Hacker, Father and Founder

Joined March 2017
175 Photos and videos
Pinned Tweet
People are building incredible products, yet many hit the same wall: 0 users / 0 revenue. Drop your startup link below πŸ‘‡ I'll sign up, try it out, and if I genuinely like it, I'll become a paying customer. #SaaS #Startups #BuildInPublic #IndieHackers #StartupIdeas #Entrepreneur
11
10
407
You asked for it β€” we built it. πŸš€ Pingback.sh now supports correlated injections (Pro users). Save the original HTTP request before inserting your payload. If it fires hours or days later, the callback links directly back to the exact injection attempt. Track: β€’ Label β€’ Bug type β€’ Target URL β€’ Injection point β€’ Request method β€’ Responsible HTTP request No more guessing which payload triggered the callback. #BugBounty #BugBountytips #BlindXSS #SSRF #CyberSecurity #Infosec

1
52
WordPress XML-RPC pingback bugs are still alive. Not a jackpot, but an easy ~$100 now and then. Use pingback.sh to capture DNS HTTP callbacks and validate xmlrpc.php / pingback-ping issues in minutes. πŸ’° $100 hackerone.com/reports/458696 πŸ’° $50 hackerone.com/reports/458696 πŸ’° Rewarded report hackerone.com/reports/673384 #bugbounty #hackerone #bugcrowd #xss #pentest #owasp #SSRF #XMLRPC #infosec #bugbountytips
1
91
622 bug bounty hunters used PingBack.sh over the last two weeks. Most prefer connecting their scripts directly to the API and pulling callback data into their own analysis pipelines. πŸ“‘ 177,000 callbacks received so far. Still hunting on HackerOne, Bugcrowd, and YesWeHack with generic public OAST services? You're probably leaving money on the table. The difference between an Informative report and a paid report is often the evidence you can collect from a callback. SSRF, Blind XXE, Blind XSS, PDF injections, internal network interactions... every callback is another opportunity to prove impact. Integrate PingBack.sh into your workflow, automate your analysis, and turn more findings into payouts. πŸ’° More evidence. More valid reports. More bounty rewards. #bugbounty #bugbountytips #hacker #cybersecurity #pentest #appsec #ssrf #oast #infosec
2
173
Secuaudit retweeted
Intercepts mobile HTTPS traffic without rooting github.com/danieldev23/trafe…
30
216
10,216
how many $ have you burned with claude fable 5 yet?
1
88
Got old bug bounty reports closed as "Informative" or "Need More Impact"? Why not grab a Pro account on PingBack.sh and revisit them with fresh payloads? That's exactly what I did this morning. I reopened an old report about external resource loading in a PDF viewer that had been closed as Informative. By experimenting with different payloads, I discovered additional behaviors, including JavaScript execution inside the PDF sandbox. Sometimes the bug isn't dead you just haven't found the right impact path yet. #bugbounty #bugbountytips #pentest #appsec #infosec #securityresearch #hackerone #bugcrowd #cybersecurity #yeswehack
20
991
Just received a $550 bounty for a simple, beginner-friendly bug you can easily find with Pingback.sh β€” just automate testing for overly permissive wildcard CORS policies (Access-Control-Allow-Origin: * Access-Control-Allow-Headers: *). Honestly, I don't know what you're waiting for β€” get a Pingback.sh Pro account, plug the API (Pingback.sh/api-docs ) into your bug bounty recon workflow, and wait for the notification in your Telegram or email. #bugbounty #bugbountytips #pentest #appsec #infosec #securityresearch #hackerone #bugcrowd #cybersecurity
5
7
95
3,155
Bug bounty tip πŸ‘‡ Found a password reset feature? Don't stop at token leakage. Try injecting a Pingback.sh URL into profile fields, organization names, support tickets, or invitation workflows. Many systems generate emails, PDFs, CRM records, and internal dashboards that render your data later. A callback can reveal hidden internal processing paths nobody told you existed. #bugbounty #pentest #bugbountytips #infosec #securityresearch
1
271
Bug bounty tip πŸ‘‡ Before declaring a finding "dead", ask yourself: What happens after the upload? PDF processors, AI agents, antivirus scanners, image converters, email gateways, and internal workflows often interact with your payload long after the request is finished. You might be missing the interesting part. Generate your file payloads with embedded Blind XSS, SSRF, XXE, and OOB payloads directly on Pingback.sh #bugbounty #pentest #pentesting #infosec #securityresearch
1
1
243
A website has a contact form πŸ‘‡ Name: Email: Message: Looks harmless. But PHPMailer CVE-2016-10033 proved otherwise. πŸ’‘ Technical Notes: 1️⃣ Input flows: Contact Form β†’ PHPMailer β†’ mail() β†’ sendmail β†’ OS Command Line 2️⃣ Vulnerable fields: From: Sender: Reply-To: Specially crafted addresses with "attacker\"-X" can break the sendmail argument chain. 3️⃣ RFC trick: Addresses in quotes can contain spaces and special characters β†’ bypasses naive validation. 4️⃣ Impact: Potential RCE if combined with PHP gadgets Can write to logs, webroot, or email headers 5️⃣ Detection / Prevention: Validate & escape all fields before passing to mail() Use SMTP transport instead of local sendmail Monitor unexpected outbound connections πŸ“Œ Lesson: :Never assume an email field is β€œjust an email”. Sometimes, the smallest fields expose the largest attack surfaces. Try it yourself: pingback.sh/ #bugbountytips #bugbounty #php #infosec #security
1
19
860
Bug bounty hunters are the only people on Earth making $5,000 a month from security... And still using Burp Suite v1.7.35 cracked by Dr. FarFar in 2014. #bugbounty #bugbountytips #HackerOne #Bugcrowd #infosec #appsec
12
5
150
7,968
Email Workflows Are Hidden Attack Surfaces πŸ‘‡ β€’ Create a Pingback SMTP mailbox. β€’ Use it in contact forms, password reset flows, invitations, support tickets, or any feature that sends emails. β€’ Wait for the target to process your request. If Pingback receives a message, you've confirmed a real backend email workflow. Inspect the headers. You may discover: β€’ Internal hostnames β€’ Mail relays β€’ Security gateways β€’ Third-party providers β€’ Processing pipelines Many interesting findings start with a simple email. Generate your SMTP listener at pingback.sh/ #bugbountytips #bugbounty #infosec #security #smtp
5
561
The Callback Nobody Expects πŸ‘‡ β€’ Generate a file payload in Pingback.sh (PDF, PNG, SVG, XML, HTML, and more). β€’ Add your email, Discord, or Telegram notification. β€’ Upload the file to the target. β€’ Delete it immediately. β€’ Move on. Days later, Pingback sends you a notification. Why? Backups, indexing jobs, antivirus engines, AI pipelines, compliance scanners, and archival systems may still process your file long after it's been deleted. The file is gone. The callback isn't. Deleted doesn't always mean forgotten. Give it a try at pingback.sh/ #bugbountytips #bugbounty #infosec #security #recon
1
1
13
845