xnl_h4ck3r Profile Banner
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky) Profile
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)

@xnl_h4ck3r

Followers
9K
Following
9K
Media
222
Statuses
3K

Aspiring Bug Bounty Hunter & dev of tools: GAP, xnLinkFinder, waymore, urless, XnlReveal, knoxnl, xnldorker 🤘 RTFM🧐... always... PLEASE!

Wales
Joined August 2020
Don't wanna be here? Send us removal request.
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 years
My #BugBounty tools 🤘 👉xnLinkFinder - get links, params & target wordlist 👉waymore - get URLs & archived responses 👉GAP - Burp ext. like xnLinkFinder 👉urless - de-clutter URL list 👉knoxnl - wrapper for KNOXSS API 👉 Xnl Reveal - BB Chrome Extension https://t.co/o97XWDJjne
Tweet card summary image
github.com
Aspiring Bug Bounty Hunter and developer of tools! 🤘 - xnl-h4ck3r
15
74
338
@Jhaddix
JS0N Haddix
17 hours
Our FREE Modern Recon Workshop is coming up! https://t.co/SXD5b30kQm We also want to thank our sponsor for this webinar @PlexTrac ! PlexTrac unifies and streamlines pentesting operations through a continuous, workflow-driven approach that brings pentest data directly into the
Tweet card summary image
us06web.zoom.us
Join us Dec 8th to chop game on new tools, sites, and methodologies for modern horizontal recon. Horizontal recon is the art of identifying acquisitions, domains, subdomains, infrastructure, and...
1
22
97
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 days
v7.0 of waymore is available: ✅ Get URLs 2-4x faster in mode U ✅ Download responses upto 2x faster in mode R 🩹 Many bug fixes 👉 See CHANGELOG for all details 👉 Update with "pip install --upgrade waymore" https://t.co/Olv7lLQtha #BugBounty 🤘
Tweet card summary image
github.com
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! - xnl-h4ck3r/waymore
2
8
85
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 days
Wayback machine is currently broken and bringing back a mix of responses: 504 Gateway Time-out & 503 Service Unavailable 😢 I knew it was down though because the Xnl Reveal browser extension shows the icon with a red background, which is a feature I find useful
1
0
21
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 days
I listened to less music than last year. Kinda annoyed about that 😂
0
0
8
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 days
Obviously you don't need to use a VPN if Common Crawl hasn't blocked you yet, but if you start seeing errors like: CommonCrawl - [ ERR ] Connection error for index... then you're getting blocked by IP :( I also reboot my router to get a new IP instead, if running locally
0
0
4
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 days
And DON'T use a VPN if you want full results from Wayback machine and get them quicker. This is especially the case for mode R downloading responses So you can use --providers to run separately for different sources. #BugBounty 🤘
1
0
7
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
2 days
🛠️ waymore: Tip #11 📝 Using a VPN can mean getting URLs from Common Crawl when otherwise you may be blocked, but a VPN can make Wayback rate limit you So, DO use a VPN for Common Crawl and use --limit 0 to check ALL indexes You can use --providers commoncrawl ...
1
0
41
@busf4ctor
Vitor Falcão "busfactor"
3 days
Did you see BugBountyDaily got a "Ask AI" feature now? The best part is that it makes a proxy and uses your Gemini tokens, not mine (it's free). I had no idea we could do that. Note: since I didn't scrape the posts' content or descriptions, it may have a few misses :)
0
10
106
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
4 days
Just a yearly reminder... The wayback machine internet archives are a goldmine for bug hunters which we all take for granted. Imagine it just went offline for good!... Scary 😱 So if it's helped you find bugs, consider donating to this nonprofit https://t.co/cEnBk1gCIg #BugBounty
0
1
60
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
4 days
A new version of waymore is coming soon where it will be 2-4x faster getting URLs with mode U and 2x faster downloading responses with mode R https://t.co/Olv7lLQtha #BugBounty 🤘
Tweet card summary image
github.com
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! - xnl-h4ck3r/waymore
2
10
101
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
7 days
I know there is still no @CaidoIO version of GAP, but if you really want all the functionality of GAP, you can save the Caido history and pass the CSV to xnLinkFinder! See https://t.co/h9U0XIRqaS for more. #BugBounty 🤘
1
1
31
@0xacb
André Baptista
9 days
If you need to generate a target-specific wordlist, make sure to check out @xnl_h4ck3r GAP extension. It will scan for sus parameters and generate you a complete wordlist with one click of a button. See it in action 👇
2
43
290
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
10 days
Will I see any of you there? 👇
@GreenJamSec
Jim Green
16 days
Bug bounty hunters near London! The next HackerOne Brand Ambassador meet up is on Sat 29th November and we have a few spaces left. RSVP https://t.co/JJUA4L2EVJ What to expect: - Talk from @xnl_h4ck3r on his amazing tools 🔧 - Hackalong 👨‍💻 - 🆓🍕 - 🆓swag 🎁 - Meet, chat, learn!
0
0
3
@Jhaddix
JS0N Haddix
10 days
As a bonus we added the JS Analysis section from TBHM Core to the expansion too, in case you didn't have it yet! It includes advanced techniques for parsing secrets, endpoints, and useful data for bug hunting! https://t.co/8VTCHCDLhM
2
26
193
@Jhaddix
JS0N Haddix
10 days
TBHM Expansion - Bug Chaining, Escalation, and Advanced Client-Side is now live! Come catch @xssdoctor give his masterclass! https://t.co/8VTCHCDLhM
Tweet card summary image
arcanum-sec.com
@xssdoctor
xssdoctor
10 days
For the past 3 months I worked really hard with @Jhaddix to make a course on client side exploitation. I think it turned out really well, and It’s finally live! I hope you guys like it https://t.co/n7lMbavc8m
2
9
61
@xssdoctor
xssdoctor
10 days
For the past 3 months I worked really hard with @Jhaddix to make a course on client side exploitation. I think it turned out really well, and It’s finally live! I hope you guys like it https://t.co/n7lMbavc8m
Tweet card summary image
arcanum-sec.com
8
28
226
@Jhaddix
JS0N Haddix
14 days
We got some FANTASTIC feedback from this cohort of Attacking AI! - We added several more PI Techniques and Evasions - We added sections on understanding and attacking ecosystems like OpenAI and Microsoft - We upped the defense section a lot I'm so excited! Working on two more
3
7
66
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
14 days
@tabaahi_ @NahamSec @arshadkazmi42 @bug_vs_me @coffinxp7 @TeslaTheGod @HarshDRanjan1 @ThisIsDK999 @h4x0r_dz @PhilippeDelteil @Nouureldin_Ehab @h4x0r_fr34k @GodfatherOrwa @hxp7th @galnagli @ReebootToInit5 are specific GPTs that can be even more useful and specific to bug bounty. A good example is Jason Haddix's Arcanum Cyber Security Bot: https://t.co/OBR5J8CUFr Good luck hunting!
0
0
0
@xnl_h4ck3r
/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky)
14 days
@tabaahi_ @NahamSec @arshadkazmi42 @bug_vs_me @coffinxp7 @TeslaTheGod @HarshDRanjan1 @ThisIsDK999 @h4x0r_dz @PhilippeDelteil @Nouureldin_Ehab @h4x0r_fr34k @GodfatherOrwa @hxp7th @galnagli @ReebootToInit5 then by all means reach out to someone for help. There are many discord servers with many people wiling to help if you post a question. Here are some good ones: https://t.co/u0NYogUHg4 https://t.co/yO354gthiv https://t.co/3DuDxyEUWP Also, asking AI is always useful but there
1
0
0