coffinxp7 Profile Banner
Coffin Profile
Coffin

@coffinxp7

Followers
26K
Following
11K
Media
507
Statuses
5K

ʜᴇʟᴘɪɴɢ ᴏʀɢᴀɴɪᴢᴀᴛɪᴏɴꜱ ꜱᴛᴀʏ ꜱᴇᴄᴜʀᴇ ᴛʜʀᴏᴜɢʜ ʙᴜɢ ʜᴜɴᴛɪɴɢ, ᴏꜱɪɴᴛ ᴀɴᴅ ꜱᴇᴄᴜʀɪᴛʏ ʀᴇꜱᴇᴀʀᴄʜ | ᴡʀɪᴛᴇᴜᴘꜱ: https://t.co/i4lh1OfrQY | ᴄᴏᴍᴍᴜɴɪᴛʏ: https://t.co/UmuN0pmh37

area 51
Joined October 2023
Don't wanna be here? Send us removal request.
@coffinxp7
Coffin
4 months
here we go! hope this helps every beginner trying to master the full recon to exploitation process. i’ve covered every step in detail and will be adding more soon..just a bit caught up with things right now. https://t.co/bykbiDNYGG
Tweet card summary image
infosecwriteups.com
Proven Step-by-Step Recon Techniques to Uncover Your First Vulnerabilities in Bug Bounty Programs
30
105
547
@coffinxp7
Coffin
1 hour
You’ll find a curated list of top browser extensions specially for bug hunters in this article. https://t.co/FTH3F3zDtF
Tweet card summary image
infosecwriteups.com
30 Must-Have Browser Extensions for BugHunters & Cybersec professional
1
3
25
@coffinxp7
Coffin
1 hour
You’ll find a curated list of top browser extensions specially for bug hunters in this article. https://t.co/FTH3F3zDtF
Tweet card summary image
infosecwriteups.com
30 Must-Have Browser Extensions for BugHunters & Cybersec professional
1
3
25
@coffinxp7
Coffin
1 hour
These three extensions will definitely help and save you time during your bug hunting process: Fake Filler, Code Formatter: js, css, json
5
2
50
@coffinxp7
Coffin
6 hours
The less experience you have, the more likely you are to be exploited.
3
0
26
@coffinxp7
Coffin
7 hours
We live in a World where people profit from beginners by selling courses, even selling PortSwigger lab solutions and nobody talks about it. If someone publishes free, real-world demonstrations rather than lab walkthroughs, it provokes criticism. At least my video helped many to
20
16
197
@coffinxp7
Coffin
1 day
I also added a search option to make lookups easier. I'll include this script in my Medium article like I usually do..
5
4
91
@ethicalrohitt
Rohit Pawar
2 days
Hey bro! Just wanted to let you know I received another bounty €1,000 for reporting an account takeover! First 2fa bypass & now this one.Thank you so much, man. Because of you, I’ve come this far. Really appreciate everything love you, bro🥹❤️ @coffinxp7 #ethicalrohitt
9
4
93
@coffinxp7
Coffin
2 days
This is the reason I stopped using Burp’s IP rotation extension because it can quickly consume paid proxy/traffic limits. If you use it without monitoring, you’ll likely face a big bill. Extension link:
Tweet card summary image
portswigger.net
Uses AWS API Gateway to change your IP on every request.
@ThePrimeagen
ThePrimeagen
3 days
TIL I have an AWS something or other running
7
4
68
@coffinxp7
Coffin
3 days
admin russian
0
0
21
@coffinxp7
Coffin
3 days
Thanks @orderby99 for testing the username with the same password and letting me know..thats why i love hacking community 🔥
1
0
13
@coffinxp7
Coffin
3 days
cc2:
0
0
16
@coffinxp7
Coffin
3 days
cc:
@AUZombie
luu
4 days
More sex shop themed Cyber Stealer panels: 69.30.247[.]233:3004 iloveboats9[.]vip @solostalking @500mk500 #InfoSec #malware #iocs
0
0
14
@coffinxp7
Coffin
3 days
Hell nahh..Check this out all🔥you will enjoy it <33 Full Admin pannel access via this simple methodology..
40
52
566
@coffinxp7
Coffin
3 days
Due to restrictions in the Brave browser, only certain cookies are visible.
0
0
10
@coffinxp7
Coffin
3 days
PoC: I was able to access all users’ cookies, localStorage data and IP addresses..
1
3
125
@coffinxp7
Coffin
3 days
When I first started on Medium within a week i found Stored XSS/Htmli/Iframe Injection that could run on readers’ browsers. At the time Medium had no bug bounty or disclosure program, so they quietly fixed it without acknowledgment.
9
14
329
@coffinxp7
Coffin
6 days
now, i love gospider more then any other crawlers <3 i will prove it why this is so powerful in upcomming videos..
3
2
44
@coffinxp7
Coffin
6 days
I just updated my recon guide and added a new section on Gospider methodology. it’ll definitely help you in your bug hunting. Check out the full article:
@coffinxp7
Coffin
1 month
Finally Here’s a new recon guide that will help you find bugs. I’ve included some private scripts and techniques I use. if even one person lands a bounty from this, I’ll consider the effort worth it. https://t.co/CQcSMGVLQy
13
44
327
@coffinxp7
Coffin
17 days
Hi everyone! I just built a WaybackURLs extension that saves you a ton of time when gathering archive URLs. it supports main domains, wildcards, specific paths and sensitive file extensions. Give it a try and let me know your feedback! https://t.co/vezBMPFpgp
46
156
1K
@coffinxp7
Coffin
18 days
more techniques here:
Tweet card summary image
infosecwriteups.com
Learn How Hackers Bypass Rate Limits and How You Can Too
@0x0SojalSec
Md Ismail Šojal 🕷️
19 days
Rate Limiting Bypass ✨ IP Rotation --> Sending new ip's Null byte -- %00,%0d%0a,%09 exapmple:email:test5119@yopmail.com%00 4. X-Forwarded-For: IP ex:X-Forwarded-For: 127.0.0.1 5. Double X forward option ex: X-Forwarded-For: X-Forwarded-For:127.0.0.1 #infosec
0
15
138