Anirudh Anand (@a0xnirudh) 's Twitter Profile
Anirudh Anand

@a0xnirudh

Head of Product Security Engineering at @CRED_club | Application Security ♥ | CTF lover - @teambi0s | Security Trainer - @7asecurity | Tweets are my own.

ID: 115002905

linkhttps://blog.0daylabs.com calendar_today17-02-2010 08:46:11

437 Tweet

3,3K Takipçi

697 Takip Edilen

Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

An Obscure Github Actions Workflow Vulnerability in Google's Flank leading to leaking Google service account credentials & Github Tokens (write access) with Google VRP (Google Bug Hunters) awarding $7500 ! A nice read from Adnan Khan 🔥 adnanthekhan.com/2024/04/15/an-…

An Obscure Github Actions Workflow Vulnerability in <a href="/Google/">Google</a>'s Flank leading to leaking Google service account credentials &amp; Github Tokens (write access) with <a href="/GoogleVRP/">Google VRP (Google Bug Hunters)</a> awarding $7500 ! A nice read from <a href="/adnanthekhan/">Adnan Khan</a> 🔥

adnanthekhan.com/2024/04/15/an-…
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

Making #PHP Great Again 2.0, or how to use filters with `require_once` ? Fun read from jvoisin 🔥 dustri.org/b/solution-to-… If you love solving similar PHP challenges, do checkout websec.fr (Extremely fun PHP based challenges)

Making #PHP Great Again 2.0, or how to use filters with `require_once` ? Fun read from <a href="/dustriorg/">jvoisin</a> 🔥

dustri.org/b/solution-to-…

If you love solving similar PHP challenges, do checkout websec.fr (Extremely fun PHP based challenges)
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

Exploiting Race Condition to Gain Infinite Wealth (through unlimited refunds) - m0leCon (pwnthem0le) CTF 2023 goldinospizza2 writeup: hackmd.io/@Solderet/m0le…

Exploiting Race Condition to Gain Infinite Wealth (through unlimited refunds) - m0leCon (<a href="/pwnthem0le/">pwnthem0le</a>) CTF 2023 goldinospizza2 writeup: hackmd.io/@Solderet/m0le…
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

CVE-2024-0333: ZIP embedding attack on Google #Chrome extensions through abusing CRX file format ( Embedding malicious extension inside a valid Chrome extension to create a malicious extension with a valid signature) readme.synack.com/exploits-expla…

Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

CVE-2023-46851: #Apache Allura (< 1.15.0) Arbitrary File Read via Discussion Import leading to Remote Code Execution (#RCE) via Signed Serialized Session, amazing read from Sonar Research 🔥 sonarsource.com/blog/dangerous…

Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

[Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty ! "the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣 johnstawinski.com/2024/04/15/fix…

[Fun Read] Fixing Typo's and breaching Microsoft's perimeter for a whopping $0 bounty !

"the only thing standing between the public internet and Microsoft’s internal network was a single typo and some shell commands" 🤣

johnstawinski.com/2024/04/15/fix…
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

An interesting collection of Server-Side Prototype Pollution gadgets found in Node.js, Deno standard libraries, and various third-party NPM packages along with exploits: github.com/KTH-LangSec/se…

An interesting collection of Server-Side Prototype Pollution gadgets found in Node.js, Deno standard libraries, and various third-party NPM packages along with exploits: github.com/KTH-LangSec/se…
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

Leaking sensitive data within shared preferences using an insecure Content Provider in the Android App leading to Account Takeover, an interesting read from Ahmed Elmorsi 🇵🇸 🔥 medium.com/@ahmedelmorsy3…

Leaking sensitive data within shared preferences using an insecure Content Provider in the Android App leading to Account Takeover, an interesting read from <a href="/0Xhunterx/">Ahmed Elmorsi 🇵🇸</a> 🔥
medium.com/@ahmedelmorsy3…
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

Just released the first part of a multi-part series on analyzing recent #TeamCity vulnerabilities! Part 1 is all about CVE-2024-23917 and how it leads to Authentication Bypass.

Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

Detailed analysis on #XSS -> #RCE in #electron bypassing the nodeintegration affecting user note app ! Amazing writeup from Ruikai 🔥 0reg.dev/blog/electron-…

Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

Microsoft #Copilot: From Prompt Injection to Exfiltration of Personal Information, amazing read from Johann Rehberger embracethered.com/blog/posts/202…

Microsoft #Copilot: From Prompt Injection to Exfiltration of Personal Information, amazing read from <a href="/wunderwuzzi23/">Johann Rehberger</a>

embracethered.com/blog/posts/202…
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

CVE-2024-45489 - Gaining access to anyone's browser without them even visiting a website, fun read from xyzeva 🔥 kibty.town/blog/arc/

CVE-2024-45489 - Gaining access to anyone's browser without them even visiting a website, fun read from <a href="/xyz3va/">xyzeva</a>  🔥

kibty.town/blog/arc/
Anirudh Anand (@a0xnirudh) 's Twitter Profile Photo

CVE-2024-0132: Escaping @NVIDIA Container Toolkit allowing attackers to gain full access to the host's filesystem leading to Remote Code Execution (#RCE). Amazing research from Wiz 🔥 wiz.io/blog/wiz-resea…