GET /inflictx HTTP/2
Host: standoff365.com
User-Agent: hunter/2026 (recon-first; app-model) burpsuite/pro
Accept: text/vnd.critical-bugs
HTTP/2 200 OK
X-Handle: alexander · @inflictx
X-Role: application security researcher · bug bounty hunter
X-Based: moscow, ru (gmt+3)
X-Focus: broken access control · idor / bola · cross-tenant authz
X-Auth: oauth & sso redirect_uri bypass · session/token leakage · 2fa step-up bypass · ato chains
X-Also: api data exposure (pii) · ai/llm (prompt injection · system-prompt leak) · ssrf · dom/stored xss
X-Method: recon-first · model the app before payloads · raw-http proof · strict self-triage
X-Status: huntingOffline arsenal for pentesters & bug bounty hunters, open-sourced.
payloads · click-to-build commands · GTFOBins · checklists · one search across everything. fully offline, RU/EN.



