Brute Logic (@brutelogic) 's Twitter Profile
Brute Logic

@brutelogic

#CyberSecurity | #XSS | #WAF #bypass | #hack2learn | @RodoAssis | @KN0X55 | X55.is

ID: 84484829

linkhttps://leanpub.com/brutexss calendar_today23-10-2009 02:23:01

12,12K Tweet

62,62K Takipçi

280 Takip Edilen

Rodolfo Assis (@rodoassis) 's Twitter Profile Photo

=> Vulnerability LFR via SSRF => Scenario PHP file_get_contents() with filter_var() + FILTER_VALIDATE_URL + FILTER_FLAG_QUERY_REQUIRED => Payload file:///etc/?/../passwd

=> Vulnerability 
LFR via SSRF

=> Scenario
PHP file_get_contents() with filter_var() + FILTER_VALIDATE_URL + FILTER_FLAG_QUERY_REQUIRED

=> Payload 
file:///etc/?/../passwd
Brute Logic (@brutelogic) 's Twitter Profile Photo

Super Simple Script GET 2 POST WAFs usually got bypassed easier via POST so if you can change from GET to POST you increase your chances. Copy and save the code below as your bookmark. #bookmarklet

Brute Logic (@brutelogic) 's Twitter Profile Photo

If you are new to #BugHunting or haven't received your FIRST BOUNTY yet, this is a great help for you. Check it out. #CyberSscurity #BugBounty brutelogic.net/first-bounty

(((gamliel))) 🇮🇱 (@gamliel_infosec) 's Twitter Profile Photo

Amazing reading, this ebook helps to address the common issues that, as beginners, we face at bug bounty hunting. Definitely, it's a must to have it in order to start in bug bounties in the right way & a realistic path. Sometimes, we don't need technical guidance but wise advice.

Brute Logic (@brutelogic) 's Twitter Profile Photo

SSRF Mastery Series: Fundamentals The Complete Guide to Server-Side Request Forgery Discovery and Exploitation By Rodolfo Assis Brute Logic Check it out! #SSRF #BugBounty #PenTesting #WebAppSec brutelogic.net/ssrf-mastery-s…

KNOXSS (@kn0x55) 's Twitter Profile Photo

Before the next update with #SSRF-based #XSS, you can already use our completely free Blind XSS Service with SVG image generator. With that customized image with your unique ID in our system, you can host online or upload manually to test Blind SSRF-based scenarios. #BugBounty

Before the next update with #SSRF-based #XSS, you can already use our completely free Blind XSS Service with SVG image generator.

With that customized image with your unique ID in our system, you can host online or upload manually to test Blind SSRF-based scenarios.

#BugBounty
KNOXSS (@kn0x55) 's Twitter Profile Photo

KNOXSS v4.3.0 is out! Now with another Blind #XSS payload in a file format to catch Rendered Blind #SSRF-based scenarios Also a regular SSRF-based Reflected Remote XHTML Inclusion. Complete detection list below. knoxss.pro/?page_id=766 #BugBounty #WebAppSec #PenTesting

Rodolfo Assis (@rodoassis) 's Twitter Profile Photo

Finally, my techniques for BYPASS! 😎 Most of them can be applied to other web vulnerabilities as well. Check it out: brutelogic.net/brute-art-bypa… #XSS #Bypass #WAF #BugBounty

Finally, my techniques for BYPASS! 😎

Most of them can be applied to other web vulnerabilities as well.

Check it out: brutelogic.net/brute-art-bypa…

#XSS #Bypass #WAF #BugBounty
Brute Logic (@brutelogic) 's Twitter Profile Photo

Learn the tricks I've been using all those years to #bypass filters and WAFs out there. Although for #XSS, the principles apply to other web vulnerabilities as well. brutelogic.net/brute-art-bypa…

Brute Logic (@brutelogic) 's Twitter Profile Photo

#XSS Micro Challenge Data:Text/HTML,<p id=p>Hello</p><form onsubmit=k()><input id=i><input type=submit></form><script>k=()=>{a=document.getElementById('i').value.replace(/\(|`|&|\\|%/g,'');document.getElementById('p').innerHTML='Hello '+a}</script> Copy, paste and pop.

Brute Logic (@brutelogic) 's Twitter Profile Photo

2 Techniques for #XSS #Filter #Bypass 1⃣ Location-Based - Tag Blending <Svg OnLoad= location=textContent>JavaS<a>cript:al<a>ert(<a>1)// 2⃣ Location-Based - Template Literals <Svg OnLoad= location=`Java${/S/.source}cript:alert${"\50"}1)`> #WebAppSec brutelogic.net/brute-art-bypa…

hihackthis (@hihackthis) 's Twitter Profile Photo

Hey Brute Logic I read your SSRF Mastery Series Fundamentals ebook and thought it was wonderful! A collection of insights that guide us on a path full of positive expectations. Congratulations! 😎👍

Hey <a href="/BRuteLogic/">Brute Logic</a> 
I read your SSRF Mastery Series Fundamentals ebook and thought it was wonderful! A collection of insights that guide us on a path full of positive expectations. Congratulations! 😎👍