Sign in

HackingHub

@hackinghub.bsky.social
122 followers 1 following 538 posts

Educating the next generation of ethical hackers @ hackinghub.io

PostsRepliesMedia
HackingHub @hackinghub.bsky.social · 27m
Can feel it through the chest when the IDOR finally returns someone else's data 🥸
000
HackingHub @hackinghub.bsky.social · 19h
LET ME BYPASS!!
000
HackingHub @hackinghub.bsky.social · 03/10/2026
What are the odds of finding a dupe......
000
HackingHub @hackinghub.bsky.social · 02/10/2026
Want to learn webapp hacking? Check out our practice labs (Hubs), they're free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 02/10/2026
A few years back, pulling a specific bug bounty dataset meant writing your own scraper or API calls. Today you can grab it with zero code, here's how: 👇
110
HackingHub @hackinghub.bsky.social · 01/10/2026
Want to learn webapp hacking? Check out our practice labs (Hubs), they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 01/10/2026
Mass hunting of secrets has never been this easy. 🤓 Here’s the overview of the entire pipeline:
100
HackingHub @hackinghub.bsky.social · 30/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
010
HackingHub @hackinghub.bsky.social · 30/09/2026
You’ve tried every bypass trick, but nothing worked. What if it’s a Windows server? 🪟 Here’s what you can try:
100
HackingHub @hackinghub.bsky.social · 30/09/2026
Course includes: ✔️ 11 hands-on labs ✔️ 6+ hours of video content ✔️ Lifetime access & updates ✔️ Community access ✔️ Real hunter strategies Limited-time sale, grab it below! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 30/09/2026
🚀 LAUNCHING: 40% off our new course! Hacking AI Apps & Agents By Johann Rehberger (@wunderwuzzi23)  Yes, the guy behind some of the wildest prompt injection research out there. 🤓
100
HackingHub @hackinghub.bsky.social · 29/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
000
HackingHub @hackinghub.bsky.social · 29/09/2026
Aside from encoding tricks, here’s another technique that can also bypass a 403: 💰
100
HackingHub @hackinghub.bsky.social · 28/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 28/09/2026
How to BYPASS protections and access hidden endpoints? Here’s @NahamSec with his favorite trick: 👇
100
HackingHub @hackinghub.bsky.social · 27/09/2026
Learn more techniques by hacking our AI Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
011
HackingHub @hackinghub.bsky.social · 27/09/2026
Have you tried hacking an AI assistant? 🤖 Here’s @rez0__ dropping gold nuggets on how to approach it: 👇
100
HackingHub @hackinghub.bsky.social · 26/09/2026
Learn more techniques by hacking our AI Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 26/09/2026
Intercepting the HTTP request your browser sends when you chat with an AI assistant. Turns out there's actually a lot you can tamper with. 🤓
100
HackingHub @hackinghub.bsky.social · 25/09/2026
Learn more techniques by hacking our AI Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
000
HackingHub @hackinghub.bsky.social · 25/09/2026
These are the actual prompts you can send when hacking an AI Assistant: 👇
100
HackingHub @hackinghub.bsky.social · 24/09/2026
Learn other bug classes by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
000
HackingHub @hackinghub.bsky.social · 24/09/2026
Having a hard time catching SSRF? Maybe you’re hunting in the wrong places. 🤔 Here's where you should look: 👀
100
HackingHub @hackinghub.bsky.social · 23/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
000
HackingHub @hackinghub.bsky.social · 23/09/2026
This is the first and most important thing you should look at when you’re hunting SSRF: 👀
101
HackingHub @hackinghub.bsky.social · 22/09/2026
Learn other bug classes by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
010
HackingHub @hackinghub.bsky.social · 22/09/2026
Stop misidentifying SSRF. Let’s clear things up: 🤓
100
HackingHub @hackinghub.bsky.social · 21/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
111
HackingHub @hackinghub.bsky.social · 21/09/2026
Your ideal scenario: the origin ignores the trailing junk (; param, extra path segment, encoded traversal) and returns private data anyway, but the CDN only sees the .css suffix and caches it as static. NOTE: Also try other delimiters, file extensions, and static directories.
100
HackingHub @hackinghub.bsky.social · 21/09/2026
Web cache deception tricks 🪄 GET /api/me → returns PII Run these to trick the CDN into caching a sensitive endpoint: 🟥 GET /api/me;.css 🟥 GET /api/me/foo.css 🟥 GET /static/..%2fapi/me 🟥 GET /api/me%00.css 🟥 GET /profile%2f%2e%2e%2fstatic
100
HackingHub @hackinghub.bsky.social · 20/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
010
HackingHub @hackinghub.bsky.social · 20/09/2026
Edge/WAF blocks /admin by path rules, the origin may re-route on these headers before your request hits its own auth.
101
HackingHub @hackinghub.bsky.social · 20/09/2026
Want to access the /admin panel? Try these variants: 🟥 //admin 🟥 /./admin 🟥 /%2f/admin Didn't work? Add these headers: GET / HTTP/1.1 X-Original-URL: /admin/panel X-Rewrite-URL: /admin
100
HackingHub @hackinghub.bsky.social · 19/09/2026
Learn practical techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 19/09/2026
You can still find success in hunting for stored/blind XSS today. 🥸 Here’s why: 👇
101
HackingHub @hackinghub.bsky.social · 18/09/2026
Learn practical techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
010
HackingHub @hackinghub.bsky.social · 18/09/2026
These 3 bug classes became harder to find. If you’re starting bug bounty today, here’s why you might want to skip learning them and focus on other bug classes instead: 👇
100
HackingHub @hackinghub.bsky.social · 17/09/2026
Learn practical techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
111
HackingHub @hackinghub.bsky.social · 17/09/2026
3 tips to get to a 75% bug bounty report hit rate: 👇
100
HackingHub @hackinghub.bsky.social · 16/09/2026
Grab the latest Caido for Hackers masterclass: 👇
hhub.io
Caido For Hackers - HackingHub
HackingHub offers training and challenges for ethical web application hacking.
010
HackingHub @hackinghub.bsky.social · 16/09/2026
Analyze JS files with a Caido plugin. 🤓 Here’s a quick demo: 👇
100
HackingHub @hackinghub.bsky.social · 15/09/2026
Grab the latest Caido for Hackers masterclass: 👇
hhub.io
Caido For Hackers - HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 15/09/2026
Want to hunt WebSockets vulns? Here’s how to do it using Caido: 👇
100
HackingHub @hackinghub.bsky.social · 14/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 14/09/2026
What can you do to increase the trigger chance of your blind XSS payloads? 🥸 Here are some solid tips: 👇
100
HackingHub @hackinghub.bsky.social · 13/09/2026
Learn more techniques by hacking our Hubs, they’re free! 👇
hhub.io
HackingHub
HackingHub offers training and challenges for ethical web application hacking.
110
HackingHub @hackinghub.bsky.social · 13/09/2026
🟥 Inject tailored payloads into those newly discovered fields to pivot from a single XSS into a full internal tool takeover. By doing these, you can maximize impact and your bounty. 💰
100
HackingHub @hackinghub.bsky.social · 13/09/2026
Try this: 🟥 When your server receives a blind ping, extract the execution URL, origin, and document title. 🟥 Inspect the leaked context for internal query parameters (like ticket_id, admin_user_id).
100
HackingHub @hackinghub.bsky.social · 13/09/2026
Use that execution context to map out adjacent internal parameters and chain multiple findings together.
100
HackingHub @hackinghub.bsky.social · 13/09/2026
Triggering Blind XSS isn't the end goal. When your blind callback fires, it doesn't just validate a bug - it may also leak the internal routing structure, DOM context, and parameter naming of private tools you can't normally see.
100