Sayaan Alam

2.5K posts

Sayaan Alam banner
Sayaan Alam

Sayaan Alam

@ehsayaan

Security Researcher @nuasecurity | Red Teamer and Bug Bounty Hunter | SRT Hero at @Synack Red Team | Hackerone - sayaanalam

가입일 Nisan 2017
998 팔로잉9.4K 팔로워
고정된 트윗
Sayaan Alam
Sayaan Alam@ehsayaan·
Finally, the Most awaited write-up is here , SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever! Kudos to @TechFenixSec Red team for helping me throughout the research Retweet if you like it.🙂 #bugbounty medium.com/techfenix/ssrf…
English
31
307
948
0
Sayaan Alam
Sayaan Alam@ehsayaan·
I placed a gift card order on @myntra , it’s been 2 days and it has not delivered yet - 1325944 95965457622603 . I called customer care multiple times, they just mark the tickets as resolved with no resolution at all. This is the shittiest service, they can’t even cancel it.
English
0
0
0
152
Sayaan Alam
Sayaan Alam@ehsayaan·
Absolutely thrilled that one of the most amazing cybersecurity conferences is happening in breathtaking Mussoorie! @BsidesMussoorie is more than a conference, it’s an experience: insightful talks, brilliant minds, networking, and fresh mountain air.
English
0
0
1
237
Soham Datta
Soham Datta@tech_savvy_guy_·
hey @rauchg - there seems to be a flaw in the deployment protection in @vercel i am part of an organization in both GitHub and Vercel with my organization email added to both platforms. Now, when I author commits to my repo with my organization email, it blocks the deployment
Soham Datta tweet media
English
2
0
12
11.4K
Sayaan Alam
Sayaan Alam@ehsayaan·
@rauchg Obsession can make me sit on a screen for straight 16 hours or more. A job could never match that productivity!! Obsession + Goal is key to super productivity.
English
0
0
1
95
Guillermo Rauch
Guillermo Rauch@rauchg·
Obsession is the mother of invention
English
373
1.1K
8.5K
452.6K
Sayaan Alam
Sayaan Alam@ehsayaan·
@ArmanSameer95 Sorry to hear bro, you can always call whenever you don’t feel good or need someone.
English
0
0
2
113
TESS
TESS@ArmanSameer95·
Life isn’t fair. I lost my childhood best friend, the one I grew up with. This doesn’t feel right.
English
7
0
26
1.4K
Sayaan Alam
Sayaan Alam@ehsayaan·
@dhruvagoyal Less AI interactions when using MCP, you just give input and final output/results. No follow up on each step
English
0
0
1
75
Dhruva Goyal
Dhruva Goyal@dhruvagoyal·
If AI models can control applications directly (CLI/Browser/API), what’s the point of MCP?
English
2
0
0
182
Sayaan Alam
Sayaan Alam@ehsayaan·
@arshadkazmi42 Takeover check failed: incompatible encoding regexp match (UTF-8 regexp with ASCII-8BIT string)
English
1
0
2
169
Arshad Kazmi
Arshad Kazmi@arshadkazmi42·
I recently added subdomain takeover monitoring to issl.today, along with an API. You can now generate an API key and programmatically check whether a domain is vulnerable or potentially vulnerable to subdomain takeover. It also supports importing your HackerOne scope via API key. The system will: Import all in-scope domains Perform subdomain enumeration (including wildcards) Continuously monitor them for services that could lead to takeover Useful if you’re tracking takeover opportunities across many programs.
Jenish Sojitra@_jensec

Is there an updated version or library or API for github.com/EdOverflow/can… ?

English
2
0
24
4.1K
Sayaan Alam
Sayaan Alam@ehsayaan·
@rauchg @YShahinzadeh Haha i didn’t expect a lightning fast response like that. I must applaud for your responsiveness on such issues. I wish all other C Suite executives were like that🙌🏻
English
0
0
7
314
YS
YS@YShahinzadeh·
Is anyone here from Vercel? I discovered a P2 vulnerability in one of their products. I initially reported it by email but received an automated response directing me to submit through HackerOne, and you know the rest of the story :] Is there anyone I can speak with directly?
English
13
0
131
14.7K
Mahindra For You
Mahindra For You@18002096006·
@ehsayaan Hi @ehsayaan, this is definitely not the experience we want you to have. Kindly share your registered contact number and vehicle details with us via DM, so we can connect and address the issue more effectively. Regards, MahindraForYou twitter.com/messages/compo…
English
1
0
0
84
Sayaan Alam
Sayaan Alam@ehsayaan·
@rauchg Hahaha it’s good to see you involved in bug bounties lately. Especially during Vercel WAF challenge. Can’t donate funds to some early age cybersecurity startup to kickstart their journey?
English
1
0
1
1.5K
Guillermo Rauch
Guillermo Rauch@rauchg·
Due to how these bug bounty programs work, we’re getting paid for the discoveries by Cloudflare / Matthew. Please reply with interesting AI and cybersecurity research teams or open source projects we should donate the funds to!
English
56
8
1K
104K
Guillermo Rauch
Guillermo Rauch@rauchg·
We've identified, responsibly disclosed, and confirmed 2 critical, 2 high, 2 medium, 1 low security vulnerabilities in Cloudflare's vibe-coded framework Vinext. We believe the security of the internet is the highest priority, especially in the age of AI. Vibe coding is a useful tool, especially when used responsibly. Our security research and framework teams are extending their help and expertise to Cloudflare in the interest of the public internet's security.
English
329
140
4.2K
959.5K
Sayaan Alam
Sayaan Alam@ehsayaan·
On a recent target, the application had a Slack integration on the client side that allowed me to message anyone within their Slack workspace. #bugbounty
Sayaan Alam tweet media
English
1
2
44
2.7K