CVE-2022-36804: Bitbucket Server was vulnerable with Remote Code Execution (RCE)
Docker Lab and Proof of Concept (PoC) python script can be found at https://t.co/LK9Ur3egRQ
Blog: https://t.co/MaWG1hbnPU
Finally...!!
It's always a great feeling to accomplished a long term goal.
Super excited to posting this as I have successfully delivered my first Blackhat training in Blackhat USA 2022.
"Attacking Injection Flaws Masterclass - Virtual" x2 batches
https://t.co/mlYCW3kO3W
We are continuing our efforts in virtual environment!
OWASP Pune Meet - 02 July,22
Topic: How to keep your dependencies secure & up-to-date
Speaker: Pramod Rana (@IAmVarchashva)
Time: 11 AM - 11:50 AM
https://t.co/gOhZ59fEHC
Google Meet: https://t.co/DEZoLLjyaN
cc:@JenyRaval
We are continuing our efforts in new normal! It’s virtual again!
OWASP Pune Meetup: 8-Jan-22
Topic: The criticality of managing an application security program
Speaker: Ankit Giri (@aankitgiri)
Time: 11-11:50 AM
https://t.co/wgl3NZH69b
@IAmVarchashva@JenyRaval@nirav4peace
Identifying and Exploiting Path Traversal or Remote Code Execution in Apache 2.4.49 and 2.4.50. For manual and automated approaches for exploitation, kindly visit below link
https://t.co/rcIls8txco
@nirav4peace
We have created a vulnerable docker lab for CVE-2021-41773 and a PoC python script to test Path Traversal and Remote Code Execution vulnerability in Apache 2.4.49.
https://t.co/LhjabQmTIN
I hope this is helpful. Do share your suggestions.
@nirav4peace
👨💻Lack of #securecoding may lead to #security vulnerabilities making organizations & customers at risk
💡Learn the best methods to #secure your #code with Gaurav @4auvar & Mihir @m1h1rd at Nullcon Sep Online Training 2021
✅Book your spot ➡️ https://t.co/7cEpvDb0HJ
#SQL#Java
We are continuing our efforts in new normal environment! It’s virtual again!
OWASP Pune Meetup - 19th June, 2021
Topic: Attacking GraphQL APIs
Speaker: Ali Jujara (@alijujara7)
Time: 11 AM - 11:50 AM
(Virtual) Location:
https://t.co/o0EgfHPi3M
Meetup: https://t.co/PmiSGEfogu
We are back again with meet-up, new normal this time! Its virtual! @OWASP_PUNE Meetup - 20 Feb, 2021
"Use of Linux commands and utilities in security testing" by @sw4pn1lp
Join https://t.co/rLa2mhLfid & Fill https://t.co/wWRDqCT1ZR
@JenyRaval@nirav4peace
We are back again with meet-up, new normal this time! Its virtual! @OWASP_PUNE Meetup - 20 Feb, 2021
"Use of Linux commands and utilities in security testing" by @sw4pn1lp
Join https://t.co/rLa2mhLfid & Fill https://t.co/wWRDqCT1ZR
@JenyRaval@nirav4peace
Want to virtualize ARM-based firmware? Here is one of the custom way to achieve it.
Part-1: https://t.co/5fMdpxPX8y
Part-2: https://t.co/RQGE5iZRqC
cc: @payatulabs#IoTSecurity#Firmware#Virtualizing
When the application has custom protections @realsanjay gets to build a custom extension in burp. nice writeup @notsosecure on managing application with per request HMAC protection
If you are stuck in a pentest and unable to run an automated/burp scans because of an integrity check at client side. Checkout this awesome blog by @realsanjay .
New #notsosecure blog.
https://t.co/yAEOrLFbnW