Rezy Dev 🇳🇵

272 posts

Rezy Dev 🇳🇵 banner
Rezy Dev 🇳🇵

Rezy Dev 🇳🇵

@RezyDev

Security Researcher | HTB CPTS | Penetration Tester | Open To Work

Kathmandu, Nepal Katılım Ekim 2021
127 Takip Edilen244 Takipçiler
Sabitlenmiş Tweet
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Certified Hacker!! :D
Rezy Dev 🇳🇵 tweet mediaRezy Dev 🇳🇵 tweet media
Español
2
1
8
870
Veshraj Ghimire🇳🇵
Veshraj Ghimire🇳🇵@GhimireVeshraj·
On December 11, We reported a AWS token leaked on a public repository belonging to marriot infrastructure which had SES service with verified domain of @marriot.com on December 12 @Hacker0x01 closed the report as n/a saying github.com is explicitly out of scope:
Veshraj Ghimire🇳🇵 tweet mediaVeshraj Ghimire🇳🇵 tweet media
English
18
20
306
62.2K
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
@OreoB1scuit Very much yes. I have alot of reports pending with no reply and is killing motivation slightly.
English
0
0
2
127
Biscuit
Biscuit@OreoB1scuit·
not gonna lie but this really kills the motivation for hunting
Biscuit tweet media
English
9
1
49
3.6K
Rezy Dev 🇳🇵 retweetledi
vx-underground
vx-underground@vxunderground·
vx-underground tweet media
ZXX
31
297
3K
74.2K
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
seems like using claude opus 4.6 is becoming new flex
English
0
0
3
81
Rezy Dev 🇳🇵 retweetledi
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
542
4.1K
16.3K
12.3M
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
@AlfinCodes For a single year, GoDaddy is pretty good with their first year discounts. For long term like 10 years, Cloudflare wins easy.
Rezy Dev 🇳🇵 tweet media
English
1
0
1
55
Alfin
Alfin@AlfinCodes·
Hey devs I have $10. Which is the best place to buy a domain?
Alfin tweet mediaAlfin tweet mediaAlfin tweet mediaAlfin tweet media
English
158
8
162
24.5K
SysTrack
SysTrack@SysTrack40·
@RezyDev Painful. Sorry for your loss
GIF
English
1
0
0
239
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
@EvanKlein338226 I tried techniques like case manipulation of event handlers and null bytes. Mixing tricks made some payloads work. One simple XSS payload I found on Twitter months ago still bypasses the Cloudflare WAF. Surprisingly, it still works! Haha.
English
0
0
3
375
Evan Klein
Evan Klein@EvanKlein338226·
@RezyDev Nice find! Case manipulation bypasses are underrated. Also try event handler variations like OnMoUsEoVeR or mixing in null bytes/unicode. The fact that basic regex patterns still work against major WAFs in 2026 is wild 🔥
English
1
0
6
450
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Just found a simple Cloudflare WAF bypass 👀 <img src=x onerror=alert()> → blocked by Cloudflare <Img Src=OnXSS OnError=alert(document.domain)> → bypasses the WAF and triggers the alert. #BugBounty #BugBountyTips #WAFBypass
Rezy Dev 🇳🇵 tweet media
English
2
21
232
7.6K
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
If you haven't sent 200 modified requests, you haven't tested anything yet. #BugBounty
English
1
1
48
2.1K
🔥♣️RedApple ♨️Leroibull💯♠️
@RezyDev @hackinghub_io Hi @RezyDev, thank you for the challenge. I don't have much experience but I have tried almost everything I know and it is not working. I know there is a discrepancy between the registration and the account verification process but all my attempts to bypass it is not working😢
English
1
0
1
41