Rafa Sec
483 subscribers
85 photos
2 videos
14 files
28 links
Hey I'm Rafu ๐Ÿ‘‹

Cybersec enthusiast | bughunter | Ethical hacker | CTF player
Feel free to join๐Ÿ˜Š

- Join chat: @rafasec_chat

- join course channel: @Rafa_course
Download Telegram
๐Ÿ˜



@rafa_sec
@rafasec_chat -> join chat
@rafa_course -> join course channel
๐Ÿ˜6๐Ÿ˜Ž2
แАแŒˆแˆญ แŒแŠ• แŠฅแŠ› แŠ€แŒขแŠ แ‰ฐแŠžแ‰ฝ แˆณแˆˆแŠ• แŠญแˆญแˆตแ‰ถแˆต แˆตแˆˆ แŠฅแŠ› แˆžแ‰ฐแค แ‹ญแˆ…แˆ แŠฅแŒแ‹šแŠ แ‰ฅแˆ”แˆญ แˆˆแŠฅแŠ› แ‹ซแˆˆแ‹แŠ• แ‹จแˆซแˆฑแŠ• แแ‰…แˆญ แ‹ซแˆณแ‹ซแˆแข

แˆฎแˆœ 5:8

แˆ˜
แˆแŠซแˆ แ‰ แŠ แˆ๐Ÿ™โค๏ธ

@rafa_sec
๐Ÿ™10๐Ÿ‘2๐Ÿ˜1
This media is not supported in your browser
VIEW IN TELEGRAM
โค๏ธ

I was thinking about you ๐Ÿง

@rafa_sec
@rafasec_chat -> join chat
@rafa_course -> join course channel
โค4๐Ÿ”ฅ3
Something is comming! ๐Ÿ‘€ Can you guess what we're preparing? Share your predictions in the group! @rafasec_chat ๐Ÿคซ


@rafa_sec
@rafasec_chat -> join chat
@rafa_course -> join course channel
๐Ÿ‘1๐Ÿ‘€1
๐Ÿ˜

@rafa_sec
@rafasec_chat -> join chat
@rafa_course -> join course channel
๐Ÿ˜5
199๐Ÿ˜ณ

Sudo apt install 1 member ๐Ÿ˜
๐Ÿ˜9
This media is not supported in your browser
VIEW IN TELEGRAM
โค3๐Ÿ‘3
Rafa Sec
Something is comming! ๐Ÿ‘€ Can you guess what we're preparing? Share your predictions in the group! @rafasec_chat ๐Ÿคซ @rafa_sec @rafasec_chat -> join chat @rafa_course -> join course channel
We said it beforeโ€ฆ and now itโ€™s LIVE!
Weโ€™ve launched our own CTF website!
๐Ÿง  Solve real hacking challenges
โš”๏ธ Sharpen your skills
๐Ÿ•ต๏ธโ€โ™‚๏ธ Learn and level up your game

Try it now: http://rafasecctf.rf.gd/

Join the movement:
๐Ÿ”— @rafa_sec โ€“ Main Channel
๐Ÿ‘ฅ @rafasec_chat โ€“ Chat Group
๐Ÿ“š @rafa_course โ€“ Course Channel

Let the hacking begin!


If you want to help me in ui/css contact me: @Rafa_support
๐Ÿ”ฅ3๐Ÿ†’2
Rafa Sec
We said it beforeโ€ฆ and now itโ€™s LIVE! Weโ€™ve launched our own CTF website! ๐Ÿง  Solve real hacking challenges โš”๏ธ Sharpen your skills ๐Ÿ•ต๏ธโ€โ™‚๏ธ Learn and level up your game Try it now: http://rafasecctf.rf.gd/ Join the movement: ๐Ÿ”— @rafa_sec โ€“ Main Channel ๐Ÿ‘ฅ @rafasec_chatโ€ฆ
RafaCTF โ€“ Web CTF Lab (Free & Online)
Hey hackers!
Iโ€™ve launched RafaCTF, a custom Capture The Flag (CTF) lab where you can practice real-world web vulnerabilities across 4 difficulty levels โ€” from Easy to Insane!

Whatโ€™s Inside?
๐Ÿ›ก๏ธ 7 Vulnerability Categories:

1. โš”๏ธ XSS (Cross-Site Scripting)


2. โฑ๏ธ Rate Limit Bypass


3. ๐Ÿ” Brute Force


4. โœ๏ธ Content Injection


5. ๐Ÿงฉ HTML Injection


6. โš™๏ธ JavaScript Injection


7. ๐Ÿ•ต๏ธ XSSI (Cross-Site Script Inclusion)



Features:
โœ… 4 difficulty levels per challenge
โœ… Hidden flag in each level
โœ… Beginner-friendly & self-hosted
โœ… Learn while hacking โ€” hands-on!

Flag Path Format:
/flags/<vuln_name>/level1.txt (โ€ฆup to level4.txt)

Try it. Hack it. Learn it.
Website: http://rafasecctf.rf.gd/

Need help or want to share your progress?

๐Ÿ’ฌ Chat: @rafasec_chat
๐Ÿ“ข Channel: @rafa_sec
๐Ÿ“š Course Updates: @rafa_course

Created by: Rafu | 2025
๐Ÿ”ฅ10
Rafa Sec
RafaCTF โ€“ Web CTF Lab (Free & Online) Hey hackers! Iโ€™ve launched RafaCTF, a custom Capture The Flag (CTF) lab where you can practice real-world web vulnerabilities across 4 difficulty levels โ€” from Easy to Insane! Whatโ€™s Inside? ๐Ÿ›ก๏ธ 7 Vulnerability Categories:โ€ฆ
Complete 3CTF (Level 3) and get access to the

- Movement, Pivoting, and Persistence course!

Submit a proof screenshot in @Rafa_support to claim your reward!

Good luck! Stay sharp!
โšก๐ŸŽฏ๐Ÿ’ป





๐Ÿ’ฌ Chat: @rafasec_chat
๐Ÿ“ข Channel: @rafa_sec
๐Ÿ“š Course Updates: @rafa_course
๐Ÿ‘2
I identified a critical security issue ๐Ÿšจ where sensitive credentials were exposed through source code ๐Ÿง‘โ€๐Ÿ’ป๐Ÿ”“ โ€” received a reward of 11,000 birr ๐Ÿ’ฐ


@rafa_sec
๐Ÿ”ฅ32โค1
We made it again! ๐Ÿ’ฅ Another 11K birr! ๐Ÿ’ธ
This all happened because of 3 things:
1๏ธโƒฃ God ๐Ÿ™
2๏ธโƒฃ My mentor Nathan ๐Ÿ‘จโ€๐Ÿซ @geeztechgroup
3๏ธโƒฃ My hard work ๐Ÿ˜‚๐Ÿ’ป



#Blessed #GrindPays #BugBountyWin


@rafa_sec
๐Ÿ‘18๐Ÿ”ฅ10
Did you guys need hacking roadmap with free resource?๐Ÿ›ฃ๏ธ
Anonymous Poll
95%
Yes๐Ÿ‘๐Ÿ”ฅ
5%
No๐Ÿ‘Ž
๐Ÿ”ฅ6โคโ€๐Ÿ”ฅ2
๐Ÿงญ Cybersecurity Roadmap By Rafu


๐Ÿ”น 1. ๐Ÿ”ฐ Fundamentals

๐Ÿ’ป Computer Basics (learn this from YouTube)

๐ŸŒ Networking _resource -> Link

๐Ÿง Linux basics _resource -> Link


๐Ÿ”น 2. ๐Ÿง  Core Cyber Skills

โš™๏ธ Scripting: Bash, Python


๐Ÿš Bash -> Link

๐Ÿ Python -> Link


๐Ÿ” Networking tools: Nmap, Wireshark


- ๐Ÿ“ก Nmap -> Link 1

Link 2


- ๐Ÿ“Š Wireshark -> Link



- ๐ŸŒ Web technologies: HTML, JS, HTTP

Resource -> Link

- ๐Ÿ” Cryptography

resource -> Link



3. ๐Ÿ›ก Ethical hacking fundamentals: system hacking, website hacking...


๐Ÿ“š Resources:

- ๐Ÿง‘โ€๐Ÿ’ป Ethical hacking video -> Link
- ๐ŸŒ Web hacking -> Link
- ๐Ÿ“– If you want a book -> Link



๐Ÿ”น 4. ๐ŸŽฏ Specializations (Choose Your Track)

- Soon



๐Ÿš€ I will share advanced courses on my course channel โ€” join it. @rafa_course




@rafa_sec
๐Ÿ”ฅ9๐Ÿ‘3โค2
Hey everyone ๐Ÿ‘‹
When I started learning bug bounty ๐Ÿž๐Ÿ’ฐ, I got a cool lab ๐Ÿงช that really helped me. Now I want to share it with you โค๏ธ and weโ€™ll do it together โ€” live ๐ŸŽฅ!

Join me every Saturday & Sunday ๐Ÿ“… in the Live Cyber Security Group ๐Ÿ›ก๏ธ or on my channel .
Itโ€™s easy, fun, and perfect for beginners ๐Ÿš€.


What do you think?
Share your idea in group: @rafasec_chat

Vote ๐Ÿ‘‡๐Ÿ‘‡

@rafa_sec
๐Ÿ”ฅ9
Regarding the live hacking lab session, which channel would you prefer: ๐Ÿค” Cyber Security or ๐Ÿš€ RafaSec?
Anonymous Poll
43%
Cyber Security Channel
57%
RafaSec
๐Ÿ”ฅ3
๐Ÿš€ eWPTv2 Course: Become a Web App Pentesting Pro! ๐Ÿš€

Ready to launch your career in web application security? This Intermediate Level course is your fast track to mastering practical pentesting skills! ๐ŸŽฏ

Course Highlights:

โ€ข Web App Security Fundamentals ๐Ÿ’ก
โ€ข Information Gathering ๐Ÿ”Ž
โ€ข Authentication & Authorization Testing ๐Ÿ”‘
โ€ข Injection Attacks ๐Ÿ’‰
โ€ข File Inclusion Vulnerabilities ๐Ÿ“„
โ€ข Server-Side Request Forgery (SSRF) ๐ŸŒ
โ€ข Web Services Security โš™๏ธ
โ€ข Practical Exploitation Techniques ๐Ÿ› 
โ€ข Hands-On Labs ๐Ÿงช
โ€ข Report Writing ๐Ÿ“

Key Benefits:

โ€ข ๐Ÿ”ฅ Hands-On Learning: Real-world scenarios and practical exercises.
โ€ข โœ… Certification Prep: Ace the eWPTv2 exam with confidence.
โ€ข ๐Ÿ“ˆ Career Advancement: Boost your skills and earning potential.
โ€ข ๐Ÿ›ก Real-World Skills: Protect web apps with cutting-edge techniques.

Join now and start your journey to becoming a Best web application penetration tester! โœจโžก๏ธ click this for course





๐Ÿ’ฌ Chat: @rafasec_chat
๐Ÿ“ข Channel: @rafa_sec
๐Ÿ“š Course Updates: @rafa_course
๐Ÿ”ฅ3โค1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”ฅ5
Hacking TIP Day1:

Tip1:

Start every recon๐Ÿ” by mapping the attack surface thoroughly. Use tools like subfinder, httpx, and nmap to discover subdomains, alive hosts, and open ports. A wide recon often reveals hidden or forgotten services that are goldmines for bugs.



Tip2:

Always check for parameter pollution by duplicating query or body parameters (e.g., ?user=admin&user=guest). Some backends may use the first, others the lastโ€”leading to unexpected behavior or even auth bypass.


Happy hacking and bug hunting! ๐Ÿž๐Ÿ”


๐Ÿ’ฌ Chat: @rafasec_chat
๐Ÿ“ข Channel: @rafa_sec
๐Ÿ“š Course Updates: @rafa_course
โค9