✦ Application Security Researcher ✦ Breaking the modern web stack ✦ Focused on client-side security ✦ Impact-driven tactics ⚡ 🌿 Open to collaborations

Between Source & Sink
DorkSearch generates Google dorks for discovering exposed admin panels, public files, leaks, and hidden endpoints. Useful for faster recon. Source: dorksearch.com #BugBounty #OSINT #CyberSecurity
4
49
266
12,012
obscaries ❘ AppSec retweeted
Want to find subdomains quickly? Try crt.name it indexes CT + historical data to uncover hostnames. Source: crt.name/ #BugBounty #Recon
3
15
1,869
obscaries ❘ AppSec retweeted
Calling all researchers 📢 @agoda's program is now public on the HackerOne platform. Help protect Agoda's customers' travel experiences and earn bounties up to $6K! bit.ly/3SbnLJn #Happyhacking
3
8
104
12,557
obscaries ❘ AppSec retweeted
Pre-orders for Grand Theft Auto VI will officially begin on June 25 on digital storefronts and at other select retailers. Check out the official cover art, also available as downloadable artwork at rockstargames.com/VI
1
3
1,166
obscaries ❘ AppSec retweeted
24 Bug Bounty tools:
8
63
1,790
obscaries ❘ AppSec retweeted
POV: You’re hunting a top-tier bug bounty target alongside seasoned pros operating at another level. Every request feels like it’s already been tested. Every lead feels one step behind. Pressure rising. Focus locked in. Welcome to the real game. 💀 #BugBounty #Infosec #CyberSecurity #EthicalHacking #BugBountyHunter
1
1
4
591
obscaries ❘ AppSec retweeted
Clean endpoint enumeration with Katana ⚔️ Filters out static noise and surfaces only useful endpoints Great for faster recon & finding hidden attack surface #BugBounty #Recon #InfoSec #CyberSecurity #Hacking
2
10
63
1,965
obscaries ❘ AppSec retweeted
Discover Subdomains via Certificate Transparency (CT) Logs Quickly enumerate subdomains using the CertSpotter CT log API. What it does: • Queries CT logs for certificates issued to a domain • Extracts all DNS names from those certificates • Outputs a clean, deduplicated list of subdomains How to use: 1️⃣ Replace example.com with your target domain CT logs often expose hidden assets like: dev, staging, internal, and forgotten environments. Small recon trick, big attack surface. 🕵️‍♂️ #BugBounty #AppSec #Recon #CyberSecurity
3
16
829
obscaries ❘ AppSec retweeted
4
7
101
4,545
obscaries ❘ AppSec retweeted
Business Logic Bugs are the silent assassins of bug bounty hunting. 💼⚰️ No zero-days. No complex payloads. No SQL injection. Just a sharp mind and the ability to see the gap between how a system should work and how it actually works. Here is my step-by-step playbook for finding them. 🧵👇
2
30
172
10,778
obscaries ❘ AppSec retweeted
🚨 Commix — Automated OS Command Injection Exploitation Tool If you're testing web applications for command injection, this open-source tool is definitely worth knowing. 🔎 Commix (Command Injection Exploiter) helps pentesters and bug bounty hunters automatically: • Detect OS command injection vulnerabilities • Exploit vulnerable parameters (GET / POST / Headers / Cookies) • Execute system commands on the target server • Launch interactive pseudo-shells for deeper testing • Perform result-based, blind & time-based injection attacks 💡 Think of it as “sqlmap but for command injection.” ⚠️ Command Injection can lead to Remote Code Execution (RCE) — one of the most critical vulnerabilities in web applications. 🔗 Source: github.com/commixproject/com… #BugBounty #CyberSecurity #Pentesting #InfoSec #AppSec #EthicalHacking #RCE #CommandInjection
4
29
2,997
obscaries ❘ AppSec retweeted
🚨 SSRF in Next.js Apps – Interesting Research If you're testing modern web apps, this is a great read from Assetnote on how SSRF can appear in Next.js applications. Key attack surfaces they discuss: 🔹 /_next/image endpoint 🔹 Redirect-based bypass tricks 🔹 Server Actions behavior 🔹 Host header manipulation Modern frameworks = new bug hunting opportunities. 🕵️‍♂️ 🔗 assetnote.io/resources/resea… #BugBounty #AppSec #WebSecurity #NextJS #SSRF
1
30
138
5,929
obscaries ❘ AppSec retweeted
🔎 Best Wordlists for Fuzzing (Bug Bounty Edition) If you're doing recon, fuzzing endpoints, parameters, or directories — these wordlists are gold. Sharing some of my favorites with the community 👇 📂 SecLists (Must Have) github.com/danielmiessler/Se… 📂 Assetnote Wordlists (Amazing for modern web targets) wordlists.assetnote.io 📂 fuzzdb github.com/fuzzdb-project/fu… 📂 OneListForAll github.com/six2dez/OneListFo… 📂 PayloadsAllTheThings (Great payload + fuzz lists) github.com/swisskyrepo/Paylo… 📂 Bo0oM Wordlists github.com/Bo0oM/fuzz.txt Good wordlists = better attack surface discovery. What other wordlists do you use for fuzzing? 👀 #BugBounty #AppSec #CyberSecurity #Recon #Fuzzing
2
25
82
5,441
obscaries ❘ AppSec retweeted
🕵️‍♂️ graphql-cop: Automated Security Auditing for GraphQL APIs I came across graphql-cop, a Python 🐍 tool that automatically tests GraphQL endpoints for common vulnerabilities. It helps security researchers quickly identify misconfigurations without manually crafting attack queries. 🔍 What it detects: 🧠 Introspection exposure (schema leaks) ⚡ Alias overloading & batching abuse (DoS vectors) 🐛 Debug/tracing modes left enabled 🌐 GET-based query execution (CSRF risks) 💡 Field suggestion leaks & misconfigurations For bug bounty hunters 🏴‍☠️ and pentesters, tools like this provide a fast baseline of GraphQL-specific attack surfaces. But remember—automated scanning is just the first step. The real impact comes from manual testing of authorization logic, query complexity, and business logic flaws 🎯 📦 Source: github.com/dolevf/graphql-co… #BugBounty #GraphQL #APIsecurity #AppSec #InfoSec
12
71
3,502
obscaries ❘ AppSec retweeted
🧬 urlDNA --- it’s a pretty interesting platform for deep URL analysis. Instead of just checking if a link is malicious, it performs a full behavioral scan and extracts a lot of useful intelligence from the target website, such as: 🔍 HTTP transactions & request flow 📡 Response headers and server information 🔐 SSL certificate details 🍪 Cookies and tracking behavior 🧩 Technology stack detection 📄 Full DOM snapshot of the page 📸 Screenshot of the rendered website 🌐 IP, ASN, and infrastructure information This kind of visibility can be really helpful when analyzing suspicious URLs, phishing pages, or simply understanding how a site behaves from a security perspective. Definitely a useful platform for security researchers, SOC analysts, and bug bounty hunters working with web intelligence. 🔗 urldna.io/ #BugBounty #AppSec #CyberSecurity #ThreatIntel
2
10
488
obscaries ❘ AppSec retweeted
Subdomain brute-forcing is only useful if your results are clean and trustworthy. That’s where puredns shines. ⭐ github.com/d3mondev/puredns #BugBounty #Recon #CyberSecurity #Infosec
5
36
1,359
obscaries ❘ AppSec retweeted
Just tried Dork King and it’s actually a pretty handy recon companion 🔎 Instead of remembering dozens of Google dorks, it lets you click and instantly search for a target. Super useful during passive recon. Source: dorkking.blindf.com/ #BugBounty #Recon #OSINT
1
18
72
6,401
obscaries ❘ AppSec retweeted
WebGL never fails to impress. Found messenger.abeto.co — a 3D game running entirely in the browser. No installs, no plugins, just modern web technology pushing the limits of what's possible on the web. What's the most impressive WebGL project you've seen? 👇
2
3
6
1,095