๐งต The Art of Subdomain Permutations
Most hunters stop at subdomain enumeration.
The real recon starts when you begin generating what developers forgot to expose ๐
Here are some of the best permutation tools every bug bounty hunter should know about โ
Time-Based SQL Injection Is Still Everywhere!๐ฅ
You can fingerprint the backend DB version with
'; IF (SUBSTRING(@@VERSION,1,1) = 'M') WAITFOR DELAY '0:0:10' --
Delay = proof.
Thanks dude
#BugBounty#SQLi#bugbountytips#hackerone
When we decompile an APK and see an unreadable https://t.co/BbQf3H943H.bundle, it could be Hermes bytecode. Using https://t.co/DBonMwpUBM we can make it readable and look for interesting endpoints, keys, or app flows.
#bugbounty
Google has a pirate enemy.
He's one guy. His name is Raymond Hill.
He built uBlock Origin. The world's best ad blocker. 63K stars. GPL-3.0. He literally refuses every dollar you try to send him.
Then Google did the unthinkable.
July 24, 2025. Manifest V2 disabled everywhere. The full uBlock Origin stopped working on Chrome.
The world's biggest ad company nuked the world's biggest ad blocker on its own browser. They called it "security."
Coincidence.
Here's the wildest part:
Raymond didn't fold. Latest release: March 11, 2026.
Still alive on Firefox. Still alive on Edge. Still alive on Brave. Still GPL-3.0. Still refusing every dollar.
One developer vs. the trillion-dollar ad empire.
But DO NOT install it. We should all keep Google richer.
100% Open Source.
(Link in the comments)