HackingHub @hackinghub.bsky.social · 3hYou’ve tried every bypass trick, but nothing worked. What if it’s a Windows server? 🪟 Here’s what you can try: 100
HackingHub @hackinghub.bsky.social · 8h🚀 LAUNCHING: 40% off our new course! Hacking AI Apps & Agents By Johann Rehberger (@wunderwuzzi23) Yes, the guy behind some of the wildest prompt injection research out there. 🤓 100
HackingHub @hackinghub.bsky.social · 29/09/2026Aside from encoding tricks, here’s another technique that can also bypass a 403: 💰 100
HackingHub @hackinghub.bsky.social · 28/09/2026How to BYPASS protections and access hidden endpoints? Here’s @NahamSec with his favorite trick: 👇 100
HackingHub @hackinghub.bsky.social · 27/09/2026Have you tried hacking an AI assistant? 🤖 Here’s @rez0__ dropping gold nuggets on how to approach it: 👇 100
HackingHub @hackinghub.bsky.social · 26/09/2026Intercepting the HTTP request your browser sends when you chat with an AI assistant. Turns out there's actually a lot you can tamper with. 🤓 100
HackingHub @hackinghub.bsky.social · 25/09/2026These are the actual prompts you can send when hacking an AI Assistant: 👇 100
HackingHub @hackinghub.bsky.social · 24/09/2026Having a hard time catching SSRF? Maybe you’re hunting in the wrong places. 🤔 Here's where you should look: 👀 100
HackingHub @hackinghub.bsky.social · 23/09/2026This is the first and most important thing you should look at when you’re hunting SSRF: 👀 101
HackingHub @hackinghub.bsky.social · 22/09/2026Stop misidentifying SSRF. Let’s clear things up: 🤓 100
HackingHub @hackinghub.bsky.social · 21/09/2026Web cache deception tricks 🪄 GET /api/me → returns PII Run these to trick the CDN into caching a sensitive endpoint: 🟥 GET /api/me;.css 🟥 GET /api/me/foo.css 🟥 GET /static/..%2fapi/me 🟥 GET /api/me%00.css 🟥 GET /profile%2f%2e%2e%2fstatic 100
HackingHub @hackinghub.bsky.social · 20/09/2026Want to access the /admin panel? Try these variants: 🟥 //admin 🟥 /./admin 🟥 /%2f/admin Didn't work? Add these headers: GET / HTTP/1.1 X-Original-URL: /admin/panel X-Rewrite-URL: /admin 100
HackingHub @hackinghub.bsky.social · 19/09/2026You can still find success in hunting for stored/blind XSS today. 🥸 Here’s why: 👇 101
HackingHub @hackinghub.bsky.social · 18/09/2026These 3 bug classes became harder to find. If you’re starting bug bounty today, here’s why you might want to skip learning them and focus on other bug classes instead: 👇 100
HackingHub @hackinghub.bsky.social · 17/09/20263 tips to get to a 75% bug bounty report hit rate: 👇 100
HackingHub @hackinghub.bsky.social · 16/09/2026Analyze JS files with a Caido plugin. 🤓 Here’s a quick demo: 👇 100
HackingHub @hackinghub.bsky.social · 15/09/2026Want to hunt WebSockets vulns? Here’s how to do it using Caido: 👇 100
HackingHub @hackinghub.bsky.social · 14/09/2026What can you do to increase the trigger chance of your blind XSS payloads? 🥸 Here are some solid tips: 👇 100
HackingHub @hackinghub.bsky.social · 13/09/2026Triggering Blind XSS isn't the end goal. When your blind callback fires, it doesn't just validate a bug - it may also leak the internal routing structure, DOM context, and parameter naming of private tools you can't normally see. 100
HackingHub @hackinghub.bsky.social · 12/09/2026Here's how to trick an AI into exfiltrating data via HTML preview: 👇 100
HackingHub @hackinghub.bsky.social · 10/09/2026This is how password exfil via prompt injection is done. 🥸 Check it out! 👇 100
HackingHub @hackinghub.bsky.social · 09/09/2026How to hijack sessions through HTTP request smuggling: 👇 100
HackingHub @hackinghub.bsky.social · 08/09/2026How does HTTP request smuggling work? 🤓 Here’s a quick explainer: 👇 100
HackingHub @hackinghub.bsky.social · 07/09/2026THIS IS YOUR LAST CHANCE 🫵 The Labor Day Weekend sale ends tonight! Take 40% OFF EVERY SINGLE COURSE across HackingHub and lock in your discount before it's gone for good. 🎟️ Code: LDW2026S Grab your next course right now 👇 100
HackingHub @hackinghub.bsky.social · 07/09/2026Old endpoints rarely get the new security checks. 🤓 If your target migrated to a new platform, try these: 100
HackingHub @hackinghub.bsky.social · 06/09/2026How to use c99 subdomain finder for an easy recon? 🥸 Here’s a quick guide: 👇 100
HackingHub @hackinghub.bsky.social · 06/09/2026The clock is ticking 🐇⏱️ The Labor Day Weekend sale is almost gone! Take 40% OFF EVERY SINGLE COURSE across our entire platform. No exceptions. 🎟️ Use Code: LDW2026S ⏳ Ends tomorrow, September 7 Grab your next course before time runs out 👇 100
HackingHub @hackinghub.bsky.social · 05/09/2026Want a sign to level up your hacking skills? This is it. Our Labor Day Weekend sale is the perfect opportunity: 40% off all our courses, with zero exceptions. 🎟️ Use code: LDW2026S ⏳ Ends September 7 Secure your next course now👇 100
HackingHub @hackinghub.bsky.social · 05/09/2026Want to be a better and well-known hacker? Start contributing to the community. Here are some examples of what you can do 👇 000
HackingHub @hackinghub.bsky.social · 04/09/2026When you spend 5 hours setting up a complex toolchain... and then accidentally trigger a raw SQL syntax error by typing a single quote into a login field. 000
HackingHub @hackinghub.bsky.social · 03/09/2026🚨 Massive discounts on our hacking bundles, just dropped. Pick the one that matches your level: - All Access Courses - AI Web Hacking - Web Hacking Starter Pack - Web Hacking Essentials - Web Hacking Masterclasses 100
HackingHub @hackinghub.bsky.social · 03/09/2026🚨 LABOR DAY WEEKEND SALE!! Been waiting for a sign to upskill? This is it! Take 40% OFF ALL COURSES across our entire platform for a limited time. Yes, everything! 🎟️ Use code: LDW2026S ⏳ Validity: September 3–7 ONLY GRAB a course (or more) before the sale ends! 👇 100
HackingHub @hackinghub.bsky.social · 02/09/2026How it feels to unlock the All Access Courses Bundle (the complete HackingHub library in one ultimate bundle) - 106 Hands-on Labs - 39h+ Video Content - 97 Modules & 555 Lessons - Lifetime Access Honestly? More powerful than Thanos with all the gems. 100
HackingHub @hackinghub.bsky.social · 02/09/2026The complete, beginner to advanced course on Caido For Hackers is now 50% off 🔓 ✅18 Modules (Launch to capstone) ✅6+ hours of video content ✅Lifetime access & updates ❇️1 month of @CaidoIO Access for free Only for the first 100 users. Claim your spot now 👇 hhub.io/caidoforhackers 000
HackingHub @hackinghub.bsky.social · 31/08/2026How to prompt an AI to identify assets worth investigating. 👇 100
HackingHub @hackinghub.bsky.social · 30/08/2026This is how you exfiltrate sensitive data from an AI chatbot with strict front-end security. Here’s a quick breakdown of the clever techniques a hacker used to score an $8k bounty on a major retailer's AI chatbot: 🧵👇 100
HackingHub @hackinghub.bsky.social · 29/08/2026Want 1 month of free Caido Access and the skills to use it? Only for the first 100 users: 50% off the Caido for Hackers course + 1 month free @CaidoIO Access 🔓 ✅18+ Bugs to hunt ✅6+ Hours of Video ✅18 Modules (Launch to capstone) ✅Lifetime Access (Keeps up with Caido updates) 100
HackingHub @hackinghub.bsky.social · 28/08/2026How do you identify an HTTP request smuggling vulnerability? 🤔 Smuggler is an HTTP Request Smuggling / Desync testing Python tool that can help you identify this quickly 100
HackingHub @hackinghub.bsky.social · 27/08/2026Only for the first 100 users. ⏳ Limited-time drop: 50% off on the Caido For Hackers course + 1 month of Caido Access Most people install @caido.io, use maybe 10% of it, and stop. This course is the other 90%: custom workflows, deep fuzzing, advanced plugins and more. 100
HackingHub @hackinghub.bsky.social · 26/08/2026Here's why you need to ditch alert(1) in your XSS testing: 🥸 100
HackingHub @hackinghub.bsky.social · 25/08/2026Making $100K with Caido? In our complete beginner-to-advanced course, Amr Elsagaei opens his actual setup: custom plugins, advanced workflows, and deep automation that helped pull $100K+. Check it out now 👇 100
HackingHub @hackinghub.bsky.social · 24/08/2026New vulnerability drops. Your team reads about it and moves on. Teams fixes that: Managing team security training in 3 steps: 1️⃣ Pick the Hub 2️⃣ Assign & Set a Deadline 3️⃣ Track Results We're in Beta with Teams. Want to run your team through it? 👇 100
HackingHub @hackinghub.bsky.social · 23/08/2026If you’re hunting for blind XSS, you need to hear this: 👇 100
HackingHub @hackinghub.bsky.social · 22/08/2026Don't just read posts about hacking AI. Be part of it! We have practice labs (Hubs) for hacking an actual AI. 🤖 Start hacking today, they’re free! 👇 hhub.io/eSLRYyLUEV 000
HackingHub @hackinghub.bsky.social · 21/08/2026A recap of how an $8k bug was found: data exfil from an AI chatbot 🤖 100
HackingHub @hackinghub.bsky.social · 20/08/2026“Maximize your bounties.” 💰 Take this solid advice from @NahamSec on how to make the most out of your findings: 👇 101
HackingHub @hackinghub.bsky.social · 18/08/2026Before you use AI for web app hacking, build a solid foundation first. Start by hacking our Hubs. They’re 100% free, CTF-style labs built directly from: 🟥 real-world web app vulnerabilities 🟥 disclosed pentest reports 🟥 actual bug bounty findings 100