Sign in

HackingHub

@hackinghub.bsky.social
116 followers 1 following 531 posts

Educating the next generation of ethical hackers @ hackinghub.io

PostsRepliesMedia
HackingHub @hackinghub.bsky.social · 3h
You’ve tried every bypass trick, but nothing worked. What if it’s a Windows server? 🪟 Here’s what you can try:
100
HackingHub @hackinghub.bsky.social · 8h
🚀 LAUNCHING: 40% off our new course! Hacking AI Apps & Agents By Johann Rehberger (@wunderwuzzi23)  Yes, the guy behind some of the wildest prompt injection research out there. 🤓
100
HackingHub @hackinghub.bsky.social · 29/09/2026
Aside from encoding tricks, here’s another technique that can also bypass a 403: 💰
100
HackingHub @hackinghub.bsky.social · 28/09/2026
How to BYPASS protections and access hidden endpoints? Here’s @NahamSec with his favorite trick: 👇
100
HackingHub @hackinghub.bsky.social · 27/09/2026
Have you tried hacking an AI assistant? 🤖 Here’s @rez0__ dropping gold nuggets on how to approach it: 👇
100
HackingHub @hackinghub.bsky.social · 26/09/2026
Intercepting the HTTP request your browser sends when you chat with an AI assistant. Turns out there's actually a lot you can tamper with. 🤓
100
HackingHub @hackinghub.bsky.social · 25/09/2026
These are the actual prompts you can send when hacking an AI Assistant: 👇
100
HackingHub @hackinghub.bsky.social · 24/09/2026
Having a hard time catching SSRF? Maybe you’re hunting in the wrong places. 🤔 Here's where you should look: 👀
100
HackingHub @hackinghub.bsky.social · 23/09/2026
This is the first and most important thing you should look at when you’re hunting SSRF: 👀
101
HackingHub @hackinghub.bsky.social · 22/09/2026
Stop misidentifying SSRF. Let’s clear things up: 🤓
100
HackingHub @hackinghub.bsky.social · 21/09/2026
Web cache deception tricks 🪄 GET /api/me → returns PII Run these to trick the CDN into caching a sensitive endpoint: 🟥 GET /api/me;.css 🟥 GET /api/me/foo.css 🟥 GET /static/..%2fapi/me 🟥 GET /api/me%00.css 🟥 GET /profile%2f%2e%2e%2fstatic
100
HackingHub @hackinghub.bsky.social · 20/09/2026
Want to access the /admin panel? Try these variants: 🟥 //admin 🟥 /./admin 🟥 /%2f/admin Didn't work? Add these headers: GET / HTTP/1.1 X-Original-URL: /admin/panel X-Rewrite-URL: /admin
100
HackingHub @hackinghub.bsky.social · 19/09/2026
You can still find success in hunting for stored/blind XSS today. 🥸 Here’s why: 👇
101
HackingHub @hackinghub.bsky.social · 18/09/2026
These 3 bug classes became harder to find. If you’re starting bug bounty today, here’s why you might want to skip learning them and focus on other bug classes instead: 👇
100
HackingHub @hackinghub.bsky.social · 17/09/2026
3 tips to get to a 75% bug bounty report hit rate: 👇
100
HackingHub @hackinghub.bsky.social · 16/09/2026
Analyze JS files with a Caido plugin. 🤓 Here’s a quick demo: 👇
100
HackingHub @hackinghub.bsky.social · 15/09/2026
Want to hunt WebSockets vulns? Here’s how to do it using Caido: 👇
100
HackingHub @hackinghub.bsky.social · 14/09/2026
What can you do to increase the trigger chance of your blind XSS payloads? 🥸 Here are some solid tips: 👇
100
HackingHub @hackinghub.bsky.social · 13/09/2026
Triggering Blind XSS isn't the end goal. When your blind callback fires, it doesn't just validate a bug - it may also leak the internal routing structure, DOM context, and parameter naming of private tools you can't normally see.
100
HackingHub @hackinghub.bsky.social · 12/09/2026
Here's how to trick an AI into exfiltrating data via HTML preview: 👇
100
HackingHub @hackinghub.bsky.social · 11/09/2026
Here’s how Copilot Memory can be exploited: 👇
100
HackingHub @hackinghub.bsky.social · 10/09/2026
This is how password exfil via prompt injection is done. 🥸 Check it out! 👇
100
HackingHub @hackinghub.bsky.social · 09/09/2026
How to hijack sessions through HTTP request smuggling: 👇
100
HackingHub @hackinghub.bsky.social · 08/09/2026
How does HTTP request smuggling work? 🤓 Here’s a quick explainer: 👇
100
HackingHub @hackinghub.bsky.social · 07/09/2026
THIS IS YOUR LAST CHANCE 🫵 The Labor Day Weekend sale ends tonight! Take 40% OFF EVERY SINGLE COURSE across HackingHub and lock in your discount before it's gone for good. 🎟️ Code: LDW2026S Grab your next course right now 👇
100
HackingHub @hackinghub.bsky.social · 07/09/2026
Old endpoints rarely get the new security checks. 🤓 If your target migrated to a new platform, try these:
100
HackingHub @hackinghub.bsky.social · 06/09/2026
How to use c99 subdomain finder for an easy recon? 🥸 Here’s a quick guide: 👇
100
HackingHub @hackinghub.bsky.social · 06/09/2026
The clock is ticking 🐇⏱️ The Labor Day Weekend sale is almost gone! Take 40% OFF EVERY SINGLE COURSE across our entire platform. No exceptions. 🎟️ Use Code: LDW2026S ⏳ Ends tomorrow, September 7 Grab your next course before time runs out 👇
100
HackingHub @hackinghub.bsky.social · 05/09/2026
Want a sign to level up your hacking skills? This is it. Our Labor Day Weekend sale is the perfect opportunity: 40% off all our courses, with zero exceptions. 🎟️ Use code: LDW2026S ⏳ Ends September 7 Secure your next course now👇
100
HackingHub @hackinghub.bsky.social · 05/09/2026
Want to be a better and well-known hacker? Start contributing to the community. Here are some examples of what you can do 👇
000
HackingHub @hackinghub.bsky.social · 04/09/2026
When you spend 5 hours setting up a complex toolchain... and then accidentally trigger a raw SQL syntax error by typing a single quote into a login field.
000
HackingHub @hackinghub.bsky.social · 03/09/2026
🚨 Massive discounts on our hacking bundles, just dropped. Pick the one that matches your level: - All Access Courses - AI Web Hacking - Web Hacking Starter Pack - Web Hacking Essentials - Web Hacking Masterclasses
100
HackingHub @hackinghub.bsky.social · 03/09/2026
🚨 LABOR DAY WEEKEND SALE!! Been waiting for a sign to upskill? This is it! Take 40% OFF ALL COURSES across our entire platform for a limited time. Yes, everything! 🎟️ Use code: LDW2026S ⏳ Validity: September 3–7 ONLY GRAB a course (or more) before the sale ends! 👇
100
HackingHub @hackinghub.bsky.social · 02/09/2026
How it feels to unlock the All Access Courses Bundle (the complete HackingHub library in one ultimate bundle) - 106 Hands-on Labs - 39h+ Video Content - 97 Modules & 555 Lessons - Lifetime Access Honestly? More powerful than Thanos with all the gems.
100
HackingHub @hackinghub.bsky.social · 02/09/2026
The complete, beginner to advanced course on Caido For Hackers is now 50% off 🔓 ✅18 Modules (Launch to capstone) ✅6+ hours of video content ✅Lifetime access & updates ❇️1 month of @CaidoIO Access for free Only for the first 100 users. Claim your spot now 👇 hhub.io/caidoforhackers
000
HackingHub @hackinghub.bsky.social · 31/08/2026
How to prompt an AI to identify assets worth investigating. 👇
100
HackingHub @hackinghub.bsky.social · 30/08/2026
This is how you exfiltrate sensitive data from an AI chatbot with strict front-end security. Here’s a quick breakdown of the clever techniques a hacker used to score an $8k bounty on a major retailer's AI chatbot: 🧵👇
100
HackingHub @hackinghub.bsky.social · 29/08/2026
Want 1 month of free Caido Access and the skills to use it? Only for the first 100 users: 50% off the Caido for Hackers course + 1 month free @CaidoIO Access 🔓 ✅18+ Bugs to hunt ✅6+ Hours of Video  ✅18 Modules (Launch to capstone) ✅Lifetime Access (Keeps up with Caido updates)
100
HackingHub @hackinghub.bsky.social · 28/08/2026
How do you identify an HTTP request smuggling vulnerability? 🤔 Smuggler is an HTTP Request Smuggling / Desync testing Python tool that can help you identify this quickly
100
HackingHub @hackinghub.bsky.social · 27/08/2026
Only for the first 100 users. ⏳ Limited-time drop: 50% off on the Caido For Hackers course + 1 month of Caido Access Most people install @caido.io, use maybe 10% of it, and stop. This course is the other 90%: custom workflows, deep fuzzing, advanced plugins and more.
100
HackingHub @hackinghub.bsky.social · 26/08/2026
Here's why you need to ditch alert(1) in your XSS testing: 🥸
100
HackingHub @hackinghub.bsky.social · 25/08/2026
Making $100K with Caido? In our complete beginner-to-advanced course, Amr Elsagaei opens his actual setup: custom plugins, advanced workflows, and deep automation that helped pull $100K+. Check it out now 👇
100
HackingHub @hackinghub.bsky.social · 24/08/2026
New vulnerability drops. Your team reads about it and moves on. Teams fixes that: Managing team security training in 3 steps: 1️⃣ Pick the Hub 2️⃣ Assign & Set a Deadline 3️⃣ Track Results We're in Beta with Teams. Want to run your team through it? 👇
100
HackingHub @hackinghub.bsky.social · 23/08/2026
If you’re hunting for blind XSS, you need to hear this: 👇
100
HackingHub @hackinghub.bsky.social · 22/08/2026
Don't just read posts about hacking AI. Be part of it! We have practice labs (Hubs) for hacking an actual AI. 🤖 Start hacking today, they’re free! 👇 hhub.io/eSLRYyLUEV
000
HackingHub @hackinghub.bsky.social · 21/08/2026
Dang, that was an ATO. 🥲
000
HackingHub @hackinghub.bsky.social · 21/08/2026
A recap of how an $8k bug was found: data exfil from an AI chatbot 🤖
100
HackingHub @hackinghub.bsky.social · 20/08/2026
“Maximize your bounties.” 💰 Take this solid advice from @NahamSec on how to make the most out of your findings: 👇
101
HackingHub @hackinghub.bsky.social · 19/08/2026
Learn to hack JWTs in under 2 minutes: 👇
100
HackingHub @hackinghub.bsky.social · 18/08/2026
Before you use AI for web app hacking, build a solid foundation first. Start by hacking our Hubs. They’re 100% free, CTF-style labs built directly from: 🟥 real-world web app vulnerabilities 🟥 disclosed pentest reports 🟥 actual bug bounty findings
100