Made a tool to find anyone's IRL identity from their public commenting or posting history & patterns - even if they are using totally anonymous accounts.
Source: https://t.co/uiEzXdTar2
I keep building cool stuff, follow me on GitHub: https://t.co/7J3WZ1TY7T :)
We were able to get full create, read, update and delete (CRUD) access & shell access to CBSE's prod servers (as mentioned in their circular https://t.co/MFiu5xU1DF). This is disastrous. Proof archive is at https://t.co/LWWqKBOGjv.
Prod URL (might be taken down): https://t.co/gbZKz3d65V
another integral onmark subdomain has been pwn'ed, this time we managed to get super admin access of the portal. seems like it is tasked with evaluation of exams at various universities.
CBSE people didn't configure their AWS bucket properly and now we can paginate & enumerate all their media which has 2026 answersheets & question papers. ListObjectsV2 works without any auth and the bucket root is listable too — anyone on the internet can download any scanned booklet — across institutions. Multiple institutions are using the same bucket, insanely insecure.