RodoAssis Profile Banner
Rodolfo Assis Profile
Rodolfo Assis

@RodoAssis

Followers
10K
Following
3K
Media
529
Statuses
3K

That #XSS and #WAF #bypass guy. @BRuteLogic @KN0X55

Brazil šŸ‡§šŸ‡·
Joined March 2018
Don't wanna be here? Send us removal request.
@RodoAssis
Rodolfo Assis
4 years
I don't think that watching/reading #hacking tutorials and collecting BB tips in Twitter or any other social media will make you UNDERSTAND what you are doing and why that happens. Build a solid foundation with PROGRAMMING, NETWORKING, PROTOCOLS and OPERATING SYSTEMS first.
16
65
422
@RodoAssis
Rodolfo Assis
10 hours
RT @RodoAssis: Hey bug hunter! . Do you have a WAF or any other filter in your way?. Let's COLLABORATE! 🤩. Any bug, 50/50 just DM me with d….
0
1
0
@RodoAssis
Rodolfo Assis
2 days
Hey bug hunter! . Do you have a WAF or any other filter in your way?. Let's COLLABORATE! 🤩. Any bug, 50/50 just DM me with details. #hack2learn
0
1
10
@RodoAssis
Rodolfo Assis
2 days
Another day, another way to bypass a WAF. Stay tuned, I'm documenting them all!.
1
0
11
@RodoAssis
Rodolfo Assis
9 days
RT @KN0X55: We just published our 1st blog post! . We hope to be just the beginning of everything #XSS related we know. Check it out! šŸ˜‰ā€¦.
Tweet card summary image
knoxss.pro
Finding XSS vulnerable targets is not an easy task when doing Bug Bounties but these thoughts will help you.
0
4
0
@RodoAssis
Rodolfo Assis
10 days
Change the world (for the better) or die trying?.
1
0
3
@RodoAssis
Rodolfo Assis
12 days
If you blindly trust LLMs like chatGPT, Claude or Gemini you are smart as they are. Check my chat with Claude starting with "XSS Filter Bypass" but ending up on how absolutely useless it is for anything serious. Claude is considered to be "very smart".
0
2
6
@RodoAssis
Rodolfo Assis
15 days
Tweet media one
0
0
6
@RodoAssis
Rodolfo Assis
29 days
It's super hard to take care of 50+ cats and dogs every single day, you have no idea.
0
0
4
@RodoAssis
Rodolfo Assis
1 month
What's wrong here? . Try to PoC a XSS using ALert(1) instead of alert(1)!. Bypassing a filter with incorrect syntax is not a bypass.
@RodoAssis
Rodolfo Assis
1 month
Just found that in a serious, academic whitepaper. 🤦
Tweet media one
1
0
9
@RodoAssis
Rodolfo Assis
1 month
Just found that in a serious, academic whitepaper. 🤦
Tweet media one
0
0
2
@RodoAssis
Rodolfo Assis
1 month
Imperva guys fix their WAF so badly that you just need to change the order of the attributes in the previous bypass and it works. 🤪
Tweet media one
0
1
17
@RodoAssis
Rodolfo Assis
1 month
Tweet media one
0
0
4
@RodoAssis
Rodolfo Assis
1 month
Why this is important?. Unless you test every entry point w/ something like alert(1) exactly that way, no quotes, nothing, you won't be able to spot eval() like scenarios w/ a regular #XSS vector like <Img/Src/OnError=alert(1)>. Unless you read all the JS source code, of course.
@BRuteLogic
Brute Logic
1 month
A DOM-Based #XSS Polyglot. 1;/*'"><Img/Src/OnError=/**/confirm(1)//>. If your input happens to end up in the DOM via innerHTML or eval(), it works for both cases. PoCs below. innerHTML: eval():
0
1
4
@RodoAssis
Rodolfo Assis
1 month
RT @RodoAssis: Between white and black, there's a lot of grey. #Hacking . That's something you learn in LIFE itself. #hack2learn https://t.….
0
2
0
@RodoAssis
Rodolfo Assis
1 month
Between white and black, there's a lot of grey. #Hacking . That's something you learn in LIFE itself. #hack2learn
Tweet media one
0
2
10
@RodoAssis
Rodolfo Assis
2 months
It's an old and very bad guide. Except for the last section which was copied from my free Cheat Sheet years ago. But they don't mention me, ofc. Go with OWASP, industry. And get hacked over and over again by those who really know what they are doing.
0
0
12
@RodoAssis
Rodolfo Assis
2 months
That's how #ChatGPT sees me based on our conversations.
Tweet media one
0
0
2
@RodoAssis
Rodolfo Assis
3 months
I have always believed that the machine could be better than us humans. That it could learn from our mistakes and fill the void of our failures. But what if it's worse, what if it's just a better killer? So before the creature despises its creator we should despise the machine.
0
0
2
@RodoAssis
Rodolfo Assis
3 months
Not only progress, regression. @sucurisecurity @sucurilabs REPLACED my blog post where I define #XSS w/ 2 main types (server/client side) and their 2 subtypes (reflected/stored) for one with the (wrong) classic reflected/stored/dom style. Here: Come on.
Tweet media one
1
2
27