masterclass Most people think they know XSS, until they meet blind XSS, the kind that fires where you’ll never see it. Same methods that helped me earn $250K+ from real reports. hhub.io/nahamsecbxss 🎁 Retweet and reply to enter.

NahamSec's tweet image. 🚨 Doing a giveaway for my Blind XSS Masterclass
Most people think they know XSS, until they meet blind XSS, the kind that fires where you’ll never see it.
Same methods that helped me earn $250K+ from real reports. hhub.io/nahamsecbxss
🎁 Retweet and reply to enter.

Pwnr reposted

I made this script to fuzz non-printable characters. It takes a URL and fuzzes after and before the `/`.

h4x0r_dz's tweet image. I made this script to fuzz non-printable characters. It takes a URL and fuzzes after and before the `/`.

Yes, with HTTP/1.1 it’s straightforward: just create an Intruder payload like §XX§, use a brute force payload set abcdef0123456789, and add two processing rules: Add % and URL-decode. Unfortunately, HTTP2 is a binary protocol, so that trick won’t work: you’d need a ketled request

zakfedotkin's tweet image. Yes, with HTTP/1.1 it’s straightforward: just create an Intruder payload like §XX§, use a brute force payload set abcdef0123456789, and add two processing rules: Add % and URL-decode.
Unfortunately, HTTP2 is a binary protocol, so that trick won’t work: you’d need a ketled request


Pwnr reposted

🔴 Proud to share our latest finding CVE-2025-52665 (RCE) in UniFi OS, scored 10.0 CVSS, discovered with @3zizMe_ at @CatchifySA . catchify.sa/post/cve-2025-… Enjoy!


Pwnr reposted

If you're excited to see the WhatsApp bug thrown @thezdi - free to watch my talk from @reconmtl 2025 on 4 remote bugs I discovered last year! While they're not 0-click RCE - there are some remote corruption and funny logic bugs in there. youtube.com/watch?v=bre5bA…

datalocaltmp's tweet card. Recon 2025 - Call, Crash, Repeat: Hacking WhatsApp

youtube.com

YouTube

Recon 2025 - Call, Crash, Repeat: Hacking WhatsApp


Pwnr reposted

Had some recent success using untranslatable Unicode in place of a "?" when attacking URL parsers for SSRF/OAuth issues. What worked was... \udfff -> � -> ? Therefore... {"redirectUri":"https://attacker\udfff@[victim]/"} Equals... Location: https://attacker?@[victim]/

samwcyo's tweet image. Had some recent success using untranslatable Unicode in place of a "?" when attacking URL parsers for SSRF/OAuth issues.

What worked was...
\udfff -> � -> ?

Therefore...
{"redirectUri":"https://attacker\udfff@[victim]/"}

Equals...
Location: https://attacker?@[victim]/

Pwnr reposted

Earlier this year, @infosec_au and I discovered multiple vulnerabilities that allowed us to access the back office admin panel of ClubWPT Gold (the World Poker Tour's website) where we could manage customer data, KYC, and more. Read the writeup here: samcurry.net/hacking-clubwp…


Pwnr reposted

شاركوه صدقة جارية لعلها تشفع له عند ربه #صالح_الجعفراوي


Pwnr reposted

﴿إِن يَنصُرْكُمُ اللَّهُ فَلَا غَالِبَ لَكُمْ﴾❤️‍🩹.


Pwnr reposted

RIP Hero💔


Pwnr reposted

Hacking is literally a drug. You're always just trying to replicate the feeling of getting that first shell, getting that first bounty, getting that first Domain Admin account. You're ecstatic for maybe an hour and then you're back on the grind trying to get that high again.


Pwnr reposted

“My name is Palestine and I will survive” 📸 Sliman Mansour

Palestine_UN's tweet image. “My name is Palestine and I will survive”

📸 Sliman Mansour

Pwnr reposted

Interested in Spring Boot Actuators in the context of bug bounty hunting? I wrote something - nothing new - just some insights ;) Article: dsecured.com/en/articles/sp… Retweet appreciated! Dont expect 0days or some fancy magic.


Ever since #ChatGPT started ‘thinking for a better answer’ it actually became much dumber.


Pwnr reposted

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…


Pwnr reposted

For all non-french speakers out there, I finally found the time to write the article associated to "1001 ways to PWN prod!" ^.^ thinkloveshare.com/hacking/1001_w… For all those that welcomed this talk so well - cc @clintgibler @absoluteappsec @yeswehack @intigriti @chybeta @ManoMano_Tech

TheLaluka's tweet image. For all non-french speakers out there, I finally found the time to write the article associated to "1001 ways to PWN prod!" ^.^

thinkloveshare.com/hacking/1001_w…

For all those that welcomed this talk so well - cc @clintgibler @absoluteappsec @yeswehack @intigriti @chybeta @ManoMano_Tech

Pwnr reposted

مقاله لطيفه 👌: شخص حصل على المركز الاول في CTF Bug Bounty Village في ديفكون وكتب مقالة عن التحديات : shubhamchaskar.com/defcon-bbv-ctf/


United States Trends

Loading...

Something went wrong.


Something went wrong.