Amal Mohandas
@amalmohandas0
Security Engineer
You might like
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning. github.com/PhonePe/mantis
🔥 OAuth "token reuse" vulnerability An interesting OAuth attack technique by @AviadCarmel that reused OAuth tokens from a different app to fully takeover victim's account in many popular apps like Grammarly salt.security/blog/oh-auth-a… #bugbountytips #bugbounty #cybersecurity
At @assetnote, we found impactful vulnerabilities in static site generators and associated platforms (Netlify, GatsbyJS Cloud). You can read about our findings here: blog.assetnote.io/2022/10/28/exp… working with @samwcyo on this, has also been a pleasure.
assetnote.io
Exploiting Static Site Generators: When Static Is Not Actually Static
Exploiting Static Site Generators: When Static Is Not Actually Static
Slides from the talk "An attacker’s guide to AWS Access Keys" that I have delivered a while ago. Covers various techniques, tools using which attackers can gain access to #AWS Access Keys (Security Creds) #AppSec #CloudSec speakerdeck.com/0xbharath/an-a…
Here are the slides from our (@mast3root and I) talk on #Frida for Mobile app security testing at #THREATCON2022 This is a breadth first talk on Frida's capabilities on Android/iOS. frida-unleashed.netlify.app PDF at speakerdeck.com/0xbharath/frid…
We at @PhonePe (Appsec team) are hiring Security Engineers (App-Mobile-Cloud-sec/DevSecOps/Payments) I can share the job description but it doesn't do justice in explaining the opportunity so reach out to me if you are interested to know more! #infosec #appsec #cloudsecurity
Our bug bounty program is 10 yrs old now, rewarded nearly 30M dollars for over 2000 researchers, launching new program at bughunters.google.com. Thanks for all your contributions and happy bug hunting! security.googleblog.com/2021/07/a-new-…
Added a new blog post on how I developed a proof of concept exploit for the Jira DC RCE (CVE-2020-36239), including what I did wrong along the way :) dozer.nz/posts/CVE-2020…
It's an honor to get the nomination for the #BHUSA @PwnieAwards Best Server-Side Bug again!!! pwnies.com/microsoft-exch…
Linux LPE exploit for CVE-2021-3490: Tested on Ubuntu 20.10 (Groovy Gorilla) kernels 5.8.0-25.26 through 5.8.0-52.58. and Ubuntu 21.04 (Hirsute Hippo) 5.11.0-16.17. github.com/chompie1337/Li…
Blog's up! "Firebase Cloud Messaging Service Takeover: A small research that led to 30k$+ in bounties" #GoogleVRP writeup included that relays how business rep & every user of Hangouts,Google Play Music, YouTube Go etc were affected! abss.me/posts/fcm-take… #bugbounty #infosec
YEEEET! When you find that final bug to chain:
How do you stop a hacker? Make them do project management! :) ;(
When you are one of the four researchers. Thanks @JarekMsft for the recognition #msrc #microsoft @msftsecurity
Its finally in my hand. Thanks for the amazing swag @msftsecurity. It means a lot to me, loved it. :) #msrc #top100 #2018
Finally belated swag... Top 100 Microsoft security researcher 2018. Thanks a lot. #microsoft #bugbounty #blackhat
United States Trends
- 1. GTA 6 8,551 posts
- 2. GTA VI 14.3K posts
- 3. Rockstar 42.7K posts
- 4. #LOUDERTHANEVER 1,492 posts
- 5. GTA 5 6,740 posts
- 6. Nancy Pelosi 112K posts
- 7. Rockies 3,609 posts
- 8. Paul DePodesta 1,683 posts
- 9. Antonio Brown 3,026 posts
- 10. Ozempic 15.2K posts
- 11. Grand Theft Auto VI 34.2K posts
- 12. GTA 7 N/A
- 13. Justin Dean N/A
- 14. Elon Musk 220K posts
- 15. $TSLA 53.7K posts
- 16. Luke Fickell N/A
- 17. RFK Jr 26.5K posts
- 18. Michael Jackson 88.1K posts
- 19. Jonah Hill 1,435 posts
- 20. Oval Office 39.1K posts
You might like
-
streaak
@streaak -
Parth Malhotra
@Parth_Malhotra -
nikhil(niks)
@niksthehacker -
John
@JohnH4X00R -
Prasoon Gupta
@0xdekster -
Akshay Sharma 🇮🇳
@akshaysharma71 -
Aman Mahendra
@amanmahendra_ -
Abhinav
@abhinav_one -
Ahmed Alwardani
@AlwardaniAa -
Shubham Patel
@Shubham_4500 -
Jerry
@JerryShah33 -
Abhishek Karle
@AbhishekKarle3 -
dark_warlord14
@dark_warlord14 -
Coding_Karma
@karma_coded -
Mashoud
@mashoud1122
Something went wrong.
Something went wrong.