Rezy Dev 🇳🇵

263 posts

Rezy Dev 🇳🇵 banner
Rezy Dev 🇳🇵

Rezy Dev 🇳🇵

@RezyDev

Security Researcher | AppSec | Penetration Tester | Open To Work

Kathmandu, Nepal Entrou em Ekim 2021
119 Seguindo232 Seguidores
Tweet fixado
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Certified Hacker!! :D
Rezy Dev 🇳🇵 tweet mediaRezy Dev 🇳🇵 tweet media
Español
2
1
8
777
SysTrack
SysTrack@SysTrack40·
@RezyDev Painful. Sorry for your loss
GIF
English
1
0
0
235
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
@EvanKlein338226 I tried techniques like case manipulation of event handlers and null bytes. Mixing tricks made some payloads work. One simple XSS payload I found on Twitter months ago still bypasses the Cloudflare WAF. Surprisingly, it still works! Haha.
English
0
0
3
335
Evan Klein
Evan Klein@EvanKlein338226·
@RezyDev Nice find! Case manipulation bypasses are underrated. Also try event handler variations like OnMoUsEoVeR or mixing in null bytes/unicode. The fact that basic regex patterns still work against major WAFs in 2026 is wild 🔥
English
1
0
6
434
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Just found a simple Cloudflare WAF bypass 👀 <img src=x onerror=alert()> → blocked by Cloudflare <Img Src=OnXSS OnError=alert(document.domain)> → bypasses the WAF and triggers the alert. #BugBounty #BugBountyTips #WAFBypass
Rezy Dev 🇳🇵 tweet media
English
3
22
234
7.3K
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
If you haven't sent 200 modified requests, you haven't tested anything yet. #BugBounty
English
1
1
49
2.1K
🔥♣️RedApple ♨️Leroibull💯♠️
@RezyDev @hackinghub_io Hi @RezyDev, thank you for the challenge. I don't have much experience but I have tried almost everything I know and it is not working. I know there is a discrepancy between the registration and the account verification process but all my attempts to bypass it is not working😢
English
1
0
1
37
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Quick tools currently just has wafw00f.
Rezy Dev 🇳🇵 tweet media
English
0
0
3
144
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Building a web-centric recon framework to automate my long-used bash workflow. The main goal is reproducibility. Since everything is Dockerized, I can spin it up on any VPS without wasting hours reinstalling tools or reconfiguring API keys.
Rezy Dev 🇳🇵 tweet media
English
3
0
2
192
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Also, discord notification is also a by-default feature.
Rezy Dev 🇳🇵 tweet media
English
0
0
2
129
Rezy Dev 🇳🇵
Rezy Dev 🇳🇵@RezyDev·
Below is a incomplete workflow diagram showing how it works. s3scanner integration is currently in progress.
Rezy Dev 🇳🇵 tweet media
English
0
0
2
106
Biscuit
Biscuit@OreoB1scuit·
Hi @grok I do android pentesting but I'm still weak in static analysis, I know all the tools for static analysis but I get confused in Androidmanifest.xml how to move forward and how to read obfuscated code, can you please teach me in detail so I can find client side bugs
English
3
0
12
2.1K
vx-underground
vx-underground@vxunderground·
Big giveaway. - (x3) Certified Red Team Expert (CRTE) - (x3) Certified by Altered Security Red Team Professional for Azure (CARTP) - (x10) Malware Analysis for Hedgehogs Bundle CTRE and CARTP sponsored by @nikhil_mitt Malware Analysis sponsored by @struppigel Leave a comment below on what you'd like. Winners chosen in 24 hours.
vx-underground tweet media
English
1.7K
127
1.5K
111.1K