home ▶ View Live Dashboard docs use cases api pricing contact
pingback.sh pro · pay-to-play

Pay once.
Hunt all year.

PingBack.sh is built for serious bug bounty hunters and security researchers. No free tier, no endless trials, no feature gating. Just professional-grade out-of-band infrastructure for those who invest in their craft. You pay, you hunt, you keep what you find.

Crypto only Key in hours Share it freely Cancel = just don't renew
$59 / year
Less than $5/month cheaper than a Big Mac🍔🍟
  • Unlimited listeners & hits
  • Callback intelligence + reverse DNS /24
  • Email · Discord · Telegram alerts
  • Weaponized SVG/PNG/PDF/XXE payloads
  • Full SMTP bodies, export & H1 reports
  • Full API access
Pay in crypto, submit your TXID, key emailed to you.
₿ BTCΞ ETH₮ USDT
pingback.sh/dashboard?t=•••••
listener
a4f9c1b2.pingback.sh
stats
total hits147
unique IPs23
HTTP98
DNS31
Blind XSS12
SMTP6
XSScookies captured· 2s ago · 41.92.x.x 🇿🇦
document.cookie: session=eyJ0eXAiOiJKV1Qi… — httponly bypass
HTTPGET /internal/admin· 1m ago · 10.0.x.x
SSRF confirmed — rDNS: ip-10-0-3-44.ec2.internal (AWS)
DNSA query· 3m ago · 8.8.8.8
x.a4f9c1b2.pingback.sh — blind SSTI via {{7*7}}
SMTPmail received· 8m ago
From: noreply@target.com · Subject: Password reset · full body unlocked

Everything you need to confirm the finding

Every OOB channel

HTTP/S, DNS, SMTP and Blind XSS in one listener. One subdomain catches them all, in real time.

Callback intelligence

Forward-confirmed reverse DNS, RDAP/ASN org, cloud detection and a full /24 reverse map via HackerTarget.

Instant alerts

Get pinged the second your payload fires — Email, Discord and Telegram. Never miss a delayed XSS again.

Weaponized payloads

Ready-to-use SVG, PNG, GIF, PDF and XXE files pre-targeted to your listener. Drop and catch.

Full SMTP bodies

Read the entire captured email — headers and body — to prove account-takeover and SSRF-to-SMTP chains.

Export for reports

One-click JSON/CSV export and auto-generated HackerOne-ready reports straight from any hit.

pingback.sh is pay-to-play. Built for bug hunters who respect the craft and pay for their gear — not for leeches. No free tier, no trial. You pay, you hunt, you keep what you find.