Sign in

Spix0r

@spix0r.bsky.social
322 followers 137 following 72 posts

Bug Bounty Hunter | Github: github.com/Spix0r

PostsRepliesMedia
Spix0r @spix0r.bsky.social · 13/06/2026
• Installation pip install robofinder I also focused more on data quality than raw speed. Wayback lookups, especially on older targets, may take a little longer :( but you'll get much more results instead of missing data. github: github.com/Spix0r/robof... 3/3
github.com
GitHub - Spix0r/robofinder: Robofinder fetches historical robots.txt files from Archive.org to uncover old directories, hidden paths, and valuable OSINT data for reconnaissance.
Robofinder fetches historical robots.txt files from Archive.org to uncover old directories, hidden paths, and valuable OSINT data for reconnaissance. - Spix0r/robofinder
100
Spix0r @spix0r.bsky.social · 13/06/2026
What's new? • Supports both single and multiple URLs robofinder -u urls.txt • Pipe results directly into other tools robofinder -u example.com -c | httpx • JSON output for automation robofinder -u example.com -c -f json 2/3
example.com
Example Domain
100
Spix0r @spix0r.bsky.social · 13/06/2026
✎ RoboFinder v0.2.2 is out RoboFinder is now more powerful, stable, and easier to fit into your #recon workflow. It fetches historical robots.txt files from archive.org to uncover old directories, hidden paths, and #OSINT data. #bugbounty #cybersecurity 1/3
100
Spix0r @spix0r.bsky.social · 20/02/2026
Check out my new article about leveraging IP spoofing to achieve one-click account takeover in OAuth blog.mirzadzare.net/ip-spoofing-... #bugbounty #oauth #cybersecurity
000
Spix0r @spix0r.bsky.social · 01/12/2025
From "Log in with OAuth" to "Your Account Is Mine" I just published my first write-up on my blog: blog.mirzadzare.net/from-log-in-... This article is based on a recent #OAuth vulnerability I discovered. I hope you enjoy it! ❤️‍🔥🙌 #BugBounty #cybersecurity
blog.mirzadzare.net
OAuth Vulnerabilities in Desktop Apps
Security flaw in desktop app OAuth allows account takeover with malicious links. Understand attack steps, why it works, and fix strategies
030
Spix0r @spix0r.bsky.social · 08/07/2025
Then Fuzz for backup files - maybe you'll find a juicy accessible backup file! Github: github.com/Spix0r/fback #CyberSecurity #bugbountyTools #bugbounty #Recon #reconnaissance #bugbountytips 5/5
github.com
GitHub - Spix0r/fback: Fback is a tool that helps you create target-specific wordlists using a .json pattern.
Fback is a tool that helps you create target-specific wordlists using a .json pattern. - Spix0r/fback
000
Spix0r @spix0r.bsky.social · 08/07/2025
You can use FBack to generate target-specific wordlists and fuzz for possible backup files: echo example[.]com/files/config.php | fback -y 2020-2024 -m 1-12 Example Output: config.php.bak config_backup.php config_2024.php files_config.php 4/5
210
Spix0r @spix0r.bsky.social · 08/07/2025
Methodology You know those static websites, especially WordPress sites, where you encounter paths like: example[.]com/files/config.php But you don't have access to config.php, so now what? What should you test here? 3/5
100
Spix0r @spix0r.bsky.social · 08/07/2025
What’s FBack? It’s a tool that generates target‑specific wordlists to fuzz for backup files—think config.php.bak, config_backup.php, etc. Its perfect for hunting juicy unattended backups on static or WordPress sites. 2/5
100
Spix0r @spix0r.bsky.social · 08/07/2025
It’s been a while since my last update, but I’m thrilled to share some exciting news about my project called Fback 1/5 #bugbounty #bugbountytips #bugbountytools #recon #hacking #CyberSecurity
110
Spix0r @spix0r.bsky.social · 23/02/2025
github.com/synacktiv/la...
github.com
GitHub - synacktiv/laravel-crypto-killer: A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.
A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications. - synacktiv/laravel-crypto-killer
000
Spix0r @spix0r.bsky.social · 12/02/2025
GTA VI mountains:
000
Spix0r @spix0r.bsky.social · 12/02/2025
For this purpose, you can use CloudRecon by me: github.com/Spix0r/cloud... #CyberSecurity #BugBounty #BugBountyTools #pentest #infosec #Certificate #bugbountytips #reconnaissance #Recon
github.com
GitHub - Spix0r/cloudrecon: This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger.gay provider.
This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger.gay provider. - Spix0r/cloudrecon
000
Spix0r @spix0r.bsky.social · 12/02/2025
We can extract subdomains from these providers using kaeferjaeger, which performs this task for us every 60 minutes. [Passive Search] If you lack the necessary resources, you can utilize kaeferjaeger provider to conduct a passive search. 2/3
100
Spix0r @spix0r.bsky.social · 12/02/2025
Subdomain Enumeration - Finding subdomains that are hidden in the cloud. We need to conduct a certificate search on the IP ranges of cloud providers such as Amazon, Digital Ocean, Google, and Microsoft. 1/3
110
Spix0r @spix0r.bsky.social · 09/02/2025
Root Detection & SSL Bypass Script github.com/0xCD4/SSL-by...
github.com
GitHub - 0xCD4/SSL-bypass: SSL bypass check
SSL bypass check. Contribute to 0xCD4/SSL-bypass development by creating an account on GitHub.
020
Spix0r @spix0r.bsky.social · 06/02/2025
Bypass Cloudflare's /h/b/jsd challenge using 100% python github.com/xkiian/cloud...
github.com
GitHub - xKiian/cloudflare-jsd: Bypass Cloudflare's /h/b/jsd challenge using 100% python
Bypass Cloudflare's /h/b/jsd challenge using 100% python - xKiian/cloudflare-jsd
010
Reposted by Spix0r
James Kettle @jameskettle.com · 03/02/2025
I’ve updated the bug bounty & content creators starter pack with classic research group @hackerschoice.bsky.social! Let me know if you’re not on this list and would like to be added. go.bsky.app/GD7hKPX
74412
Spix0r @spix0r.bsky.social · 30/01/2025
I’ve added a new feature to Robofinder, and now you can extract old parameters from archived robots.txt files. This is very useful for your recon process because you may find hidden or deprecated parameters that other tools might miss. Github: github.com/Spix0r/robof...
000
Reposted by Spix0r
Jorian @jorianwoltjer.com · 26/01/2025
During #x3ctf, I discovered an unintended solution that turned out to be a pretty cool generic technique. It allows you to detect the result of a selector during CSS Injection, bypassing any CSP restricting external requests! Check out the writeup below: jorianwoltjer.com/blog/p/ctf/x...
jorianwoltjer.com
Post: x3CTF - blogdog (+ new CSS Injection XS-Leak!) | Jorian Woltjer
A "hard web xssbot" challenge about a fun browser quirk with the is= attribute to perform CSS Injection. Bypass the strict CSP with an unintended new technique to XS-Leak a selector's result by detect...
2247
Spix0r @spix0r.bsky.social · 30/12/2024
Why should i search for old robots.txt files? Because it's possible that the site you are investigating had numerous paths listed in its robots.txt file that were subsequently removed in later updates. Despite their removal, those paths, files, and parameters may still be accessible. 3/3
010
Spix0r @spix0r.bsky.social · 30/12/2024
How can I access the old robots.txt files data? I’ve created a tool called RoboFinder, which allows you to locate historical robots.txt files. Robofinder on Github: github.com/Spix0r/robof... 2/3
github.com
GitHub - Spix0r/robofinder: Robofinder retrieves historical #robots.txt files from #Archive.org, allowing you to uncover previously disallowed directories and paths for any domain—essential for deepen...
Robofinder retrieves historical #robots.txt files from #Archive.org, allowing you to uncover previously disallowed directories and paths for any domain—essential for deepening your #OSINT and #reco...
110
Spix0r @spix0r.bsky.social · 30/12/2024
Robots.txt File And #Reconnaissance What is a robots.txt file? The robots.txt file is designed to restrict web crawlers from accessing certain parts of a website. However, it often inadvertently reveals sensitive directories that the site owner prefers to keep unindexed. 1/3
110
Spix0r @spix0r.bsky.social · 26/12/2024
Writeup-Miner is live again on T.me/Daily_Writeups Join to be among the first to access the latest cybersecurity write-ups! Source Code: github.com/Spix0r/write...
000
Reposted by Spix0r
Liran Tal @lirantal.com · 25/12/2024
Find out about new JavaScript security vulnerabilites in npm packages on the Node.js Security newsletter: www.nodejs-security.com/newsletter/n...
021
Spix0r @spix0r.bsky.social · 24/12/2024
To hack a thing, first learn to build it.
000
Spix0r @spix0r.bsky.social · 22/12/2024
Happy Birthday♥️🍰
010
Spix0r @spix0r.bsky.social · 21/12/2024
Helped me a lot! Thank you.
010
Reposted by Spix0r
renniepak @renniepak.nl · 14/11/2024
Hey BlueSky! I case you missed it: I've created cspbypass.com A site where you can search for known CSP bypass gadgets to gain XSS. It already contains a bunch of useful gadgets with contributions from your favourite hackers. If you have some CSP bypasses to share, feel free to contribute!
17124
Spix0r @spix0r.bsky.social · 21/12/2024
These tools are amazing! I really liked the idea.
000
Reposted by Spix0r
Gareth Heyes @garethheyes.co.uk · 20/12/2024
I'm building two web security tools at the moment: Shazzer - A shared online fuzzer shazzer.co.uk Hackvertor - Web security conversion tool hackvertor.co.uk
2154
Spix0r @spix0r.bsky.social · 21/12/2024
I challenge you to a duel🔫
010
Spix0r @spix0r.bsky.social · 21/12/2024
I've created a repo for top Nuclei templates from the security community. Contribute your templates or find powerful ones for CVE scans, fuzzing, and more! Let's build the largest Nuclei template library together! github.com/Spix0r/Nucle...
github.com
GitHub - Spix0r/Nuclei-Community-Templates: A collaborative hub for Nuclei templates. Contribute, share, and explore powerful vulnerability detection tools!
A collaborative hub for Nuclei templates. Contribute, share, and explore powerful vulnerability detection tools! - Spix0r/Nuclei-Community-Templates
000
Reposted by Spix0r
Random Robbie @what-security.co.uk · 19/12/2024
github.com/veikkos/bmw Guide on there for the BMW app should work on any other app
github.com
GitHub - veikkos/bmw: BMW Connected Drive apis
BMW Connected Drive apis. Contribute to veikkos/bmw development by creating an account on GitHub.
111
Spix0r @spix0r.bsky.social · 19/12/2024
Amazing! Thank you.
000
Spix0r @spix0r.bsky.social · 19/12/2024
Ah, I totally get that... If you ever want to chat about it I'm here.
100
Spix0r @spix0r.bsky.social · 17/12/2024
Can you drop every useful resources about hacking Wordpress websites? 👇🏻
000
Spix0r @spix0r.bsky.social · 16/12/2024
Thank you.
100
Spix0r @spix0r.bsky.social · 15/12/2024
I'm looking for it too
100
Reposted by Spix0r
Nicolas Grégoire @agarri.fr · 21/11/2024
If you write Python scripts, make yourself a favor and use the Rich library to beautify their output 🐍 🧑‍💻
github.com
GitHub - Textualize/rich: Rich is a Python library for rich text and beautiful formatting in the terminal.
Rich is a Python library for rich text and beautiful formatting in the terminal. - Textualize/rich
611520
Spix0r @spix0r.bsky.social · 15/12/2024
Cloudrecon - This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger[.]gay provider. github.com/Spix0r/cloud...
github.com
GitHub - Spix0r/cloudrecon: This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger.gay provider.
This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger.gay provider. - Spix0r/cloudrecon
020
Reposted by Spix0r
Nicolas Grégoire @agarri.fr · 14/12/2024
A younger me, as a pentester and bug hunter, had exactly the bias described in this article 🤫 Luckily, I later worked with and for "the other side" and it changed my mind 🤯 I hope young people reading it will avoid taking years to understand the complexities of fixing bugs in a timely manner 🤞
maxwelldulin.com
Why Can't You Fix This Bug Faster?
Fixing security vulnerabilities in a timely manner is more complicated than you realize.
25816
Reposted by Spix0r
Gareth Heyes @garethheyes.co.uk · 09/12/2024
Hackvertor BApp pro tip: 🛠️ Did you know you can use Hackvertor tags inside custom tags? This also works with globally declared variables! Example set a global in a request: <@set_var(true)>1337<@/set_var> Custom JS tag: output = convert("< @get_var />") Now that's power 💪
0121
Reposted by Spix0r
Nick Dunn @n1ckdunn.bsky.social · 01/12/2024
While everyone waits for the next @bsideslondon.bsky.social, here are my slides from the previous event. This isn't entirely for self-promotion 😆, it's also because of the lack of resources out there for SOSL injection Apex and Java code for Salesforce. github.com/N1ckDunn/SOS...
github.com
GitHub - N1ckDunn/SOSLInjection
Contribute to N1ckDunn/SOSLInjection development by creating an account on GitHub.
193
Spix0r @spix0r.bsky.social · 07/12/2024
I've developed a Python tool called Fback that generates wordlists for fuzzing backup files. It takes a JSON-based pattern file and a seed wordlist as input and produces a target-specific wordlist as output. Github: github.com/Spix0r/Fback #bugbounty #bugbountytools #cybersecurity
github.com
GitHub - Spix0r/fback: This is a useful Python script for generating a target specific wordlist for fuzzing backup files.
This is a useful Python script for generating a target specific wordlist for fuzzing backup files. - Spix0r/fback
031
Reposted by Spix0r
James Kettle @jameskettle.com · 06/12/2024
I've updated the bug bounty starter pack with some more hitters - re-subscribe to get them in your timeline. There's still 65 open places remaining so just let me know if you'd like to be added! bsky.app/starter-pack...
7233
Spix0r @spix0r.bsky.social · 07/12/2024
Hi, I'd like to be added. Thanks!❤️
010
Spix0r @spix0r.bsky.social · 02/12/2024
Every time I hunt for bugs to buy, I end up with many duplicates.😂
000
Spix0r @spix0r.bsky.social · 30/11/2024
What is this fruite?
000
Spix0r @spix0r.bsky.social · 28/11/2024
I think i need sleep
110