dumbomason

590 posts

dumbomason banner
dumbomason

dumbomason

@dumbomason

Katılım Mart 2018
239 Takip Edilen189 Takipçiler
dumbomason
dumbomason@dumbomason·
It's been a month since I pointed this out. Like any other average Indian company, they didn't reply. Welp.
dumbomason@dumbomason

.@thirdwaveindia where do I report a security vuln? I shouldn't be able to view all the users, let alone admin users. Also, accidentally made myself an admin. Remove that asw. Thanks!

English
0
0
0
53
dumbomason
dumbomason@dumbomason·
.@thirdwaveindia where do I report a security vuln? I shouldn't be able to view all the users, let alone admin users. Also, accidentally made myself an admin. Remove that asw. Thanks!
dumbomason tweet media
English
3
3
25
4K
dumbomason retweetledi
lcamtuf
lcamtuf@lcamtuf·
My new C programming book is slowly taking shape. If you want to learn along, let's start with the basics of control flow: godbolt.org/z/3GerY3zEc 1/5
lcamtuf tweet media
English
18
75
966
87.4K
dumbomason
dumbomason@dumbomason·
@pjparties Late reply: I never thought people would gatekeep my findings haha. The document was written in public domain to educate others. Gatekeeping goes against it. :P @nkmason/p-151144499" target="_blank" rel="nofollow noopener">substack.com/@nkmason/p-151… This is the updated blog.
English
0
0
0
20
Parthenon🏛️
Parthenon🏛️@pjparties·
so apparently there’s a vulnerability in delhi and blr metro that you can exploit for infinite recharge😗
English
11
0
42
5.2K
dumbomason
dumbomason@dumbomason·
.@Swiggy 13.77 centuries for some chicken? 😅
dumbomason tweet media
English
1
0
0
168
dumbomason
dumbomason@dumbomason·
.@amitgupta007 you might be interested in some of the findings :) I must say, the obfuscation that I've seen in #Yulu's android app is top notch. Tho, obscurity is not #security :) Mandatory tag, tho I know I'll be ghosted, @YuluBike
dumbomason@dumbomason

.@YuluBike stop ghosting. Either say that your systems are secure and I'm lying or acknowledge my findings. Ghosting is not gonna do anything.

English
3
1
9
788
dumbomason
dumbomason@dumbomason·
.@YuluBike stop ghosting. Either say that your systems are secure and I'm lying or acknowledge my findings. Ghosting is not gonna do anything.
Yulu@YuluBike

@dumbomason Hey, please share your contact details via DM, and our team will get in touch with you to discuss the same.

English
0
0
5
1.1K
dumbomason
dumbomason@dumbomason·
@YuluBike Been 3 working days. Guess you need more time to drop a "Hi" in my email inbox?
English
0
0
0
92
Yulu
Yulu@YuluBike·
@dumbomason Hey, please share your contact details via DM, and our team will get in touch with you to discuss the same.
English
1
0
0
386
dumbomason
dumbomason@dumbomason·
hey @YuluBike, how do one file a bug report for one of your services?
English
2
0
2
344
dumbomason
dumbomason@dumbomason·
@YuluBike You wanna take this to DMs? I found a way to start Miracle bikes without opening the Yulu app. I can elaborate more here or DMs, you decide :).
English
1
0
4
350
Yulu
Yulu@YuluBike·
@dumbomason Hey, Could you please elaborate on your concern? So that our team will be able to assist you better.
English
1
0
0
105
dumbomason retweetledi
cvam
cvam@cvam0000·
Dear @HSBC how can you close an account without any notification. And now your officials are saying ‘you will get a demand draft worth of balance in the account’ .Is your mailing system is not working or you became so lazy to notify your customers. #fraud
Bengaluru, India 🇮🇳 English
4
9
9
3.8K
dumbomason retweetledi
Rushabh Mehta
Rushabh Mehta@rushabh_mehta·
Delhi Metro is yet to fix the bug reported by Nikhil (@dumbomason) that allows free top ups. Just shows the state of security awareness in India’s best run public utility. Shudder to think about the rest. techcrunch.com/2022/11/02/ind…
English
0
1
12
0
dumbomason retweetledi
RISC-V Instructions
RISC-V Instructions@ItsABitRISCV·
.@intel CEO @PGelsinger examines the Horse Creek @risc_v development platform at #IntelON Features four @SiFive P550 cores at 2.2GHz with PCIe G5 & DDR5 in a 4mm x 4mm die using Intel 4 process. Coming soon(tm) to a next generation HiFive dev board
RISC-V Instructions tweet mediaRISC-V Instructions tweet media
English
1
29
167
0
dumbomason
dumbomason@dumbomason·
You can change the dpid param in the URL to get other block texts.
English
1
0
1
0