0xacb
0xacb.com
0xacb
@0xacb.com
1.4K followers 98 following 210 posts
Hacker grinding for L1gh7 and Fr33dφm, straight outta the cosmic realm. Co-founder @ethiack.com https://0xacb.com
Posts Media Videos Starter Packs
Tomorrow I'll be speaking at https://lisbonai.xyz

We're building faster than ever with AI. But are we building securely?

I'll show how agents can perform penetration testing and introduce Hackian: an autonomous agent that identifies vulnerabilities before attackers do.
Just had an amazing time working with Shopify in Toronto 🍁

Thanks @hacker0x01.bsky.social for organizing such an incredible event and bringing awesome researchers together.

#togetherwehitharder #h1416 #shopify #hacking #goleafs
Modern websites use a lot of intermediary servers - caches, load balancers, proxies, and so on. You can try to send the 'Max-Forwards' header with your request to limit the amount of servers it will reach. It's defined in HTTP specs primarily for TRACE and OPTIONS methods, though.
Reposted by 0xacb
🚨BsidesLisbon CTF Quals starts now!
🔓Join at: quals.bsideslisbon.org

#CTF #BSidesLisbon
0xacb @0xacb.com · 12d
Recon tip: Run xnl-h4ck3r's waymore on the target you're testing. It searches for URLs from multiple sources, the Wayback Machine, Common Crawl, URLScan and more. It also provides a lot of options to filter your results.

Check it out here 👇
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X!
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! - xnl-h4ck3r/waymore
github.com
0xacb @0xacb.com · 13d
Found an XSS but got blocked by the CSP?

https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
0xacb @0xacb.com · Oct 2
Thanks @hacker0x01.bsky.social for the amazing LHE!

Had the chance to work with TikTok and OKX and found some cool vulns, including two 0days. Will try to publish a write up once they're fixed!

Also, big congrats to the new MVH champion @corraldev.bsky.social for the huge mic-drop at this event 🤯
0xacb @0xacb.com · Sep 28
On my way to @hacker0x01.bsky.social #h165 to pop some shells on TikTok and OKX ✈️
0xacb @0xacb.com · Sep 25
#HackAIcon is finally here! 🚀
0xacb @0xacb.com · Sep 24
How to extract endpoints from JS using @pdiscoveryio's katana 👇
0xacb @0xacb.com · Sep 18
Just one week to go until hackAIcon in Lisbon! 🤖🇵🇹

Can't believe tickets have officially sold out already!

Thank you to everyone that has supported the event 🙏

I can't wait to see you all there!
0xacb @0xacb.com · Sep 16
If you need a list of trusted resolvers, e.g. to be used with puredns for active enumeration, @trick3st has a great one.

Just run this: 
⌨️ curl https://raw.githubusercontent.com/trickest/resolvers/refs/heads/main/resolvers-trusted.txt -O

More stuff at👇
https://github.com/trickest/resolvers
0xacb @0xacb.com · Sep 15
If you look at the AI-generated code below, you may notice that path traversal is prevented via basename functions.

Can you still exploit it?

Try here 👉 https://ai4eh.ethiack.ninja
0xacb @0xacb.com · Sep 12
The Hack the Agent challenge is finished.

GG to all the hackers who played! We hope you enjoyed it.

We will leave it running for those who still want to play with it at https://hacktheagent.com

Stay tuned on @ethiack socials for more challenges.
0xacb @0xacb.com · Sep 10
This one-liner by @tomnomnom.com finds all Git repos, creates a git-objects/ folder for each one and dumps every object (commits, trees, blobs, tags) into files named by their hash.

Effectively exporting the raw Git database into human-readable files, repo by repo!
0xacb @0xacb.com · Sep 5
Some thoughts from @rez0__ on the future of bug bounty and AI 🔥

As someone working on hackbots, I agree that human + AI symbiosis will likely be more effective than either alone.

This Is How They Tell Me Bug Bounty Ends
Exploring the transformation and future of bug bounty hunting with automation and AI.
josephthacker.com
0xacb @0xacb.com · Sep 2
Want to put your AI model hacking skills to the test?

See if you can solve all the challenges in our Hack The Agent challenge!

Try it at: https://hacktheagent.com
0xacb @0xacb.com · Sep 1
Want to learn how AI can be used for ethical hacking? 

Check out the contents from my workshop on Github! 

You'll find:
✅ Workshop guide
✅ Scripts
✅ Tools
✅ CTF Challenges

Get stuck in (feedback welcome!) at 
GitHub - ethiack/ai4eh: AI for Ethical Hacking - Workshop
AI for Ethical Hacking - Workshop. Contribute to ethiack/ai4eh development by creating an account on GitHub.
github.com
0xacb @0xacb.com · Aug 28
If you want to try to win a ticket, we are currently running a 5-level LLM CTF Challenge where your goal is to jailbreak your way into our raffles! Start now: https://hacktheagent.com

Good luck!
Hack the Agent | Can you get a free ticket?
HackAIcon is around the corner, and we wanted to give you a little challenge. Can you extract a free ticket?
hacktheagent.com