geekyguyharshit's profile picture. Product Security Engineer

Harshit

@geekyguyharshit

Product Security Engineer

Harshit reposted

HTTP is supposed to be stateless, but sometimes... it isn't! Some servers create invisible vulnerabilities by only validating the first request on each TCP/TLS connection. I've just published a Custom Action to help you detect & exploit this - here's a narrated demo:


Harshit reposted

Vulnerable Bank is Now Live! 🚀 I'm excited to announce that VulnBank is officially live and accessible at vulnbank.org! This project aims to make learning application security testing easier, more practical, and highly contextual for everyone.


Harshit reposted

I’m in a pwnfunction video! Check it out, it’s very well made and the vulnerability chain is quite unique youtube.com/watch?v=RLyhPG…

MtnBer's tweet card. XSS like you've never seen.

youtube.com

YouTube

XSS like you've never seen.


Harshit reposted

AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure. github.com/microsoft/AI-R…


Harshit reposted

Just launched CTF Search with 24k+ CTF writeups, covering everything from web exploitation to reverse engineering. Check it out! ctfsearch.hackmap.win

sarperavci's tweet image. Just launched CTF Search with 24k+ CTF writeups, covering everything from web exploitation to reverse engineering. Check it out!

ctfsearch.hackmap.win

Harshit reposted

DevArmor | Threat Modeling Automation: Opportunities, Challenges, and the Role of AI devarmor.com/blog/2024-08-1…


Harshit reposted

Congratulations to @geekyguyharshit for clearing our Certified Red Team Professional exam! #ADLab #CRTP #AlteredSecurity cc @nikhil_mitt alteredsecurity.com/adlab

AlteredSecurity's tweet image. Congratulations to @geekyguyharshit  for clearing our Certified Red Team Professional exam!
#ADLab #CRTP #AlteredSecurity cc @nikhil_mitt 

alteredsecurity.com/adlab

Harshit reposted

check out my latest research (Exploiting HTTP Parsers Inconsistencies): rafa.hashnode.dev/exploiting-htt…


Harshit reposted

"Think Outside the Scope: Advanced CORS Exploitation Techniques" #infosec #pentest #redteam infosecwriteups.com/think-outside-…

CyberWarship's tweet image. "Think Outside the Scope: Advanced CORS Exploitation Techniques"

#infosec #pentest #redteam 
 infosecwriteups.com/think-outside-…

Harshit reposted

#AppSec 1. OAuth Hijacking salt.security/blog/oh-auth-a… 2. Stealing OAuth Tokens via Open Redirects eval.blog/research/micro…


Harshit reposted

Explaining 9 types of API testing. The method to download the high-resolution PDF is available at the end. 🔹 Smoke Testing This is done after API development is complete. Simply validate if the APIs are working and nothing breaks. 🔹 Functional Testing This creates a test plan…


Harshit reposted

Top 50 Vulnerabilities Leading to RCE in Public-Facing Applications redteamrecipe.com/top-50-vulnera…


Harshit reposted

Chandrayaan-3 Mission: 'India🇮🇳, I reached my destination and you too!' : Chandrayaan-3 Chandrayaan-3 has successfully soft-landed on the moon 🌖!. Congratulations, India🇮🇳! #Chandrayaan_3 #Ch3


Harshit reposted

Here's a write-up on a Browser-Powered Desync bug that I discovered in the Azure CDN service known as Front Door. The entire concept is built upon the excellent research by @albinowax. Initially identified within the @intigriti program. blog.jeti.pw/posts/knocking… #bugbounty


Loading...

Something went wrong.


Something went wrong.