๐ Great news for my followers!
Huge thanks to @theXSSrat ๐
Iโll be giving away 50 coupons, each worth 25โฌ ๐ธ
To join:
๐ฃ Follow me
๐ Retweet this post
๐ฌ Leave a comment
Winners will be picked soon based on engagement. Good luck ๐
๐ KNOXSS September 2025 Giveaway ๐
โก๏ธ Follow, like and share! ๐
โก๏ธ 1 Month Pro access for 3 winners on Friday 5th
Good luck! ๐ค
Check what only KNOXSS can find for you:
https://t.co/IpGFTHG3pl
https://t.co/3sWDgbdEN9 - try it now!
#WebAppSec#BugBounty#PenTesting
๐จ GIVEAWAY ALERT ๐จ
Got 2 fresh @tryhackme 1-month vouchers burning a hole in my pocket ๐ฅ
Meanwhileโฆ my hackers toolkit is 85% off (all current + future courses in one)
https://t.co/XMfKk25Zyj
Want one? Do this:
1๏ธโฃ Follow @TheXSSRat + @tryhackme
2๏ธโฃ Share this post
3๏ธโฃ Drop a comment
4๏ธโฃ Smash that like
Youโve got 72 hours, dear rats ๐
๐ Weโre partnering with @theXSSrat for a special giveaway!
Once we hit 5,000 followers, 1 lucky winner will get access to $600 worth of cybersecurity courses โ for FREE!
To enter the giveaway:
โ Follow
๐ Retweet this post
๐ฌ Leave a comment
๐ Course
https://t.co/drUsKr1vHH
How to find viable targets for client-side desync attacks:
1๏ธโฃ Open Burp Suite and intercept requests.
2๏ธโฃ Choose an endpoint that wouldn't usually expect a POST request (e.g GET) and send it to repeater.
3๏ธโฃ Go to Inspector > Request Attributes > Protocol field > Upgrade to HTTP/2.
4๏ธโฃ Send the Modified Request and look for this error message:
"Server ALPN does not advertise HTTP/2 support"...
5๏ธโฃ Enable ALPN Override in request settings and send again.
If you see "Stream failed to close correctly" then you've confirmed that the server does not support HTTP/2 and is a valid target for desync testing!
Want to learn more about desync attacks? On August 6, at Black Hat USA, James Kettle from PortSwigger Research will reveal new classes of desync attack that enabled him to compromise multiple CDNs and kick off the desync endgame! ๐ฒ
Stay up to date here: https://t.co/kr6SR4JOw3
To celebrate our badge launch, we're giving away FIVE free 6-month licenses to @pentesterlab.
โ Comment BADGELIFE and retweet this post to enter.
Additionally, pre-order a custom badge at https://t.co/FazR6OSE77 for a chance to win one of FIVE Annual VIP+ subscription to @hackthebox_eu. Purchasing a badge helps us run and fund the village.
That's a total of TEN WINNERS! Winners will be picked on August 1st. Good luck!
Note: Badges are pre-order only. Order online, pick up in village. No shipping. #BadgeLife #DEFCON33 #BugBounty
Time for another giveaway!
We are going to send a t-shirt and a few goodies to one person who follows @PentesterLab and retweets this tweet!!
And we are going to give a 12-month voucher to someone who follows @PentesterLab and likes this tweet!!
Hey there!
I have 2 conference passes for IWCON2.0 which is happening on 17th-18th December, 2022.
To enter the giveaway:
1. Follow @thebinarybot ๐ซ
2. Retweet ๐
3. Comment which talk you are highly looking forward to ๐ญ
#bugbounty#infosec#cybersecurity#hacking
I've got two passes for IWCON2.0 happening on 17th-18th December, 2022 from the awesome folks @InfoSecComm ๐
Register here : https://t.co/Wq5JIwUvAY
To win these passes just retweet this and like the tweet. Two of the luck winners will be contacted by the team for the passes.
It's Black Friday! ๐
Get FREE recurring API credits if you like + retweet this tweet (must be following @securitytrails).
If we get up to 100 RTs everyone gets 100 recurring monthly API credits. If we get over 100 RTs, everyone gets the # of API credits in the amount of RTs.