HackingHub @hackinghub.bsky.social · 27mCan feel it through the chest when the IDOR finally returns someone else's data 🥸 000
HackingHub @hackinghub.bsky.social · 02/10/2026Want to learn webapp hacking? Check out our practice labs (Hubs), they're free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 02/10/2026A few years back, pulling a specific bug bounty dataset meant writing your own scraper or API calls. Today you can grab it with zero code, here's how: 👇 110
HackingHub @hackinghub.bsky.social · 01/10/2026Want to learn webapp hacking? Check out our practice labs (Hubs), they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 01/10/2026Mass hunting of secrets has never been this easy. 🤓 Here’s the overview of the entire pipeline: 100
HackingHub @hackinghub.bsky.social · 30/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 010
HackingHub @hackinghub.bsky.social · 30/09/2026You’ve tried every bypass trick, but nothing worked. What if it’s a Windows server? 🪟 Here’s what you can try: 100
HackingHub @hackinghub.bsky.social · 30/09/2026Course includes: ✔️ 11 hands-on labs ✔️ 6+ hours of video content ✔️ Lifetime access & updates ✔️ Community access ✔️ Real hunter strategies Limited-time sale, grab it below! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 30/09/2026🚀 LAUNCHING: 40% off our new course! Hacking AI Apps & Agents By Johann Rehberger (@wunderwuzzi23) Yes, the guy behind some of the wildest prompt injection research out there. 🤓 100
HackingHub @hackinghub.bsky.social · 29/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 000
HackingHub @hackinghub.bsky.social · 29/09/2026Aside from encoding tricks, here’s another technique that can also bypass a 403: 💰 100
HackingHub @hackinghub.bsky.social · 28/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 28/09/2026How to BYPASS protections and access hidden endpoints? Here’s @NahamSec with his favorite trick: 👇 100
HackingHub @hackinghub.bsky.social · 27/09/2026Learn more techniques by hacking our AI Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 011
HackingHub @hackinghub.bsky.social · 27/09/2026Have you tried hacking an AI assistant? 🤖 Here’s @rez0__ dropping gold nuggets on how to approach it: 👇 100
HackingHub @hackinghub.bsky.social · 26/09/2026Learn more techniques by hacking our AI Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 26/09/2026Intercepting the HTTP request your browser sends when you chat with an AI assistant. Turns out there's actually a lot you can tamper with. 🤓 100
HackingHub @hackinghub.bsky.social · 25/09/2026Learn more techniques by hacking our AI Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 000
HackingHub @hackinghub.bsky.social · 25/09/2026These are the actual prompts you can send when hacking an AI Assistant: 👇 100
HackingHub @hackinghub.bsky.social · 24/09/2026Learn other bug classes by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 000
HackingHub @hackinghub.bsky.social · 24/09/2026Having a hard time catching SSRF? Maybe you’re hunting in the wrong places. 🤔 Here's where you should look: 👀 100
HackingHub @hackinghub.bsky.social · 23/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 000
HackingHub @hackinghub.bsky.social · 23/09/2026This is the first and most important thing you should look at when you’re hunting SSRF: 👀 101
HackingHub @hackinghub.bsky.social · 22/09/2026Learn other bug classes by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 010
HackingHub @hackinghub.bsky.social · 22/09/2026Stop misidentifying SSRF. Let’s clear things up: 🤓 100
HackingHub @hackinghub.bsky.social · 21/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 111
HackingHub @hackinghub.bsky.social · 21/09/2026Your ideal scenario: the origin ignores the trailing junk (; param, extra path segment, encoded traversal) and returns private data anyway, but the CDN only sees the .css suffix and caches it as static. NOTE: Also try other delimiters, file extensions, and static directories. 100
HackingHub @hackinghub.bsky.social · 21/09/2026Web cache deception tricks 🪄 GET /api/me → returns PII Run these to trick the CDN into caching a sensitive endpoint: 🟥 GET /api/me;.css 🟥 GET /api/me/foo.css 🟥 GET /static/..%2fapi/me 🟥 GET /api/me%00.css 🟥 GET /profile%2f%2e%2e%2fstatic 100
HackingHub @hackinghub.bsky.social · 20/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 010
HackingHub @hackinghub.bsky.social · 20/09/2026Edge/WAF blocks /admin by path rules, the origin may re-route on these headers before your request hits its own auth. 101
HackingHub @hackinghub.bsky.social · 20/09/2026Want to access the /admin panel? Try these variants: 🟥 //admin 🟥 /./admin 🟥 /%2f/admin Didn't work? Add these headers: GET / HTTP/1.1 X-Original-URL: /admin/panel X-Rewrite-URL: /admin 100
HackingHub @hackinghub.bsky.social · 19/09/2026Learn practical techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 19/09/2026You can still find success in hunting for stored/blind XSS today. 🥸 Here’s why: 👇 101
HackingHub @hackinghub.bsky.social · 18/09/2026Learn practical techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 010
HackingHub @hackinghub.bsky.social · 18/09/2026These 3 bug classes became harder to find. If you’re starting bug bounty today, here’s why you might want to skip learning them and focus on other bug classes instead: 👇 100
HackingHub @hackinghub.bsky.social · 17/09/2026Learn practical techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 111
HackingHub @hackinghub.bsky.social · 17/09/20263 tips to get to a 75% bug bounty report hit rate: 👇 100
HackingHub @hackinghub.bsky.social · 16/09/2026Grab the latest Caido for Hackers masterclass: 👇 hhub.ioCaido For Hackers - HackingHubHackingHub offers training and challenges for ethical web application hacking. 010
HackingHub @hackinghub.bsky.social · 16/09/2026Analyze JS files with a Caido plugin. 🤓 Here’s a quick demo: 👇 100
HackingHub @hackinghub.bsky.social · 15/09/2026Grab the latest Caido for Hackers masterclass: 👇 hhub.ioCaido For Hackers - HackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 15/09/2026Want to hunt WebSockets vulns? Here’s how to do it using Caido: 👇 100
HackingHub @hackinghub.bsky.social · 14/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 14/09/2026What can you do to increase the trigger chance of your blind XSS payloads? 🥸 Here are some solid tips: 👇 100
HackingHub @hackinghub.bsky.social · 13/09/2026Learn more techniques by hacking our Hubs, they’re free! 👇 hhub.ioHackingHubHackingHub offers training and challenges for ethical web application hacking. 110
HackingHub @hackinghub.bsky.social · 13/09/2026🟥 Inject tailored payloads into those newly discovered fields to pivot from a single XSS into a full internal tool takeover. By doing these, you can maximize impact and your bounty. 💰 100
HackingHub @hackinghub.bsky.social · 13/09/2026Try this: 🟥 When your server receives a blind ping, extract the execution URL, origin, and document title. 🟥 Inspect the leaked context for internal query parameters (like ticket_id, admin_user_id). 100
HackingHub @hackinghub.bsky.social · 13/09/2026Use that execution context to map out adjacent internal parameters and chain multiple findings together. 100
HackingHub @hackinghub.bsky.social · 13/09/2026Triggering Blind XSS isn't the end goal. When your blind callback fires, it doesn't just validate a bug - it may also leak the internal routing structure, DOM context, and parameter naming of private tools you can't normally see. 100