HExHTTP v2.5 is out ! 🥳
- Many fixes for bugs & FP (a huge reduction !)
- HHMP (Host Header Manipulation Poisoning) & CFP (Change Format Page) CPDoS module
- Generates an interactive HTML report from scan results with -o option (export json/csv in HTML)
& more in CHANGELOG.md,
If you find it useful, consider supporting the project - even a small contribution helps a lot !
https://t.co/uyw0Z2lC77
Hello,
A short post about a fairly simple CPDoS method that I haven't seen anywhere else (AFAIK)
I hope you enjoy it, happy reading !
CPDoS via Content Negotiation Mechanism:
https://t.co/7oZhR4Ac5T
Plop !
New tool in "Beta" version:
- GimmeYourPassword : GYP is a tool designed to perform tests on reset password features on websites and analyze the results to identify vulnerabilities and interesting behaviors.
https://t.co/XB6H2ZrkQF
If any of you have already encountered this type of vulnerability in a bug bounty program, it would be great if you could contact me, please :)
Have fun !
Happy new year !
What's new on my GitHub ?
- wcDetect v1.3: https://t.co/JlCnsAE5k3
New README & Logo
Add payloads
Fixed design/bugs & more
- Instaguard: https://t.co/osv2uyrKet
Instagram analysis apk with a trusting score indicating if it's a fake/scammer account
Hello,
A quick update for the holidays before taking a break from HExHTTP, as I'm going to focus on other new projects (which I hope you'll also enjoy), so give me as many stars and as much support as you can as a Christmas gift ! ❤️🔥
HExHTTP v2.4 now available !
Have a great holiday season and Hack the planet !
https://t.co/uyw0Z2lC77
#BugBounty
Plop !
HExHTTP v2.3:
- Renames files and directory
- Linting
- Fixed bugs
- Remake simple cache poisoning module
- New payloads
- Menu in README(.)md
- CVE-2025-57822 module check
- Add random user-agent during cpdos to avoid overly strict waf
& more ! :)
HF !
https://t.co/uyw0Z2m9WF
PS: If you have benefited from my work, you can support me financially through github sponsors or just buy me a coffe: https://t.co/WGKIoxQPaO
#BugBounty
🎉Happy to realease HExHTTP v2 !🎉
https://t.co/rKm7WZzeBS
Thanks to @KharaTheOne@Geluchat@Nishacid@__PH4NTOM__ for the help ! 🙏
& Thanks to BB FR community ! 😁
Have Fun & Hack the Planet ! 🌍
( & If you would like to contribute, pls feel free to give a little coffe :)
Want to sharpen your SSTI, cache poisoning or business logic error skills? 🧠 The hunters who topped our 2024 leaderboards for these CWEs – @LdrTom, @c0dejump and @kto_94_ – kindly shared their best-practice tips with us 👇
#BugBountyTips
https://t.co/5X60u1PuCI
Hi all,
While waiting for v2 of HExHTTP, here is a small update of wcDetect (web cache deception scanner) with new payloads and minor corrections 🙂
https://t.co/5tIIcsZXCT
As well as a little teaser of the new script projects I have in mind (I'll let you guess what they'll be used for):
- DjaNoGo
- WileThrottle
Have fun !