/ XNL -Π½4cΔΈ3r's Avatar

/ XNL -Π½4cΔΈ3r

@xnl-h4ck3r

Aspiring Bug Bounty Hunter & dev of tools: GAP, xnLinkFinder & waymore, featured in "Bug Hunter’s Methodology: Application Analysis v1" by JHaddix 🀘 RTFM🧐

1,843
Followers
193
Following
116
Posts
21.09.2023
Joined
Posts Following

Latest posts by / XNL -Π½4cΔΈ3r @xnl-h4ck3r

GitHub - xnl-h4ck3r/XnlReveal: A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled e... A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements. - xnl-h4ck3r/XnlReveal

v4.3 of Xnl Reveal is available:

🩹 BUG FIX: It wasn't installed with the intended font, so didn't look great on anyone else's machine but mine πŸ˜…

github.com/xnl-h4ck3r/X...
#BugBounty
🀘

06.03.2026 12:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! - xnl-h4ck3r/waymore

v8.6 of waymore is available:

🩹 Fixed silent regex failures (-ko / -ra)
🩹 Fixed MIME type validation for RFC-valid chars
βœ… Improved CDX/Common Crawl keyword matching logic
βœ… See CHANGELOG for more details

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

03.03.2026 14:51 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! - xnl-h4ck3r/waymore

v8.5 of waymore is available:

🩹 BUG FIX: Input paths containing spaces were failing.
🩹 BUG FIX: Input paths were incorrectly forced to lowercase.

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

07.02.2026 20:19 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! - xnl-h4ck3r/waymore

v8.4 of waymore is available:

🩹 BUG FIX: Prevent various intermittent bugs where objects are not checked if None first. I think the errors are rare, but please upgrade.

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

03.02.2026 20:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! - xnl-h4ck3r/waymore

v8.1 of waymore is available:

βœ… For some reason, the config.yml file doesn't get created for some users when installing. If this happens, the default config file will be created, if it doesn't already exist, when waymore is run

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

24.01.2026 12:58 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X! - xnl-h4ck3r/waymore

v8.0 of waymore is available:

βœ… Add source GhostArchive for mode U and R
βœ… Add arg -xga to exclude GhostArchive
βœ… Update --providers arg to include ghostarchive
βœ… Remove PDF from default filters (they can contain great content)

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

22.01.2026 00:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! - xnl-h4ck3r/waymore

v7.7 of waymore is available:

🩹 BUG FIX: Binary files like PDF, ZIP, etc. weren't being downloaded correctly so corrupted when trying to open
βœ… Add some more audio/video filter types
βœ… See CHANGELOG for more details

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

16.01.2026 14:59 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets - xnl-h4ck3r/xnLinkFinder

v8.1 of xnLinkFinder is available:

βœ… Add arg -rp / --request-proxy to specify a proxy for requests to be made through, e.g. socks5.
🩹 If --forward-proxy is used, it now correctly sends all retrieved URLs, not just ones requested.

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

15.01.2026 23:31 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets - xnl-h4ck3r/xnLinkFinder

v8.0 of xnLinkFinder is available:

βœ… Added functionality to find secrets within parsed responses/files.
βœ… Add arg -os / --output-secrets to specify name of JSON output file for secrets.
βœ… See CHANGELOG for more details.

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

14.01.2026 23:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/knoxnl: This is a python wrapper around the amazing KNOXSS API by Brute Logic This is a python wrapper around the amazing KNOXSS API by Brute Logic - xnl-h4ck3r/knoxnl

v5.8 of knoxnl is available:

🩹BUG FIX: Wasn't pausing correctly when "service UNAVAILABLE" message from @KN0X55 API.
🩹 BUG FIX: Prevent ugly threading error when Ctrl-C pressed more than once.

github.com/xnl-h4ck3r/k...
#BugBounty
🀘

12.01.2026 22:43 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
aleister1102 - Overview The best bridge between despair and hope is a good night’s sleep πŸ›οΈ. - aleister1102

v7.5 of waymore is available:

βœ… IntelX source now works with FREE Academia tier! So if you have an academic email address, go sign up to IntelX and get your API key!
βœ… Thanks to github.com/aleister1102 for the PR

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

10.01.2026 18:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnldorker: Gather results of dorks across a number of search engines Gather results of dorks across a number of search engines - xnl-h4ck3r/xnldorker

v4.0 of xnldorker is available:

βœ… Added DuckDuckGo Lite as a source (it can give different results)
βœ… Better captcha detection for original DuckDuckGo source aswell as Lite
⚠️ Both DuckDuckGo sources only work with --show-browser option

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

08.01.2026 21:11 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/GAP-Burp-Extension: Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist - xnl-h4ck3r/GAP-Burp-Extension

v6.3 of GAP Burp Extension is available:

βœ… A small improvement to the link finding regex
βœ… Some small performance improvements
βœ… A change to prevent possible memory leaks

github.com/xnl-h4ck3r/G...
#BugBounty
🀘

08.01.2026 19:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.18 of xnLinkFinder is here:

βœ… Add arg -mrs/--max-response-size to configure max resp. size (default 100 MB). Any larger is skipped
βœ… Better performance time, lazy loading heavy imports
🩹 BUG FIX: Stop freezing on large binary files

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

08.01.2026 17:27 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.16 of xnLinkFinder is available:

βœ… Get readable version of HTML content with BeautifulSoup to search for links too. It decodes a lot of content
βœ… Add arg -ro / --readable-only to only search human readable text from HTML response/files

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

07.01.2026 17:15 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.15 of xnLinkFinder is here:

βœ… Added OCR fallback for PDFs if text cant be extracted. Ensure you apt install ocrmypdf
βœ… Added PDF extraction for files, not just URL response
🩹 BUG FIX: Ctrl-C wasn't always working
βœ… See CHANGELOG

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

07.01.2026 00:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.14 of xnLinkFinder is available:

βœ… Add support to recognise PDF responses & convert it to the text later before extracting links and params
βœ… Run `sudo apt install poppler-utils` to use pdftotext instead of python pypdf. It's better

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

06.01.2026 19:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.13 of xnLinkFinder is available:

🩹 BUG FIX: The --depth processing wasn't working correctly (not sure since when)
βœ… Implement Keep-Alive to slightly speed up
🩹 See CHANGELOG for other bug fixes

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

06.01.2026 17:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnldorker: Gather results of dorks across a number of search engines Gather results of dorks across a number of search engines - xnl-h4ck3r/xnldorker

v3.4 of xnldorker is available:

βœ… When processing file of dorks as input, results are now written to output file after each dork, rather than only at the end. Also if -ow is passed, only overwrite output on first dork of input file

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

06.01.2026 12:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnldorker: Gather results of dorks across a number of search engines Gather results of dorks across a number of search engines - xnl-h4ck3r/xnldorker

v3.3 of xnldorker is available:

🩹 BUG FIX: Add --resubmit-without-subs to README args list. No idea why it was missing all this time!
🩹 BUG FIX: A few fixes to information shown when using --forward-proxy and --resubmit-without-subs

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

05.01.2026 23:45 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.12 of xnLinkFinder is available:

βœ… Add arg --heap: Take a heap snapshot of visited URLs & extract links from browser memory. This can take longer but could discover dynamically generated links that standard static analysis might miss

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

03.01.2026 00:28 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.11 of xnLinkFinder is available:

🩹 BUG FIX: Sorry, I broke it in v7.10. I may have said this before, but don't try and code under the influence and release code at Christmas kids! :/

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

30.12.2025 20:51 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnldorker: Gather results of dorks across a number of search engines Gather results of dorks across a number of search engines - xnl-h4ck3r/xnldorker

v3.2 of xnldorker is available:

βœ… Add new Google Custom Search source. Thanks to @pdstat.bsky.social for the idea, and code I could copy! πŸ™‚
βœ… Added GOOGLE_SEARCH_API_KEY & GOOGLE_SEARCH_CHAT_ID to the config.yml file
βœ… See README for instructions

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

29.12.2025 20:08 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! - xnl-h4ck3r/waymore

v7.4 of waymore is available:

🩹 BUG FIX: The source specific totals were showing as 0 when running "-mode U" and the "ERROR processIntelxUrl 1: name 'linksFoundIntelx' is not defined" was being shown. Sorry! This is fixed now :)

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

28.12.2025 20:24 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/waymore: Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X! - xnl-h4ck3r/waymore

v7.3 of waymore is available:

βœ… Add arg -nt / --notify-telegram to send a notification to Telegram when waymore is complete.
βœ… Add TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID to config.yml file to send notification to.

github.com/xnl-h4ck3r/w...
#BugBounty
🀘

27.12.2025 16:13 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/xnldorker: Gather results of dorks across a number of search engines Gather results of dorks across a number of search engines - xnl-h4ck3r/xnldorker

v3.0 of xnldorker is available:

βœ… Add Kagi search engine as a source. Kagi is a premium, ad-free search engine that focuses on privacy and quality results
βœ… Added config.yml to provide your Kagi Session Link

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

20.12.2025 23:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.9 of xnLinkFinder is available:

βœ… Replaced the crude rule-based function with the "inflect" library for significantly more accurate singular/plural word variations in wordlist generation
βœ… Reduced the regex timeout to 30 seconds

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

17.12.2025 21:25 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
GitHub - xnl-h4ck3r/GAP-Burp-Extension: Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist - xnl-h4ck3r/GAP-Burp-Extension

v6.1 of GAP Burp Extension is available:

βœ… Correctly get links/domains containing unicode like Γ€ or %C3%A
βœ… Improved regex statements to avoid catastrophic backtracking, replacing all unbounded quantifiers
βœ… See CHANGLOG for more info

github.com/xnl-h4ck3r/G...
#BugBounty
🀘

16.12.2025 01:05 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.8 of xnLinKFinder is available:

βœ… You can now pass a .har (HTTP Archive) file as input. These can be generated from most browsers, and ZAP proxy can also export as a HAR file.

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

15.12.2025 21:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - xnl-h4ck3r/xnLinkFinder: A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target - xnl-h4ck3r/xnLinkFinder

v7.7 of xnLinkFinder is available:

βœ… When passing a proxy file as input, Requests will also be searched aswell as Responses
🩹 When passing Caido file, the first record was not checked for links and params
βœ… See CHANGLOG for more

github.com/xnl-h4ck3r/x...
#BugBounty
🀘

15.12.2025 01:29 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0