CHANGE | GROW | SUCCEED

Joined January 2022
108 Photos and videos
AOXSIN retweeted
My JS surface mapper is now live in CAI (@AliasRobotics). It's a tool for the web pentester agent that does JS analysis: github.com/aliasrobotics/cai…
7
80
4,487
AOXSIN retweeted
28 Sep 2025
$1,000 GIVEAWAY 🎁‼️ Here’s how to enter: 1️⃣ Fill out the ITMOAH survey 2️⃣ Like this post 3️⃣ Comment your fave tool 4️⃣ Repost bc your friends deserve a chance too Giveaway closes Sept 30 at 11:59pm ET. One hacker takes home $1K. 20 others will score $200 each. Already filled out the survey? You’re entered to win! If not, now's your chance: surveymonkey.com/r/bugcrowd-…
413
305
677
61,232
31 Mar 2025
Eid Mubarak 🌙✨
1
174
22 Mar 2025
Had an amazing time at Exploit Exchange: A Gathering for Bug Bounty Hunters & Penetration Testers🔥 Huge thanks to @Hacker0x01 & @remonsec for hosting this awesome event happen. Great meetup, awesome discussions, and unforgettable moments⚡ #BugBounty #hackermeetup #aoxsin
8
837
AOXSIN retweeted
16 Mar 2025
WordPress quick wins! 😎 #HackWithIntigriti
6
29
327
19,584
AOXSIN retweeted
What’s up @KN0X55 From the pro to the pros. All credit goes to @KN0X55 and @BRuteLogic XSS is confirmed. Sqli is confirmed. Lfimap still working on the lfi list.
Automate bug bounty. SQLI - XSS - LFI waymore -i urls | tee urls-his cat urls-his | gf sqli |urless| anew sqli cat urls-his | gf xss | urless|anew xss cat urls-his | gf lfi | urless|anew lfi ghauri -m sqli --confirm --batch --level=3 -b knoxnl -i xss -X BOTH python3 lfimap.py -F lfi --use-long -a --no-stop Use -x Exploit and send reverse shell if RCE is available Tools:- github.com/xnl-h4ck3r/waymor… github.com/r0oth3x49/ghauri github.com/xnl-h4ck3r/knoxnl github.com/hansmach1ne/LFIma… github.com/xnl-h4ck3r/urless knoxss.pro/
3
47
3,858
AOXSIN retweeted
Early results from the StealthNet.AI beta Congrats to @aoxsin for securing a bounty with our AI-powered agent 🔗Bug Bounty Hunting Using StealthNets AI Agent shorturl.at/iU196 #bugbounty #AI #CyberSecurity #infosecurity #AIforSecurity #Pentesting #StealthNetAI

1
2
6
461
AOXSIN retweeted
Meet the Future of Cybersecurity: AI-Powered Hacking StealthNet.AI Agentic AI revolutionizes pen testing with autonomous assessments. Watch our beta demo to see AI agents think, adapt, & hack 🤖🔍 💡 Want beta access? Comment or DM! 🔗 bit.ly/4i70Fv9

4
7
13
1,590
AOXSIN retweeted
ok, so, as a reminder, my recon course is free on youtube, go check it out. (and I demonetized my channel a while ago so that there are no ads - not sure if that works).
4
5
68
4,739
AOXSIN retweeted
29 Jan 2025
Replying to @deepseek_ai @wiz_io
Taking our target root domain (for Bug Bounty / Responsible Disclosure) such as deepseek[.]com, we will want to feed it into DNS Discovery tools, those divide to 2 main workflows - Passive & Active. In the passive sense, we want to query public DNS datasets all over the internet and collect known subdomains of our target, the best way to do that is using a tool such as subfinder by @pdiscoveryio In the active sense, we will collect public wordlists with hundreds of thousands of domain names, and will try to fuzz and "guess" additional valid domains under our target - deepseek[.]com, such as "admin.deepseek[.].com" etc,etc... For this task, a tool I recommend is Puredns github.com/d3mondev/puredns Which is simply run by the following command: Additionally, there are more techniques such as permutation (adding dev-admin.deepseek[.]com for example) but we will leave it like that. The goal of this phase is to collect a list of valid subdomains, and save them all in a single place. Valid subdomain in our sense - a DNS record that has an IP Address or points to another asset.
2
13
111
28,928
5 Jan 2025
Got some bounty using @StealthNetAI , and it was an awesome experience. 💰 2 bounties from a self-hosted program: $200. 💻 1 issue on HackerOne (pending program review) Severity: Low Type: Info Disclosure #BugBounty #infosec #CyberSecurity #bounty #Huntwithai
1
4
280
5 Jan 2025
1st finding Fun part: Ran some prompts on a self-hosted program to test the tool. Checked the report section and i was surprised,it already found CVE-2000-0114 with a full report ready.Just copied, sent it, and got rewarded. 😅 Thanks, Alex Thomas, for early access.
1
204
14 Jan 2025
I received many messages asking how it works and what it can do. In this blog post, I share how I used the tool to find vulnerabilities. You will also find ideas on how you can use it. Check it out to see how it can simplify your bug-hunting process. stealthnet.ai/post/informati…

1
112
AOXSIN retweeted
3 Dec 2024
You found this new host via Shodan with an open HTTP server on port 8443 with a default IIS server homepage... 🧐 Quick fuzzing led to the discovery of the /AdministratorLogin.aspx endpoint 👀 But how do you continue from here? 🤔 In our latest article, we went over various ways to exploit broken authentication vulnerabilities! Check it out! 👇 buff.ly/49o2XCL
27
152
7,600
AOXSIN retweeted
JavaScript Treasure Hunt JS files often contain references to API endpoints that aren't immediately visible in the web interface. 1. Use Burp Scanner or the JS Link Finder BApp to extract these endpoints from JavaScript files. 2. And, imo, manually reviewing JS code will invariably yield valuable insights. More: portswigger.net/web-security…

6
83
4,122
AOXSIN retweeted
21 Oct 2024
My @defcon talk about how we made around $150k in Bug Bounty only with Denial of Services is out ! Let me know what you think 😁 youtu.be/b7WlUofPJpU?si=Ef4m…
12
108
577
41,898
AOXSIN retweeted
Is this the best and fastest recon framework? 🎥👉🏼youtu.be/GOwq95QMv_g
3
26
174
10,745