PingBack.sh is built for serious bug bounty hunters and security researchers. No free tier, no endless trials, no feature gating. Just professional out-of-band infrastructure for people who invest in their craft — a single key, 30 days of unlimited hunting. One callback can pay for years of access.
Send $39 in BTC, ETH or USDT — or pay with PayPal. No account or card details shared with us.
Paste your transaction hash (or PayPal name) and a contact. We match it — usually confirmed within a few hours.
Your key lands in your inbox and unlocks everything for 30 days. Every listener keeps its captures for 90 days from its creation — your evidence stays put even after the key expires. Want to keep hunting? Just grab a new key.
HTTP/S, DNS, SMTP and Blind XSS in one listener. One subdomain catches them all, in real time.
Forward-confirmed reverse DNS, RDAP/ASN org, cloud detection and a full /24 reverse map via HackerTarget.
Get pinged the second your payload fires — Email, Discord and Telegram. Never miss a delayed XSS again.
Ready-to-use SVG, PNG, GIF, PDF and XXE files pre-targeted to your listener. Drop and catch.
Read the entire captured email — headers and body — to prove account-takeover and SSRF-to-SMTP chains.
One-click JSON/CSV export and auto-generated HackerOne-ready reports straight from any hit.
pingback.sh is built for serious hunters who need reliable out-of-band infrastructure. No free tier, no trial, no noisy limits. Pay for a month, hunt without limits, and keep what you find. No subscription traps — when your 30 days are up, you decide whether to come back.
Self-hosted · dedicated server · custom domain · unlimited seats & testers · priority support. Delivered within 48h of payment confirmation.
Send $39 / 30 days, then tell us your payment reference so we can confirm it. Your 30-day key is emailed to you, usually within a few hours.
Please send as Friends & Family if you can — that way the full amount reaches us and your key isn't delayed. Add your contact below so we can match the payment and send your key.
For security teams running pingback at scale. A private, self-hosted deployment provisioned for your organization. Delivered within 48h of payment confirmation.