Ana Ins Profile
Ana Ins

@hack2save

Followers
5
Following
155
Media
1
Statuses
190

Science Technology InfoSec

Earth
Joined February 2024
Don't wanna be here? Send us removal request.
@hack2save
Ana Ins
8 days
RT @WebSecAcademy: Learning Path: CORS Misconfigurations. This learning path teaches you how to find, exploit, and escalate CORS misconfigu….
0
10
0
@hack2save
Ana Ins
9 days
RT @xss0r: 🚨 Did you know? We’ve just published FREE Course Videos on Blind XSS Hunting at . 📍 Visit the “Where to….
0
10
0
@hack2save
Ana Ins
9 days
RT @NahamSec: HTTP Request Smuggling Explained (with @albinowax) . 🎥👉🏼
Tweet media one
0
89
0
@hack2save
Ana Ins
10 days
RT @KN0X55: 🏆 KNOXSS August 2025 Giveaway 🏆. ➡️ Follow, like and share! 😍. ➡️ 1 Month Pro access for 3 winners on Friday 8th. Good luck! 🤞….
0
79
0
@hack2save
Ana Ins
11 days
RT @HusseiN98D: 🚀 $100 GIVEAWAY 🚀. Clone ANY website into clean React + TypeScript code in MINUTES!. Watch me recreate GitHub's landing pag….
0
14
0
@hack2save
Ana Ins
13 days
RT @WebSecAcademy: How to find viable targets for client-side desync attacks:. 1️⃣ Open Burp Suite and intercept requests. 2️⃣ Choose an e….
0
53
0
@hack2save
Ana Ins
1 month
I find it overwhelming testing this target and I see many hunters might avoid it because of the heavy reliance on websockets by the app. Please how do you approach a complex target heavily relying on websockets? Do you recommend some tools or techniques?.
0
0
0
@hack2save
Ana Ins
1 month
The access controls, managing tasks, inbox, and lots more of the core app all depends on websockets. Never seen an app so heavily rely on websockets like this one. In fact the HTTP history is extremely low compared to websocket history in proxy.
1
0
0
@hack2save
Ana Ins
2 months
RT @phwd_: Facebook page admin and email disclosure.
0
25
0
@hack2save
Ana Ins
3 months
Hey hunters (esp. manual hunters), don't miss this treasure from @ArchAngelDDay .
Tweet card summary image
douglas.day
Treating Your Scope Like a Treasure Hunt
0
0
0
@hack2save
Ana Ins
3 months
RT @0xacb: Hidden or disabled fields are commonly overlooked, but they can still open the door to some cool bugs. Try creating a bookmarkl….
0
97
0
@hack2save
Ana Ins
3 months
RT @0xTib3rius: Quickest way to reliably find business logic flaws is to change your mindset:. You're not looking for bugs, you're hunting….
0
3
0
@hack2save
Ana Ins
5 months
RT @Jhaddix: 🛑 GIVEAWAY ALERT 🛑 ⬇️. Today @arcanuminfosec is giving away 3 seats to our training: . "Red Blue Purple AI" - March 27-28….
0
242
0
@hack2save
Ana Ins
6 months
RT @Doyensec: Despite being central to their security, many orgs struggle to securely implement #OAuth. Our new post walks through common i….
0
65
0
@hack2save
Ana Ins
7 months
RT @tbbhunter: A Journey of Limited Path Traversal To RCE With $40,000 Bounty!.
Tweet card summary image
medium.com
#Introduce Myself:
0
40
0
@hack2save
Ana Ins
8 months
RT @S1r1u5_: Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earne….
0
178
0
@hack2save
Ana Ins
9 months
RT @Jhaddix: 🚨 GIVEAWAY ALERT 🚨. Today is DAY ONE of FIVE DAYS of @arcanuminfosec and friends Black Friday and Cyber Monday giveaways!. Tod….
0
329
0
@hack2save
Ana Ins
9 months
RT @Burp_Suite: 🛠️ Huge shoutout to Oussama Zgheb for their incredible BApp extension, JSON Web Tokens! . Quickly and efficiently assess th….
Tweet card summary image
portswigger.net
Enables Burp to decode and manipulate JSON web tokens.
0
22
0
@hack2save
Ana Ins
9 months
RT @RenwaX23: New writing: Story of how I got UXSS, LFI and RCE in Arc browser by visiting a webpage and clicking Install Boost. Using a b….
0
45
0