The XSS Rat - Uncle Rat ❤️ Profile picture
Alone we survive, together we prosper. Are you with me? https://t.co/AfnDsVhqqA
Feb 5, 2023 8 tweets 1 min read
1000 FREEEEEEE 95k Bundles

Work for it :)
Tip:
64 x 4
85
45
62
32
45
64
58

KZhmWcyXvRkT5hJz9VoWdFNN4juTaHLzAMdGUoigk7LXG5irmnWm856zDhNgzAfD1Pp59zZdaGPJkHR6oBqdr6CfBAx1WYekFzgijKbhrXdQuTdgQx5VV93vDMbepRR6rarUiwdkRBXwzr55WhjL7r3s1JG5rz8VvtcWm2JWPnmCbfpg1dioo6wPjjyzJukm64K3Z2Lq mKkY5q7d6eTSkEkWbNVtUn4YwTLiPVK6tJuek3qMATtjLtJWMtMnJLcwLgvmqqpTuVF8uoywYPe48Nxfs5YL99fupeq31mkAxoMd3StM8mpdgFe55exK7xQwNdUhankChbSuFhMdfjkH6B5BRmTxVa7UGCG7BmpZEfW2M7CxRsZLN26f5MgNWjPmuRyt7TMfAq5afPYqMCCfyiKSgBxMKcBwkceuqAdNrH6zyk5dkHUxhHAdecYoooEp2cd6MMJxF9Ku8Y8BZKaxiQ5TDVJroFbk
Mar 24, 2022 14 tweets 3 min read
CSRF:
- Check if the token is present on any form it should be
- Server checks if the token length is correct
- Server checks if parameter is there
- Server accepts empty parameter
- Server accepts responds without CSRF token
- Token is not session bound JWT:
- None-signing algorithm is allowed
- Secret is leaked somewhere
- Server never checks secret
- Secret is easily guessable or brute-forceable
Jan 8, 2022 4 tweets 3 min read
My amazing hacker rats, please be kind to each other <3 Don't start "exposing" people on profiles they never hack on .. don't start wars.
I did the same and I was wrong to do so, I said sorry in a public tweet for that.

If you want to judge, I will let my students speak though 90 pages of 5 star reviews
43 Pages with 5 star reviews
9 pages with 3 star reviews
4 pages of 2 star reviews
4 pages of 1 star reviews

Over 95 000 students on udemy... I don't think I have anything to be ashamed of :3

Lastly I want to thank everyone for believing in me <3
Jan 7, 2022 4 tweets 2 min read
#bugbountytip Broad scope target:
1) Subdomain enum
2) httprobe
3) subdomain flyover
4) Nuclei (develop your own templates as well)
5) Portscan

Now pay attention
1/4
6) Write subdomains to database for later use
7) If new domain goes into db, do full nuclei scan
8) If new nuclei template, scan old domains

BAM testing <3
9) Optional, do a cronjob every 3 weeks with nuclei
(Companies release new software that might break other things)
2/4