Harshit
@geekyguyharshit
Product Security Engineer
You might like
HTTP is supposed to be stateless, but sometimes... it isn't! Some servers create invisible vulnerabilities by only validating the first request on each TCP/TLS connection. I've just published a Custom Action to help you detect & exploit this - here's a narrated demo:
Vulnerable Bank is Now Live! 🚀 I'm excited to announce that VulnBank is officially live and accessible at vulnbank.org! This project aims to make learning application security testing easier, more practical, and highly contextual for everyone.
I’m in a pwnfunction video! Check it out, it’s very well made and the vulnerability chain is quite unique youtube.com/watch?v=RLyhPG…
youtube.com
YouTube
XSS like you've never seen.
AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure. github.com/microsoft/AI-R…
Just launched CTF Search with 24k+ CTF writeups, covering everything from web exploitation to reverse engineering. Check it out! ctfsearch.hackmap.win
Drilling the redirect_uri in OAuth { by @yshahinzadeh } from @hashnode blog.voorivex.team/drilling-the-r…
DevArmor | Threat Modeling Automation: Opportunities, Challenges, and the Role of AI devarmor.com/blog/2024-08-1…
Analysis of CVE-2024-43044 — From file read to RCE in Jenkins through agents blog.convisoappsec.com/en/analysis-of…
Congratulations to @geekyguyharshit for clearing our Certified Red Team Professional exam! #ADLab #CRTP #AlteredSecurity cc @nikhil_mitt alteredsecurity.com/adlab
check out my latest research (Exploiting HTTP Parsers Inconsistencies): rafa.hashnode.dev/exploiting-htt…
"Think Outside the Scope: Advanced CORS Exploitation Techniques" #infosec #pentest #redteam infosecwriteups.com/think-outside-…
#AppSec 1. OAuth Hijacking salt.security/blog/oh-auth-a… 2. Stealing OAuth Tokens via Open Redirects eval.blog/research/micro…
Explaining 9 types of API testing. The method to download the high-resolution PDF is available at the end. 🔹 Smoke Testing This is done after API development is complete. Simply validate if the APIs are working and nothing breaks. 🔹 Functional Testing This creates a test plan…
Top 50 Vulnerabilities Leading to RCE in Public-Facing Applications redteamrecipe.com/top-50-vulnera…
Chandrayaan-3 Mission: 'India🇮🇳, I reached my destination and you too!' : Chandrayaan-3 Chandrayaan-3 has successfully soft-landed on the moon 🌖!. Congratulations, India🇮🇳! #Chandrayaan_3 #Ch3
Here's a write-up on a Browser-Powered Desync bug that I discovered in the Azure CDN service known as Front Door. The entire concept is built upon the excellent research by @albinowax. Initially identified within the @intigriti program. blog.jeti.pw/posts/knocking… #bugbounty
United States Trends
- 1. Chiefs 50.1K posts
- 2. Colts 21.5K posts
- 3. Mahomes 12K posts
- 4. Steelers 36.2K posts
- 5. Caleb 30.4K posts
- 6. Flacco 3,858 posts
- 7. Lamar 17.7K posts
- 8. #GoPackGo 3,621 posts
- 9. Jameis 9,123 posts
- 10. Drake Maye 7,418 posts
- 11. #HereWeGo 4,285 posts
- 12. DJ Moore 1,733 posts
- 13. Daniel Jones 1,867 posts
- 14. #Bears 5,277 posts
- 15. #Skol 2,105 posts
- 16. Marcus Jones 1,760 posts
- 17. Micah Parsons 1,173 posts
- 18. #OnePride 2,304 posts
- 19. Jaxon Smith 2,220 posts
- 20. Tony Romo 1,742 posts
You might like
-
Jerry
@JerryShah33 -
testnoob
@testn00b -
Miguel Santareno
@MiguelSantareno -
an0n
@an0n_r0 -
Parth Shukla
@0xParth -
Muhe
@mechboy_ -
Alam
@alamlearnN -
AbdeRaouf 🇵🇸
@abderaoufzx -
K.S.S
@0xhaxor -
Mohammad Yunus
@yunus_ahmed96 -
Ayoub
@Yukusawa18 -
Rajveer
@R4JVE3R -
naveen
@nvk0x -
Nekotish.eth
@Nekotish -
Ahsan Ali
@ahsanali7452
Something went wrong.
Something went wrong.