Keyur

420 posts

Keyur banner
Keyur

Keyur

@Keyur_K_P

Computer Geek 🤓 Cyber Security Professional 🧑🏻‍💻

Se unió Mayıs 2017
657 Siguiendo269 Seguidores
Keyur
Keyur@Keyur_K_P·
@_jensec @_jensec I had same issue, but now it is working fine for me. What I did was: I Gave program detail, what I want to achieve in Claude Web UI, and ask to create me CLAUDE.md and relevant file. I had copy it in my Claude Code CLI. And it work fine.
English
0
0
1
370
Jenish Sojitra
Jenish Sojitra@_jensec·
Seeing Claude Usage Policy banner despite being a part of Claude Cyber Verification Program, anyone else seeing this?
Jenish Sojitra tweet media
English
10
0
84
10.1K
Keyur
Keyur@Keyur_K_P·
What if AI could do your recon, analyze Burp traffic, and write your pentest report — all from one terminal? I'll show you exactly how this Sunday. Live demos, real findings, no slides-only fluff. 📅 5th April | 11:00 AM 🔗Registration Link: lnkd.in/d4KGGdPw
Keyur tweet media
English
1
0
2
82
Keyur retuiteado
bugcrowd
bugcrowd@Bugcrowd·
Let’s STOP ignoring WebSockets  There are P1s to be found. Here we go.👇🧵
bugcrowd tweet media
English
5
27
176
10.7K
Ishwar Kumar
Ishwar Kumar@Ravenzbb·
Solved it in 1st try!! Thanks @8kSec for the challenge💪🥳
Ishwar Kumar tweet media
8kSec@8kSec

🚨Nobody’s solved these AI Labs yet! academy.8ksec.io/course/ai-expl… We’ve just launched a hands-on lab series focused on AI and LLM security exploitation. The series includes 10 practical challenges covering: - Prompt injection and LLM logic abuse - Unauthorized tool and agent access - Adversarial ML and model evasion - Data poisoning and neural backdoors - Privacy leakage from overfitted models - AI supply-chain compromise Each challenge puts you in a red team role. You exploit the system, submit a real solution, and earn a verified certificate after review. Start hacking: academy.8ksec.io/course/ai-expl…

English
2
0
9
741
Kyrian
Kyrian@kyr19n·
Does anyone know where I can learn and master wireshark, I can't just understand anything on it🙏🙏
English
28
15
205
23.1K
Keyur retuiteado
Security BSides Ahmedabad
Security BSides Ahmedabad@bsidesahmedabad·
🔥 Guess who’s back and bringing the heat to the Cyber Party 🤫💥 @Hacker0x01 is now the official Bug Bounty Sponsor for BSides Ahmedabad 0x06! 🕵️‍♂️💥 Not only are they bringing their A-game to the world of bug bounties, but they're also helping us make this the Finest Cyber Security Conference Around. 🤩 Ready to flex those cybersecurity skills? 🧠💻 And yes… that must-have t-shirt and the coolest swag in town? It’s making a comeback too — and you better believe it’s gonna be 🔥 this year! 😎🧢👕 Feeling excited? You should be! 👀 Tickets drop soon – don’t let the bugs (or the FOMO) get you! 🏃‍♂️💨 #HackerOne #BugBountySponsor #BSidesAhmedabad #Cybersecurity #CyberHunt #HackTheWorld #NextLevelCyber #FOMO #CyberPower #Innovation
Security BSides Ahmedabad tweet media
English
0
12
24
983
Keyur
Keyur@Keyur_K_P·
@bhavukjain1 My Authentication Bypass report was mark as Not Applicable on Shopify😅.
English
0
0
1
598
Bhavuk Jain
Bhavuk Jain@bhavukjain1·
Shopify isn’t for the weak!
Bhavuk Jain tweet media
English
5
1
73
8.1K
Keyur retuiteado
Security BSides Ahmedabad
Security BSides Ahmedabad@bsidesahmedabad·
We’re beyond excited to launch the BSides Ahmedabad 0X06 new website landing page – it’s officially LIVE! 🎉🚀 Go check it out now at bsidesahmedabad.in🔥 Get ready, the CFP is just around the corner! 📝✨ More updates coming your way, stay tuned! 👀📲 #bsidesahmedabad #websitelaunch #bsidesahmedabad0x06 #cybersecurity #techcommunity #ahmedabadevents #newwebsite #staytuned #pentesting #ethicalhacking #securityexperts #hackerprevention #cyberawareness #cyberdefence
Security BSides Ahmedabad tweet media
English
0
10
17
1.9K
Keyur
Keyur@Keyur_K_P·
@tabaahi_ And another was something related to blood change.
English
0
0
0
52
Keyur
Keyur@Keyur_K_P·
@tabaahi_ Hi Mohsin, Recovery from GBS takes time, depends upon multiple factors. Ranging from 6 months to may be 1 year. I would suggest start the treatment as soon as possible. There was 2 types of treatments, one was injection which cost 16k - 17k in 2022
English
1
0
2
326
Keyur retuiteado
Security BSides Ahmedabad
Security BSides Ahmedabad@bsidesahmedabad·
🚨 Big Announcement! 🚨 🥁 We’re thrilled to unveil the official dates for BSides Ahmedabad 2025! 🕶️🎉 🗓️ 12-13 September 2025 🔥 Mark your calendars🗓️, rally your squad🫡& prepare for two incredible days packed with groundbreaking talks😎, hand-on workshops🤩,unparalleled networking🛜& of course,the coolest swags to take home.💼✌️✨ #bsidesahmedabad #ethicalhacking #infosec #techevent #cybersecurity #bugbounty #cyberdefense #conference #dataprotection #pentesting #securityawareness #cloudsecurity #cyberthreat #securityresearch #networking #workshops
English
2
10
40
2.4K
Keyur retuiteado
Jayesh Madnani
Jayesh Madnani@Jayesh25·
🚨 Yay, we were rewarded with $20,000 on our @Hacker0x01 submission for a SSRF bug discovered in collaboration with @Shlibness! 💰🎉 🥳 We uncovered a Critical SSRF vulnerability, turning it into unauthorized access to internal admin endpoints, leading to PII leaks and administrative access! Here’s how we escalated a simple SSRF to a $20,000 bounty. 💰🛡️ 🔍 Step-by-Step Breakdown: 1️⃣During our testing, we found an endpoint accepting an "url" parameter. 2️⃣To confirm it was vulnerable to SSRF, we passed a Burp Collaborator URL and received an HTTP pingback, indicating a potential SSRF issue. ✅ 3️⃣We then attempted to escalate this Issue by accessing localhost and AWS metadata. 4️⃣It turned out the endpoint was part of an AWS Lambda function. By hitting http://localhost:9001/2018-06-01/runtime/invocation/next, we retrieved Lambda function details. 💡 5️⃣At this point, there were no sensitive credentials or Information leaked. But since the SSRF allowed partial read, we wondered: "What if we could access internal services whitelisted for this Lambda?" 🤔 6️⃣Next, we identified two categories of targets across all subdomains: Externally resolving but not directly accessible via HTTP Internally resolving and obviously not accessible via the Internet🌐 7️⃣We used Shub's @infosec_au Surf tool (github.com/assetnote/surf) for discovering potential Internal targets and found 5000+ viable subdomains that were inaccessible from the internet. 🎯 8️⃣Chaining the SSRF further, we searched for Swagger endpoints on all these targets Identified by the surf tool, we ended up looking for endpoints like: http:///swagger-ui/swagger.json http:///api/v1/api-docs http:///api/v2/api-docs etc We discovered that the Lambda function had whitelisted access to internal hosts exposing Swagger API documentation. 🚀 9️⃣The Swagger docs revealed administrative endpoints. Chaining the SSRF again, we accessed these Internal API endpoints, leading to PII leaks and unauthorized access to other internal administrative functionalities. 🔓 ⚠️ Impact: This vulnerability allowed attackers to access internal administrative endpoints, leaking PII and exposing other critical business risks. 🚨 💡Lesson Learned: Don’t stop at confirming SSRF! Always think outside the box and explore ways to escalate for maximum impact. Creativity wins the game! 🧠✨ #BugBounty #HackerOne #BugCrowd #YesWehack #Intigriti #bugbountytips #security Y
Jayesh Madnani tweet media
English
58
142
1.1K
68.7K
Keyur retuiteado
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
Slides of my talk in @bsidesahmedabad I hope you like it and found it a little bit useful #slide=id.g2fe50fbe464_0_0" target="_blank" rel="nofollow noopener">docs.google.com/presentation/d… #bugbounty #bugbountytip #bugbountytips #infosec Thanks for support for all of you and @bsidesahmedabad & @Bugcrowd
Godfather Orwa 🇯🇴@GodfatherOrwa

check my new tools for #bugbounty its just came public now github.com/orwagodfather/… github.com/orwagodfather/… and dont forget to check my updated wordlists Thanks @bsidesahmedabad @Bugcrowd #bugbountytip #bugbountytips

English
25
112
480
31.7K