I'm going to explain how I found two OS command injection vulnerabilities a few days ago.
The vulnerabilities were quite easy to exploit once the injection points were identified.
Pathetic service @StarHealthIns
Their doctors are not even validating the documents provided and just keep on repeating the same blunder.
Even after submitting all the required documents they denied reimbursement.
😡Absolutely frustrated with StarHealth insurance provider! It's been nearly 2 months since I submitted my reimbursement claim, and I still haven't seen a dime.
Sent many emails as well but no satisfactory response.
Is this what we pay premiums for?
@StarHealthIns@irdaindia
🎧Wear your headsets 🌋Volume up for this one!
The flagship HackIM CTF 15th Edition is now open for you to register ➡️https://t.co/o0HsEPdpZ0
⭐Sponsored by @ChaleitG | 🧠Challenges designed by @ENOFLAG#NullconGoa2023#Infosec#Conference
From code execution to S3 data leak, my latest blog post is on the journey of discovering a bug in Meta (Facebook).
You don't want to miss this!
#infosec#hacking#pentesting
https://t.co/UkaQLHUFtL
Were you able to spot the vulnerability in yesterday's code snippet? 🕵️♂️
✅ Yes? That’s impressive!
❌ No? Don't worry. This is your chance to learn, so let's take a look at the writeup 👇
🧵 Be sure to keep reading this thread for more resources and the winner of our swag!
I wonder why some sys-admins configure the server with sudo privileges! 🤔
Tip: Always test for Expression Language Injection like OGNL when you see *.do and *.action file extensions.
#security#bugbountytip#hacking
Check out my latest blog on how I compromised a banking server by exploiting some vulnerabilities.
The journey from AFR to RCE.
I hope you'll like it. 🥂
#security#infosec#hacking
https://t.co/pxC6xjJiuI
9 Google Dorks you NEED to know about! 🧵
Google knows everything about your target. Google Dorking is using the search engine to find juicy stuff!
Here are some quick examples to show you the POWER of dorks 👇
💡How often do you revisit the past patched vulnerability?👾There could be a malicious code still hiding in plain sight!
🧠End this year on a progressive note by💻upskilling at Nullcon #OnlineTrainings
🎟️Early Bird offer is activated👉https://t.co/U82ZRoFVen
#Nullcon#Infosec
👨💻Learn #securecoding
💡Gaurav @4auvar & Mihir @m1h1rd with this training will provide a guide to make the code secure, understand the common mistakes at the code level & guard against #security#vulnerabilities
🖥️Checkout & register here➡️https://t.co/xbSqsuEpqg
#Nullcon