Web - Mobile pentester

Joined April 2021
Photos and videos
Linna retweeted
Cambodia accuses Thailand of detaining 20 soldiers after a ceasefire was agreed between the two sides. Cambodian officials take foreign diplomats to a destroyed border checkpoint in Preah Vihear and deny Thai claims of ceasefire violations. #Cambodia #Thailand #Ceasefire
632
2,653
4,309
150,723
Linna retweeted
9 Jun 2025
Hackers 🔥 Stuck on a 403? Here are some powerful tricks to try for bypassing 🚀 1⃣ X-Forwarded-For 2⃣ X-Original-URL 3⃣ Referer 4⃣ HTTP method manipulation 5⃣ Case sensitive (/admin or /aDmIn) 6⃣ Encoding 7⃣ Path normalization Happy hunting! 🎯
5
87
527
25,487
Linna retweeted
14 May 2025
beware of all applications developed in-house, where security may not be as strong as in a public app !
14 May 2025
DLL injection and DLL proxying on macOS? Yes it is possible! Checkout this blog by @antoinedss about macOS automated DYLIB injection! #redteam blog.balliskit.com/macos-dyl…
1
2
5
407
Linna retweeted
⚠️CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications. github.com/musana/CF-Hero ✅ Join Telegram For More Content: t.me/brutsecurity ---------------------------------------------------------------------------- 📖 Your Ethical Hacking Journey Starts Here → topmate.io/saumadip/1391531 🎓 Ready to Skill Up? Enroll Now → wa.link/brutsecurity 📢 Join the Community & Stay Updated: 📱 Discord: discord.gg/u7uMFV833h 💼 X (Twitter): x.com/brutsecurity ⭐ Found this helpful? Like, Share & Level Up Your Skills! #CyberSecurity #BugBounty #EthicalHacking #Infosec #BrutSecurity
61
256
11,499
Linna retweeted
Apache Tomcat: Potential RCE Severity : Critical CVE-2025-24813 Exploit : github.com/MuhammadWaseem29/… Refrence : github.com/advisories/GHSA-8… #ApacheTomcat #bugbounty #RCE
4
142
597
31,272
Linna retweeted
14 Feb 2025
A great and useful tip that helped me find many bugs is just to play with the HTTP method 😋 Here I found broken access control (sent PUT instead of GET/POST) in the API of the target, that enabled me to discover XSS where the developers did not expect any user input 🔥
9
44
343
20,952
Linna retweeted
15 Feb 2025
Bypass OTP in an unexpected way : replace the OTP value to "true" ( without quote ) Origin Request - { "OTP": "11111" } Modify To - } "OTP": true } medium.com/@deepk007/how-i-b… Credit: DEep
13
118
819
42,894
Linna retweeted
I just realized I have a large collection of notes taken during pentests, in-depth documentation on techniques and tradecraft, and a sizeable code repo. Considering sharing this in its written form. Probably time to use hackersploit.wiki. Lmk what you think
13
59
324
19,778
Linna retweeted
26 Jan 2025
Bypass waf for SQL injection :) cloudflare command : sqlmap -u "target.com" --dbs --batch --time-sec 10 --level 3 --hex --random-agent --tamper=space2comment,betweeny time-based blind: AND (SELECT 5140 FROM (SELECT(SLEEP(10)))lfTO)
13
172
912
48,975
Linna retweeted
🍪 Introducing the “Cookie Sandwich” technique. This vulnerability manipulates how servers parse cookies, potentially exposing sensitive user information like session IDs. Read more: portswigger.net/research/ste…
1
21
97
5,335
Linna retweeted
Day 8 & 9 : LFI x2 Refer : medium.com/@cyber_dark/cve-2… Video : Will post on YouTube
1
17
269
11,986
Linna retweeted
Bypass CloudFlare WAF with JSFuck (jsfuck.com)♻️ #infosec #cybersec #bughunting
3
76
376
21,686
Linna retweeted
Introducing InternetCTF! 🤯 Earn up to $10,000 for finding RCE vulnerabilities in open-source software AND creating Tsunami plugin patches. Make the internet safer and get rewarded! 🤑 For details on the program, see our latest blog post: bughunters.google.com/blog/6…
10
112
597
40,594
Linna retweeted
27 Dec 2024
Want to master 2FA bypassing? 🤑 Let's look at several possible ways to bypass this 2FA screen! 👇
5
65
370
27,437
Linna retweeted
Extract all endpoints from a JS File and take your bug 🐞 ✅Method one waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]? 15*[=: 1\5*[ '\"]?[^'\"] .js[^'|"> ]*" | awk -F '/' '{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh -c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\. (get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ] {5,})\"" | awk -F "['|"]" '{print $2}' sort -fu ✅Method two cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt #infosec #cybersec #bugbountytips
2
76
374
20,975
Linna retweeted
javascript How to extract urls,srcs and hrefs from all HTML elements in any website? Open DevTools and run urls = [] $$('*').forEach(element => { urls.push(element.src) urls.push(element.href) urls.push(element.url) }); console.log(...new Set(urls)) #infosec #cybersec #bugbounty
9
118
655
44,393
Linna retweeted
7 Nov 2024
You can bypass path-based WAF restrictions by appending raw/unencoded non-printable and extended-ASCII characters like \x09 (Spring), \xA0 (Express), and \x1C-1F (Flask):
4
154
726
50,340