How to access servers behind Cloudflare by bypassing the firewall?
@FearsOff#bugbountytips#cloudflare#firewall#bypass
1) Found a sweet hostname but Cloudflare Firewall blocks you? There's a neat trick attackers can use if the origin is misconfigured.
🎉 You’ve been asking for it. The Caido Scanner plugin is finally here.
Run checks in the background or scan specific requests on demand to find issues like reflected XSS, SQL injection, and CORS misconfigs.
All checks are open source. Add your own and help the list grow 💪
Just released a new recollapse version thanks to @ryancbarnett and @4ng3lhacker after their talk in @BlackHatEvents today.
What’s new?
💥Mode 6: Fuzz case folding/upper/lower
💥 Mode 7: Fuzz byte truncations
💥 Recollapse is now available to use as a python library and…
Join the OneTest Discord! The XSS extension is running a bit late, but we’re working hard to ship the beta ASAP. Check out this quick demo video, all updates and test-lab access will be shared there. See you inside! 👇
discord.gg/tPgThJ6RAU
I just built a custom action to let you test for race conditions with a single click! No tab groups required, and it uses the cutting edge single-packet attack under the hood.
HTTP Request Smuggling Lab Walkthrough: Confirming a CL.TE vulnerability via differential responses.
How to identify CLTE Vulnerabilities:
1. Send request to repeater
2. Downgrade protocol to HTTP/1.1
3. Disable "Update Content-Length"
4. Set Content-Length to 6
5. Add…
the research paper is out:
Next.js and the corrupt middleware: the authorizing artifact
result of a collaboration with @inzo____ that led to CVE-2025-29927 (9.1-critical)
zhero-web-sec.github.io/research-and-t…
enjoy the read!
Day 4 of launch week!
Introducing Nuclei -ai flag. We’re making custom vulnerability detection easy for everyone. No YAML skills required.
Here's what's new in v1 👇
(1/7)
Legacy vulnerability management tools weren’t built for today’s internet. We’re changing that.
Next week, we’re launching ProjectDiscovery v1 — a faster, more scalable, and more actionable approach to security.
Stay tuned. 👇
2 Followers 133 FollowingFront-End Freelancer & Pentester: 3+ سنوات في بناء واجهات React وتأمين التطبيقات عبر TryHackMe/HackTheBox. تواصل: +201127799760
2 Followers 111 FollowingFuture smart contract engineer 🧠currently learning solidity via @cyfrinupdraft ||
I will Share wins,fail and growth with you💪| let’s build the #web3 together
54K Followers 10 Following🔮 Web3 Jobs ᵍᵐ Start your career in Web3
💼 #1 Job Board in Web3 | 60k+ Roles
🌐 Part of @BondexApp ecosystem
🚀 Powered by $BDXN
924K Followers 180 FollowingFounder https://t.co/gQN7OehYd2, Co-Founder https://t.co/VLS8LzeasI. My new book $100M Money Models is out. (3.6M copies sold) Get yours now
7K Followers 324 Following👉 Available for freelance work! 👈 Blogging about @laravelphp and more to 25K visits/mo: Repo → https://t.co/WI0QIAkOLv Ad space → https://t.co/oiW1wJocxk
3.1M Followers 150 FollowingEngineer. Selecting and curating pictures and videos trying to awaken your sense of wonder. Science, tech, art, weather, space, the unusual around us.
2K Followers 1K FollowingCyber Security professional - visionary, straightforward and neutral opinionist and mentor. Apolitical India lover and nationalist at heart.
819 Followers 212 FollowingA centralised repository of the newest and top-rated infosec tools and content. Get your profile on https://t.co/UevQywW8xO now! 🙏
3K Followers 79 FollowingFounder & CEO of NFD team.
/ @superteam member.
/ @solana grant recipient.
Believe in something.
But make sure it’s @somethingco_ol
4K Followers 135 FollowingInstitutional Grade Web3 security, for when it has to be right the first time. Guarded $10 Billion.
Book an audit → https://t.co/eDa6yn6Fsh
10K Followers 0 FollowingAssetnote combines advanced reconnaissance and high-signal continuous security analysis to help enterprises gain insight and control of their evolving exposure.