Posts
All the articles I've posted.
-
Reveal Hidden risks using Securityhub
Walkthrough of exploring AWS securityhub and a simulation activity to identify an issue that lead to some interesting findings
-
Solving Intigriti's May 2024 XSS Challenge — PhpSpreadsheet Formula Injection to XSS
A detailed walkthrough of how I solved Intigriti's May 2024 XSS challenge by exploiting a 2nd-order formula injection vulnerability in PhpSpreadsheet's calculateFormula() to achieve Cross-Site Scripting
-
Hacking Porn and Dating Sites - A Theme-Based Bug Bounty Approach
An Individual research on bugbounty programs that I took an unique approach on choosing porn industry based programs which paid me pretty much..
-
Solving Intigriti's April 2024 XSS Challenge — postMessage, Race Conditions, and a Sneaky iframe Sandbox
A walkthrough of how I solved Intigriti's April 2024 monthly XSS challenge — hardcoded creds in the DOM, an iframe sandbox misconfiguration, and a postMessage handler with no origin check that turned into a clean XSS
-
Breach in the Cloud - Cloudtrial challenge
This is a challenge from pwnedlabs where I've been provided with the cloudtrial logs and from there I've to do log analysis and trying to reproduce the attack from the attacker perspective
-
SSRF to Pwned
Lab from pwnedlabs where we have provided with a webserver and we are gonna look into how we can leverage it to SSRF
-
Big IAM Challenge - Wiz CTF Challenge
IAM Challenge from Wiz where we will be given an IAM rules and need to identify misconfiguration and exploit it to get a flag
-
A story of Default wordlist in Dirsearch to 20k INR Bounty
My First Bug in my bugbounty journey where I took an approach of guy who solves the CTF... Unfortunately it worked and I found some sensitive files which lead to a bounty