0xacb
@0xacb
Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm. Co-founder @ethiack.com
We just open-sourced EthiBench: a new evaluation protocol for AI pentesting agents. Ground truth and code available here: https://github.com/ethiack/ethibench
Revshells is a great tool for quickly generating shell payloads according to your needs. It supports reverse shells, bind shells, msfvenom payloads, HoaxShell, and assembled payload options.
Most recon stops at A records, and that's where some attack surface hides. Querying all DNS records allows you to expand your recon. 🧑💻 CNAME records can reveal third-party services and subdomain takeover opportunities 🧑💻 MX records expose mail infrastructure
Here's a quick one-liner for finding open redirects to chain with something more impactful. This will hit all archived URL variants, replace parameter values with your payload, and confirm live redirects using HTTPX response matching.
We've all been there: found an XSS, blocked by CSP. There's a bunch of CSP bypasses that you can try by @renniepak.nl: https://cspbypass.com It has a compilation of bypasses, based on the exact CSP you're up against. Here’s a quick tutorial on how to use it 👇
On my way to #H121 in Lisbon 🌞 Super cool to see the first LHE from @Hacker0x01 in Portugal.
Manually hunting for endpoints and hidden parms in web apps? Another nice tool from xnl_h4ck3r is xnLinkFinder that crawls targets, extracts links, discovers secrets, and builds target-specific wordlists. Try it out 👇 https://github.com/xnl-h4ck3r/xnLinkFinder
💥 One click could completely compromise a OpenClaw / Moltbot / Clawdbot (CVE-2026-25253) The vulnerability is now fixed, but here's how it worked:
Need to find the APIs the devs forgot about? Combine waymore with xnLinkFinder or similar. - waymore: Gathers the archived URL responses. - xnLinkFinder: Extracts the hidden paths and parameters. GitHub repos 👇 https://github.com/xnl-h4ck3r/waymore https://github.com/xnl-h4ck3r/xnLinkFinder
It's crazy how hallucinated AI CVE PoCs keep ending up in NIST NVD references. One recent example is CVE-2026-21962, a 10.0 CVE in Oracle HTTP Server / Apache Proxy Plugin. https://nvd.nist.gov/vuln/detail/CVE-2026-21962 links to a GitHub repository with a fake PoC.
Active crawling is powerful, but combining it with passive leads to even better results. GAU fetches historical URLs from external sources like AlienVault OTX, Wayback Machine, and Common Crawl. It’s great for uncovering forgotten endpoints and parameters. 👉https://github.com/lc/gau
Manually going through multiple web archiving sites while hunting can be a tedious task. Here is a browser extension to help you do that quickly. https://chromewebstore.google.com/detail/web-archives/hkligngkgcpcolhcnkgccglchdafcnao https://addons.mozilla.org/en-US/firefox/addon/view-page-archive/
With a single command, xnldorker gathers dork results from multiple search engines. Another nice tool by @xnl_h4ck3r Github link 👇 https://github.com/xnl-h4ck3r/xnldorker
Do you know you could fingerprint technologies right from the terminal? 🕵️♂️ The -td flag of httpx enables Wappalyzer-based detection to identify underlying technologies like CMS, web frameworks, and programming languages.
If you need to generate a target-specific wordlist, make sure to check out @xnl_h4ck3r GAP extension. It will scan for sus parameters and generate you a complete wordlist with one click of a button. See it in action 👇
When looking for postMessage vulnerabilities, the FancyTracker Firefox extension can be very useful. It has built-in syntax highlighting and sortes out duplicates. Check it out 👇 https://github.com/Zeetaz/FancyTracker-FF And the original for Chrome: https://github.com/fransr/postMessage-tracker
When doing recon, if you have a file with a bunch of URLs, you can use @xnl-h4ck3r.bsky.social's urless tool to declutter and reduce the amount of noise in the results. Check it out here 👇 https://github.com/xnl-h4ck3r/urless
When faced with a GraphQL endpoint, make sure to run it through amrelsagaei's GraphQL Caido Analyzer plugin. It will try to expose the server's schema using Introspection queries & you can run custom attacks to test the batch query limit, field suggestions, etc.
When testing GraphQL APIs make sure to run graphw00f (https://github.com/dolevf/graphw00f) to fingerprint the specific GraphQL implementation the application is running. Then you can review the Threat Matrix to get likely attack vectors.
If you found a package.json file in the wild, you might find some internal packages vulnerable to a dependency confusion attack 👀 Check for it quicker using this cool new tool by JSMon: https://app.jsmon.sh/tools/npm-validator 👇
Tomorrow I'll be speaking at https://lisbonai.xyz We're building faster than ever with AI. But are we building securely? I'll show how agents can perform penetration testing and introduce Hackian: an autonomous agent that identifies vulnerabilities before attackers do.
Just had an amazing time working with Shopify in Toronto 🍁 Thanks @hacker0x01.bsky.social for organizing such an incredible event and bringing awesome researchers together. #togetherwehitharder #h1416 #shopify #hacking #goleafs
Found an XSS but got blocked by the CSP? https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
Thanks @hacker0x01.bsky.social for the amazing LHE! Had the chance to work with TikTok and OKX and found some cool vulns, including two 0days. Will try to publish a write up once they're fixed! Also, big congrats to the new MVH champion @corraldev.bsky.social for the huge mic-drop at this event 🤯
On my way to @hacker0x01.bsky.social #h165 to pop some shells on TikTok and OKX ✈️