Ritik Patel
93 posts

Ritik Patel
@HackmeRitik
I am the Son of a Farmer. 🧑🌾 Security researcher 🚀
انضم Eylül 2023
242 يتبع10 المتابعون
Ritik Patel أُعيد تغريده
Ritik Patel أُعيد تغريده

Just started CSRF labs. Any suggestions for me? Comments down below @PortSwigger
English

I completed the Web Security Academy lab:
CSRF vulnerability with no defenses
@WebSecAcademy
portswigger.net/web-security/c…
English
Ritik Patel أُعيد تغريده

404 page to RCE. A report by @spaceraccoon
He chained two old CVEs to achieve RCE:
- Found a 404 page mentioning an obscure CMS, discovered /josso/signin login
- Triggered CVE-2007-0450 (directory traversal in mod_proxy) using a %5C../ to bypass the internal proxy
- Reached an unprotected JBoss web console on localhost (CVE-2007-1036)
- Exploited Java deserialization with jexboss tool for full RCE
Full report 👇
hackerone.com/reports/502758
English
Ritik Patel أُعيد تغريده

The era of AI attacks is here Just joined the OSAI giveaway Let’s see how offensive security evolves next @offsectraining #aisecurity #offsec

English

@PortSwigger Thanks @PortSwigger for response and suggestion and i am a big fan of portswigger labs it was insane 🚀🚀
English

Hey Ritik. Try to visualize how your input is being used to dynamically construct the SQL statement on the backend, and brush up on some basic SQL syntax to help you build an exploit.
Watch this video for more SQL injection context: youtube.com/watch?v=wX6tsz…
Also, big shoutout to @Mi1So, @rana__khalil and @z3nsh3ll for their excellent videos on the @WebSecAcademy SQL Injection labs.

YouTube
English



““Hii everyone this is my first write up so ignore my silly mistakes”😊” by Ritikpatel
Thanks @hetroublehacker for giving me advice on writing the article. @hackmeritik/hii-everyone-this-is-my-first-write-up-so-ignore-my-silly-mistakes-9fc42066f72b" target="_blank" rel="nofollow noopener">medium.com/@hackmeritik/h…

English

I just completed Bounty Hacker room on TryHackMe! You talked a big game about being the most elite hacker in the solar system. Prove it and claim your right to the status of Elite Bounty Hacker! tryhackme.com/room/cowboyhac… #tryhackme via @tryhackme
English

Cyber Security 101 (SEC1) certification is live! 🚀 a Hands-on certification built to show you actually understand the fundamentals. So stop saying you know the cyber fundamentals and start proving it.
And to launch it properly…🎁 We are giving away 500 FREE SEC1 certification attempts!
🔁 Share this post
📝 Fill in the form: forms.gle/rTEPcR6UdaXR7r…
🏆 Get Certified
🖇️ Learn more about SEC1 here: tryhackme.com/certification/…
English









