Open in app

Sign in

Medium Logo
Write

Sign in

Akash c
Akash c

82 followers

Home

About

Exploiting Session Fixation via Stored XSS and Cookie Jar Overflow Attack

As a Pentester, I know that sometimes finding a vulnerability isn’t enough you also need to demonstrate the real impact to get it taken…

Oct 18, 2024
1
Exploiting Session Fixation via Stored XSS and Cookie Jar Overflow Attack
Exploiting Session Fixation via Stored XSS and Cookie Jar Overflow Attack
Oct 18, 2024
1

Bypass SSL Pinning on Flutter iOS App Using Frida and OpenVPN

Flutter is an open-source mobile app development framework created by Google, that enables developers to create natively compiled…

Mar 2, 2023
Bypass SSL Pinning on Flutter iOS App Using Frida and OpenVPN
Bypass SSL Pinning on Flutter iOS App Using Frida and OpenVPN
Mar 2, 2023

Blind XSS To SSRF

During bug hunting in a private bug bounty program, I came across a feature within the application that allowed for the generation of PDF…

Jan 29, 2023
1
Blind XSS To SSRF
Blind XSS To SSRF
Jan 29, 2023
1

Bypassing account lockout through password reset functionality

During a recent penetration testing engagement, I discovered a vulnerability in the login page of a web application. Specifically, I found…

Jan 28, 2023
Jan 28, 2023

Attack | Defense — Pivoting II Walkthrough

Network Topology

Apr 22, 2021
Attack | Defense — Pivoting II Walkthrough
Attack | Defense — Pivoting II Walkthrough
Apr 22, 2021

Common ports enumeration and exploitation technique

Port 21 —  FTP

Apr 22, 2021
Apr 22, 2021

Reflected Cross-site scripting in Triconsole Datepicker Calendar (CVE-2021–27330)

Risk: Medium

Apr 10, 2021
Reflected Cross-site scripting in Triconsole Datepicker Calendar (CVE-2021–27330)
Reflected Cross-site scripting in Triconsole Datepicker Calendar (CVE-2021–27330)
Apr 10, 2021

Hack The Box Jerry Write-Up

Enumeration

Nov 19, 2018
Hack The Box Jerry Write-Up
Hack The Box Jerry Write-Up
Nov 19, 2018

Celestial Hack The Box Write-Up

Enumeration

Aug 25, 2018
Celestial Hack The Box Write-Up
Celestial Hack The Box Write-Up
Aug 25, 2018

2 Factor Authentication Bypass on Appcelerator

Weakness:Web Parameter Tampering

Oct 13, 2017
Oct 13, 2017
Akash c

Akash c

82 followers

Self-learner |Bug Hunter|

Following
  • Ryan Hausknecht

    Ryan Hausknecht

  • George O

    George O

  • Luke Stephens (@hakluke)

    Luke Stephens (@hakluke)

  • d0nut

    d0nut

See all (20)

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech