Sign in

0xacb

@0xacb.com
1.5K followers 101 following 412 posts

Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm. Co-founder @ethiack.com 0xacb.com

PostsRepliesMedia
0xacb @0xacb.com · 10h
Turns out those Unicode dashes are actually useful. Filter blocks "-"? Send full-width "-" instead. Windows converts it back to "-" inside curl.exe, injecting a -o argument that drops a webshell.
101
0xacb @0xacb.com · 29/09/2026
Have you looked at localName when testing an HTML filter? A tag name that looks useless as markup can come back from the browser as a transformed string. If an event handler reads that value, a payload the filter never saw as JavaScript may become code later.
100
0xacb @0xacb.com · 28/09/2026
In our KindaRails2Shell research, a file labelled image/png can make Rails read /etc/passwd. The trick lies beneath the upload layer. On the direct-upload path, Active Storage can keep the client’s `image/png` label without checking the bytes.
100
0xacb @0xacb.com · 15/09/2026
Some security controls, such as auth checks, rate limiting, WAF rules, and IP allowlisting are often implemented with a gateway. If you're able to discover the origin host and it accepts requests directly, you can bypass all of that by sending your requests straight to the origin.
220
0xacb @0xacb.com · 14/09/2026
Been testing the IDOR trick where you wrap the identifier in an array, in Node JS. You are 123, victim is 124. {"user_id": [124, 123]} The ORM doesn't pick the first element. Sequelize and Mongoose turn it into WHERE id IN (124, 123) and can write both rows.
100
0xacb @0xacb.com · 11/09/2026
How to trick an AI into downloading and running malware, by @wunderwuzzi23:
120
0xacb @0xacb.com · 09/09/2026
I was playing with SQL Server and noticed the default collation is case insensitive (SQL_Latin1_General_CP1_CI_AS). admin and ADMIN are the same string to the DB. That part is well known. Less talked about: = also ignores trailing spaces. 'admin' = 'admin␣' is true (␣ is an actual space char)
100
0xacb @0xacb.com · 07/09/2026
This is how user data can be exposed via prompt injection, explained by @wunderwuzzi23:
110
0xacb @0xacb.com · 04/09/2026
Did you know you can actually steal a dev's GitHub account using their expired domain? Here's how @0xLupin did it. It's pretty cool:
120
0xacb @0xacb.com · 02/09/2026
What happens when an attacker gets a live, interactive shell inside Microsoft 365 Copilot? @vbcrlf.bsky.social from Rubrik Zero Labs dropped ChatMate, the first publicly documented Remote Prompt Execution (RPE): an attacker manipulating a victim's assistant, prompt by prompt.
100
0xacb @0xacb.com · 01/09/2026
How do we prevent Hackian (our hackbot) from performing destructive actions? Here’s how we do it: 👇
100
0xacb @0xacb.com · 31/08/2026
IDOR to image-based data exfiltration on an AI chat agent. Here’s a clip from @monkehack’s talk, explaining how they did it.
120
0xacb @0xacb.com · 24/08/2026
This is how @0xLupin bypassed the supply chain security of major companies like Google, Salesforce, Netflix, and many others. Here’s the clip:
120
0xacb @0xacb.com · 14/08/2026
Using SHA collision to trick an AI for a $10k bounty. Really interesting technique by my buddy @0xLupin:
110
0xacb @0xacb.com · 13/08/2026
This is how @monkehack (with @Rhynorater, @0xLupin, @rez0__ ) used prompt injection to hack the Gemini mobile app:
220
0xacb @0xacb.com · 12/08/2026
Got an arbitrary file write that got closed as medium? It shouldn't have been. Most AFWs get downgraded because nobody could prove RCE 🥷 Some research we've been doing for years just dropped!
ethiack.com
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack — Autonomous Ethical Hacking for continuous security
Autonomous Ethical Hacking for continuous security
250
Reposted by 0xacb
0xacb.bsky.social @0xacb.bsky.social · 08/08/2026
libvips has flagged matload as untrusted for years and exposes a switch to block it. Rails’ ActiveStorage just never flipped it. Until last week. That’s CVE-2026-66066: a .mat file declared as image/png, arbitrary file read, then RCE. Full chain👇 ethiack.com/info-hub/res...
ethiack.com
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — Autonomous Ethical Hacking for continuous security
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
351
0xacb @0xacb.com · 04/08/2026
We at #BHUSA Who's around?
000
0xacb @0xacb.com · 30/07/2026
🚨We reported KindaRails2Shell, a critical RCE in Ruby on Rails via Active Storage. It’s not a one-shot RCE, but the preconditions are kinda common under default configurations. Patch your applications now! CVE-2026-66066 ethiack.com/info-hub/res...
ethiack.com
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous security
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
020
0xacb @0xacb.com · 21/07/2026
Hacking With AI and Hacking AI @mohansrk.bsky.social 's HackAICon talk is live on YouTube 👀
youtube.com
Hacking With AI and Hacking AI: Two Sides of the Same Problem | Mohan Krishna (s1r1us) @ HackAICon
Can AI actually hack? And how easy is it to hack AI? Mohan Sriram K...
000
0xacb @0xacb.com · 20/07/2026
Are you familiar with zero-width space? This character 👉 %E2%80%8B Try inserting %E2%80%8B between characters of a blocked word. If the filter sees a different string, and the backend ignores the invisible character, you may bypass some filters.
100
0xacb @0xacb.com · 15/07/2026
Which AI pentesting agent is the best in the world? And how can we even measure this? (We figured it out! Keep reading 👇) The existing benchmarking methods ain't good because they work like a CTF, which doesn't resemble real-world vulns.
100
0xacb @0xacb.com · 14/07/2026
We just open-sourced EthiBench: a new evaluation protocol for AI pentesting agents. Ground truth and code available here: github.com/ethiack/ethibench
110
0xacb @0xacb.com · 13/07/2026
Revshells is a great tool for quickly generating shell payloads according to your needs. It supports reverse shells, bind shells, msfvenom payloads, HoaxShell, and assembled payload options.
121
0xacb @0xacb.com · 03/07/2026
Most recon stops at A records, and that's where some attack surface hides. Querying all DNS records allows you to expand your recon. 🧑‍💻 CNAME records can reveal third-party services and subdomain takeover opportunities 🧑‍💻 MX records expose mail infrastructure
210
0xacb @0xacb.com · 29/06/2026
Here's a quick way to get a bunch of JS files associated with your target.
110
0xacb @0xacb.com · 23/06/2026
Here's a quick one-liner for finding open redirects to chain with something more impactful. This will hit all archived URL variants, replace parameter values with your payload, and confirm live redirects using HTTPX response matching.
121
0xacb @0xacb.com · 22/06/2026
We've all been there: found an XSS, blocked by CSP. There's a bunch of CSP bypasses that you can try by @renniepak.nl: cspbypass.com It has a compilation of bypasses, based on the exact CSP you're up against.  Here’s a quick tutorial on how to use it 👇
052
0xacb @0xacb.com · 18/06/2026
Here's a simple concept that's helped me find a lot of bugs. Once it clicks you can't unsee it. A huge family of bugs is basically the same bug: two components read the same input and disagree about what it means.
120
0xacb @0xacb.com · 15/06/2026
When @jameskettle.com dropped his last-byte synchronization research back in 2019 I started hunting for race conditions. It's crazy that this still works so often 7 years later. It's such a common, widespread issue and I don't think most hackers are checking for it (usually low dupe count)
100
0xacb @0xacb.com · 02/06/2026
GTFOBins is a curated list of Unix binaries that may be exploited to bypass local security restrictions: SUID, sudo, capabilities, file read/write. On real targets you often land in a restricted shell, but those may help you escalate privileges, reading unauthorized files, etc
gtfobins.org
GTFOBins
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
000
0xacb @0xacb.com · 21/05/2026
Hacking ≡ Magic
020
0xacb @0xacb.com · 20/05/2026
New redirect tricks from @castilho101 just dropped 🥷
ethiack.com
Abusing Redirect Discrepancies to leak secrets in URLs | Ethiack — Autonomous Ethical Hacking for continuous security
Discover how attackers exploit HTTP redirect discrepancies to extract sensitive data embedded in URLs, and what you can do to prevent secret leakage in your web infrastructure.
000
0xacb @0xacb.com · 12/05/2026
Found an IDOR vulnerability but the IDs are UUIDs? Don't drop the report yet 👇
110
0xacb @0xacb.com · 11/05/2026
Submitting alert(document.location) will probably get you a medium. Proving impact can make a real difference. Escalating an XSS used to be as easy as leaking cookies. That often doesn't work anymore because the HttpOnly flag is typically present on the juicy session cookies.
110
0xacb @0xacb.com · 07/05/2026
Are you getting a forbidden status code hitting a sensitive endpoint on a Node.js app? It may be using Fastify. The middleware may check the exact path, e.g. /internal. If the app has router normalization options enabled, the following or variations may work: //internal /internal;a=b
100
0xacb @0xacb.com · 06/05/2026
A lot of people are now building and using their own hackbots daily. Here's a nice blog on using AI to hunt for vulns by 0xAsm0d3us. Some takeaways that I've also been experiencing:
120
0xacb @0xacb.com · 05/05/2026
Claude being careful
010
0xacb @0xacb.com · 29/04/2026
On my way to #H121 in Lisbon 🌞 Super cool to see the first LHE from @Hacker0x01 in Portugal.
000
0xacb @0xacb.com · 27/04/2026
You're attacking an OAuth implementation, but it properly validates if the redirect_uri starts with victim.com/callback - are we cooked? Not necessarily.  We should still check if it enforces strict path matching.
victim.com
210
0xacb @0xacb.com · 20/04/2026
It's really nice to see a lot of hackers finally coming around to the idea of using AI. Here's a cool episode from @ctbbpodcast.bsky.social on building Claude skills for hacking. Been playing with connecting Claude Code to @caido.io and loving it.
youtube.com
Critical Thinking - Bug Bounty Podcast
513 likes, 33 comments. "Building Claude Skills as a Bug Bounty Hunter (Ep. 166)"
220
0xacb @0xacb.com · 08/04/2026
CI/CD pipelines provide a lot of juicy attack surface. One common pattern: a build system lets you specify an output path for artifacts. If that path isn't sanitized, a ../ sequence lets you write files anywhere on the build server.
100
0xacb @0xacb.com · 05/04/2026
Reverse engineering MCPs like IDA Pro MCP or Ghidra MCP are really powerful to find memory corruption 0days or reversing CVEs.
120
0xacb @0xacb.com · 03/04/2026
Race conditions in OAuth flows can still happen in custom implementations. Tools like Turbo Intruder or even a simple multi-threaded script sending concurrent requests to the callback URL with different tokens may trigger it. Further reading here:
blog.avuln.com
A couple more common OAuth 2.0 vulnerabilities
TL;DR The couple of bugs described below are common across different OAuth 2.0 implementations. The bugs may allow a malicious application to maintain an access to victim's account even after access revocation performed by the victim.
000
0xacb @0xacb.com · 01/04/2026
Hackerone MCP Server (unofficial). An MCP server that gives you quick access to your HackerOne reports, programs, earnings, and scope data. Very useful tool by @OriginalSicksec for anyone that's automating but bounty hunting. GitHub repo 👇
github.com
GitHub - Sicks3c/hackerone-mcp-server: Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Code
Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Code - Sicks3c/hackerone-mcp-server
100
0xacb @0xacb.com · 18/03/2026
Super cool work by @s3bsrt HTTP trailers can be a blind spot. Proxies usually ignore them, but backend servers will happily merge them into the main headers, letting you sneak payloads right past security filters. Blog link 👇
sebsrt.xyz
Trailing Danger: exploring HTTP Trailer parsing discrepancies
Trailing Danger: exploring HTTP Trailer parsing discrepancies
030
0xacb @0xacb.com · 16/03/2026
Find hidden API parameters in seconds, not hours.  Arjun scans 25,890 parameter names with just 50-60 requests in under 10 seconds.
github.com
GitHub - s0md3v/Arjun: HTTP parameter discovery suite.
HTTP parameter discovery suite. Contribute to s0md3v/Arjun development by creating an account on GitHub.
011
0xacb @0xacb.com · 14/03/2026
Scanning 65,000 ports in just a few seconds with the power of Rust! 🦀
github.com
GitHub - bee-san/RustScan: 🤖 The Modern Port Scanner 🤖
🤖 The Modern Port Scanner 🤖. Contribute to bee-san/RustScan development by creating an account on GitHub.
000
0xacb @0xacb.com · 13/03/2026
WontFix can be an RCE Goldmine SOAPwn by chudyPB #5 in PortSwigger Web Hacking Techniques of 2025 Blog link 👇
labs.watchtowr.com
SOAPwn: Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
Welcome back! As we near the end of 2025, we are, of course, waiting for the next round of SSLVPN exploitation to occur in January (as it did in 2024 and 2025). Weeeeeeeee. Before then, we want to clear the decks and see how much research we can publish. This
011
0xacb @0xacb.com · 12/03/2026
The ETag Oracle Cross-Site ETag Length Leak by @arkark_ This technique weaponizes 1-byte ETag length variations to trigger 431 header overflows, detectable via Chromium's history API. Blog here👇
blog.arkark.dev
Cross-Site ETag Length Leak | XS-Spin Blog
A novel XS-Leak technique that turns ETag length differences into a cross-site oracle via 431 errors and History API.
000