Shivam Pandey 🇮🇳
@shivam31200
Infosec | Synack |Write poems in meantime
ID: 1045683038380789760
https://shivam312000.medium.com 28-09-2018 14:33:59
4,4K Tweet
1,1K Followers
601 Following
I and Rahul Maini reproduced this latest CVE of Moveit (CVE-2023-36934). This is pretty neat finding, props to original finder.
The security research team at Assetnote found and reported a critical pre-auth RCE vulnerability to Metabase earlier this month CVE-2023-38646: blog.assetnote.io/2023/07/22/pre… This one was an incredibly fun discovery as there are many roads to RCE through JDBC. We've published details
Thanks everyone who attended my keynote presentation at Security BSides Ahmedabad. I've published my slides here: drive.google.com/file/d/1aeNq_5… I hope that the keynote was informative and inspiring :)
Binni Shah FWIW, I didn't actually start looking due to the 500ms - I started looking when I saw failing ssh logins (by the usual automated attempts trying random user/password combinations) using a substantial amount of CPU. Only after that I noticed the slower logins.
A knock to remember by Nitish. He has impressed me right from the 1st Test and his composure and temperament have been on display right through. Today he took it a notch higher to play a crucial innings in this series. Wonderfully and ably supported by Washington Sundar as well. Well