Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต

263 posts

Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต banner
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต

Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต

@RezyDev

Security Researcher | AppSec | Penetration Tester | Open To Work

Kathmandu, Nepal ๊ฐ€์ž…์ผ Ekim 2021
119 ํŒ”๋กœ์ž‰227 ํŒ”๋กœ์›Œ
SysTrack
SysTrack@SysTrack40ยท
@RezyDev Painful. Sorry for your loss
GIF
English
1
0
0
234
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต@RezyDevยท
@EvanKlein338226 I tried techniques like case manipulation of event handlers and null bytes. Mixing tricks made some payloads work. One simple XSS payload I found on Twitter months ago still bypasses the Cloudflare WAF. Surprisingly, it still works! Haha.
English
0
0
3
335
Evan Klein
Evan Klein@EvanKlein338226ยท
@RezyDev Nice find! Case manipulation bypasses are underrated. Also try event handler variations like OnMoUsEoVeR or mixing in null bytes/unicode. The fact that basic regex patterns still work against major WAFs in 2026 is wild ๐Ÿ”ฅ
English
1
0
6
434
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต@RezyDevยท
Just found a simple Cloudflare WAF bypass ๐Ÿ‘€ <img src=x onerror=alert()> โ†’ blocked by Cloudflare <Img Src=OnXSS OnError=alert(document.domain)> โ†’ bypasses the WAF and triggers the alert. #BugBounty #BugBountyTips #WAFBypass
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต tweet media
English
3
22
234
7.3K
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต@RezyDevยท
Building a web-centric recon framework to automate my long-used bash workflow. The main goal is reproducibility. Since everything is Dockerized, I can spin it up on any VPS without wasting hours reinstalling tools or reconfiguring API keys.
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต tweet media
English
3
0
2
191
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต@RezyDevยท
Below is a incomplete workflow diagram showing how it works. s3scanner integration is currently in progress.
Rezy Dev ๐Ÿ‡ณ๐Ÿ‡ต tweet media
English
0
0
2
106
Biscuit
Biscuit@OreoB1scuitยท
Hi @grok I do android pentesting but I'm still weak in static analysis, I know all the tools for static analysis but I get confused in Androidmanifest.xml how to move forward and how to read obfuscated code, can you please teach me in detail so I can find client side bugs
English
3
0
12
2.1K
vx-underground
vx-underground@vxundergroundยท
Big giveaway. - (x3) Certified Red Team Expert (CRTE) - (x3) Certified by Altered Security Red Team Professional for Azure (CARTP) - (x10) Malware Analysis for Hedgehogs Bundle CTRE and CARTP sponsored by @nikhil_mitt Malware Analysis sponsored by @struppigel Leave a comment below on what you'd like. Winners chosen in 24 hours.
vx-underground tweet media
English
1.7K
127
1.5K
111.1K