I have built:
- A security testing repo: https://t.co/HMJzUDi8Fv
- An API hacking tool: https://t.co/hi8nDg3ma5
- A blog: https://t.co/zBSMjqpcWq (Yeah I know cert expired, will look into that today)
- 150 exploits + 6 lifelike labs: https://t.co/jLmNLzsTlZ
- A student base of over 180 000 big: https://t.co/RXc5kZoGIr
- A wealth of courses: https://t.co/RF9xHvny3W
- A youtube channel with over 1200 video's: https://t.co/1fblu7Byq2
- A medium with over 7300 followers: https://t.co/VTeUYZIoh6
- An incredible fanbase of over 50 000 rats on youtube + 150 000 here
- A discord server with over 10 000 members + one for CAPIE + CNWPP + Hacker's toolkit
- A list of 10 students i got to directly reporting bugs: https://t.co/CDlzXdNvPB
- A song: https://t.co/nYQUGk0DV9 (No AI)
- A family of my own
- Reports on some of the giants of this earth
- A pentesting company
And still i get constantly attacked for not knowing anything - just copy pasting shit and not being good enough :-) hahaha you are so funny - THEN GO DO BETTER <3 Much love rat pack!! Thank you for the support!
๐ New live lab on RatCTF: Shapeshifter โ a Node.js developer profile service with a "merge" endpoint that trusts deeply nested JSON a little too much. Yep, prototype pollution. The box is online right now, so go scan it and pop it for the user and root flags.
๐
Liked this? Level up your bug bounty game with the Big Beautiful Bug Bounty Bundle (a discount applies via the link):
#infosec #bugbounty #ctf
๐ New lab to sink your teeth into: JWT Labs on HackXpert! Break JSON Web Tokens hands-on โ the 'none' algorithm trick, algorithm confusion, weak signing secrets and more, with progressively harder challenges (00 โ 20) and a solutions file for when you get stuck. Perfect for bug bounty hunters and API security folks.
Try it ๐
Want to go deeper? The 907 Big Beautiful Bug Bounty Bundle is the natural next step โ a discount applies via the link:
#infosec #bugbounty
๐ New from The XSS Rat: Why CAPIE[M] is the best API hacking certificate in the industry right now.
If you're serious about API security, Uncle Rat breaks down exactly why this cert stands out โ methodology, hands-on exploitation, and proving you can actually break (and secure) real APIs.
โถ๏ธ Watch it here:
Liked this? The Big Beautiful Bug Bounty Bundle is the natural next step โ a discount applies via the link:
#infosec #bugbounty #apisecurity
๐ Fresh from the lab: Uncle Rat's Bug Bounty Methodology โ 2026 Version.
A full 5-phase workflow built off a real https://t.co/YIcYrrN6Uf hunt: recon โ mapping โ vuln discovery โ exploitation/escalation โ reporting. Includes an input-classification decision tree, escalation paths for XSS/IDOR/SSRF/SQLi, the 20-minute rotation rule, and a 7-question gate before you ever hit submit.
Read it ๐
Want to go from reading the methodology to actually running it? The Big Beautiful Bug Bounty Bundle is the natural next step (a discount applies via the link):
#infosec #bugbounty
๐ Tool of the day from my SecurityTesting repo: https://t.co/eyThjowjit
One little Python script that installs AND runs your core recon stack โ nmap, gobuster, ffuf, amass, recon-ng & nuclei โ from a single place. Perfect for spinning up a quick recon flow without juggling six terminals.
Grab it here ๐
Liked this? Level up with my Big Beautiful Bug Bounty Bundle โ a discount applies via the link:
#infosec #bugbounty
๐ Want to actually get better at *detecting* attacks โ not just reading about them?
The "Help Me, I Got Compromised" purple team series drops you into a real 5-host breach: parse auth.log + Apache logs on the SIEM box, rebuild the full kill chain, then triage 15 SOC alerts and write a Python script that auto-classifies the queue. That's detection muscle you build by doing. ๐
๐
(Want to prove those skills on paper too? Certs here:
#purpleteam #infosec
๐ฉ Want your community to actually show up? Give them something to HACK.
Spin up your own branded CTF on RatCTF โ your logo, your challenges, a live leaderboard, your own slug. Members stop lurking and start competing. $20/month, setup included, cancel any time.
๐
Want to level up your own skills too? Grab a cert ๐
#ctf #infosec
@yy_vox Great question! It leans heavily toward individuals - hunters wanting to level up faster and build a real methodology, plus some team training. The 1:1 demand is strongest by far. That's the coaching I offer if you're curious: https://t.co/JM25kDcEmy
๐ฉ Run your own branded CTF in minutes โ your logo, colours, players. $20/month, setup included.
Want to level up too? 1:1 coaching โ
#ctf#infosec
๐จ NEW Bug Bounty Video: Stored XSS in an Unexpected Attack Surface | Razer Bug Bounty
In this video, I walk through:
โข Identifying the attack surface
โข Validating the injection point
โข Achieving persistent JavaScript execution
https://t.co/OxPsovA4oX
@Detoxin01 Love this addition - WebSocket frames are such an overlooked sink for stored XSS, and you're spot on that most scanners don't touch WS traffic. Manual testing wins here every time. Great eye!
WebSocket bugs live where REST hunters never look.
Open Burp โ WebSockets tab.
โข No Origin check on the handshake = Cross-Site WebSocket Hijacking
โข Auth on connect but not per-message = IDOR over WS
โข Frames skip REST validation โ inject inside them
hello amazing hacker ๐
Your bug bounty report IS the product you're selling. Find a critical bug, write a lazy report, and it gets closed as "informational" โ you get nothing.
How to write one that gets paid fast:
1. Title = bug + location + impact in ONE line. "IDOR in /api/orders lets any user read every customer's order" โ not "IDOR found". Your triager has 40 reports today; be obvious in 3 seconds.
2. Lead with IMPACT, not your payload. Open with the consequence: "any user can read all 80k orders incl. names + addresses." That's what sets severity and pays. The payload is just proof.
3. Steps a tired triager can copy-paste. Numbered, exact requests + responses, a curl command or a 60-sec clip. If they can't reproduce it in 2 minutes, it sits in the queue.
4. PROVE it, don't theorize. "This could maybe lead to..." gets closed. Show account B reading account A's data. PoC || GTFO.
5. Don't inflate severity. Map to CVSS honestly. One oversold report and every future one from you gets doubted. Your reputation is your real bankroll.
6. Suggest a fix. One line shows you get the root cause, not just the payload โ and triagers remember the hunters who make their life easy.
One bug per report. Don't bundle. Make each one boring to accept.
Practice the whole flow on a real target today:
Want the full zero-to-paid path โ methodology, recon + reporting end to end? That's the Big Beautiful Bug Bounty Bundle (discount via the link):
:-)
Hello amazing hacker ๐ ever wonder how LDAP + OAuth actually talk inside a real corporate network?
I built a full lab around it for CNWPP. WeCorp runs its domain controllers on LDAP, EntraID hands out JWTs, an OAuth app holds the ClientID + secret โ and one golden rule: direct connections to the workstation are BLOCKED. Everything has to flow through the auth chain.
Your job: map the trust, find where it bends, pivot through it.
Real-world network + web pentesting you drill in CNWPP ๐
https://t.co/VfosUOErxE
๐ New on RatCTF: Darkpulse โ a full Active Directory environment where every layer trusts the one beneath it. 5-star difficulty, with SNMP, SMB, LDAP and SSH all in play. The monitoring system sees everything... and soon, so will you. Launching today. ๐
โก๏ธ
Newer to this and want to build the fundamentals first? My 906 web hacking guide bundle is a solid on-ramp (a discount applies via the link):
#infosec #bugbounty #ctf #ActiveDirectory #pentest
๐ JWT tokens are everywhere โ and so are the ways to break them. My FREE JWT Labs walk you through real-world attacks: the "none" algorithm, weak signing keys & more, with challenges that get progressively harder until you snag the flag ๐ฉ
Try it ๐
Liked this? Level up with my 906 Web Hacking bundle (a discount applies via the link) ๐
#infosec #bugbounty
๐ New video: Why CAPIE[M] is the best API hacking certificate in the industry.
I break down what makes this cert actually worth your time if you're serious about API security and bug bounty โ what it tests and who it's for.
โถ๏ธ Watch:
Liked this? Level up with my 906 bundle โ a discount applies via the link:
#infosec #bugbounty #APIsecurity
I built the CAPIE exam to be brutal โ business logic flaws, broken access control, IDORs, nasty edge cases. Then an agentic AI pentester from https://t.co/Ow5Ki23SFO walked in and absolutely aced it. It even rooted one of my servers in a follow-up.
Humbling? Absolutely. But the real takeaway isn't man vs machine โ it's man WITH machine. My honest writeup on losing to AI on my own exam ๐
Liked this? Level up with my 906 bundle (a discount applies via the link): #infosec #bugbounty
Want to actually practice XSS instead of just reading about it? ๐
This folder of hands-on PHP XSS labs in my SecurityTesting repo lets you break things locally โ reflected, DOM-based, JS-context, tag-injection, and a sneaky filter/whitelist-bypass challenge (it "validates" input with FILTER_VALIDATE_EMAIL... what could go wrong?).
Spin them up, pop the alert, and learn why each payload works:
Liked this? My 906 bundle is the natural next step if you want to go deeper โ a discount applies via the link:
#infosec #bugbounty