Mahendra Thanniru

283 posts

Mahendra Thanniru banner
Mahendra Thanniru

Mahendra Thanniru

@Mah1ndra_

Security Engineer

Hyderabad, India Katılım Haziran 2016
4.1K Takip Edilen239 Takipçiler
Mahendra Thanniru retweetledi
Rahul Maini
Rahul Maini@iamnoooob·
Here's our writeup of CVE-2021-26084 Confluence RCE now that it's out in public. Although, there are still a few mysteries to be solved. cc: @rootxharsh github.com/httpvoid/write…
Rahul Maini tweet media
English
20
442
1.1K
0
Mahendra Thanniru retweetledi
Scott Piper
Scott Piper@0xdabbad00·
For red teams and pentesters, and defenders wanting to know attacks to look for and protect against, I've written down the techniques I would use to attack AWS environments. tldrsec.com/blog/lesser-kn…
English
5
268
773
0
Mahendra Thanniru retweetledi
pyn3rd
pyn3rd@pyn3rd·
#CVE-2020-17530 (S2-061) Struts2 OGNL Expression Remote Code Execution @pwntester nice find!👍
GIF
English
3
84
281
0
Mahendra Thanniru retweetledi
Sam Curry
Sam Curry@samwcyo·
Ran into a neat authentication bypass via extension whitelist today with @bbuerhaus and @_specters_: GET /admin%2ejsp%3b.png Was able to turn a number of post-auth SQL injections into pre-auth vulns. Always fun messing with these. 😁
English
3
94
384
0
Mahendra Thanniru retweetledi
shubs
shubs@infosec_au·
I've just added an API routes wordlist containing 953011 possible API paths from the HTTPArchive dataset. Download it at wordlists.assetnote.io - all paths which start with "/api/", "/v1/", "/v2", or "/rest/". Good luck hacking! Thanks for requesting this, hope it helps.
English
16
283
1K
0
Mahendra Thanniru retweetledi
PT SWARM
PT SWARM@ptswarm·
💉Advanced MSSQL Injection Tricks💉 🩸 New DNS Out-Of-Band vector in SELECT statement 🩸 Quick exploitation: Get all table data in one query 🩸 Read local files in SELECT statement and more! Read the article: swarm.ptsecurity.com/advanced-mssql…
English
1
249
505
0
Mahendra Thanniru retweetledi
pyn3rd
pyn3rd@pyn3rd·
Pop up calculator in Weblogic 14.1.1
GIF
English
3
16
128
0
Mahendra Thanniru retweetledi
Bo0oM
Bo0oM@i_bo0om·
If you have found server-status, but there is nothing in it but statistics, try adding the full parameter to it: /server-status?full If it is PHP-FPM Status Page, you will be shown the request logs.
Bo0oM tweet mediaBo0oM tweet media
English
3
74
222
0
Mahendra Thanniru
Mahendra Thanniru@Mah1ndra_·
It was Really fun playing. Thank you @hackthebox_eu #hbg for making such an awesome content as always. I would recommend everyone to give it a try.
Mahendra Thanniru tweet media
English
0
0
1
0
Mahendra Thanniru retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
There seems to be quite some questions and confusion about the impact of exploiting Zerologon (CVE-2020-1472) on the environment. So here's a thread 👇
English
5
517
998
0