Ayush Pathak

256 posts

Ayush Pathak banner
Ayush Pathak

Ayush Pathak

@ehayushpathak

I'm nothing, and not even that. | Security @GetOneCardIn

India Katılım Haziran 2017
372 Takip Edilen155 Takipçiler
Sabitlenmiş Tweet
Ayush Pathak
Ayush Pathak@ehayushpathak·
@ehayushpathak/security-risks-of-cors-e3f4a25c04d7" target="_blank" rel="nofollow noopener">medium.com/@ehayushpathak… I wrote this for @mubix's OSCP voucher giveaway challenge. Not something great tho but i learned something new and that's good.
English
2
23
59
0
Ayush Pathak
Ayush Pathak@ehayushpathak·
Hi @WakefitCo @SupportWakefit. Thank you for the worst service ever by any provider. Your delivery agent called to inform me about the delivery later denied delivery saying "the driver doesn't want to drive". nd now instead of rescheduling the delivery, u guys returned the order.
English
1
0
2
23
Ayush Pathak retweetledi
Scott Piper
Scott Piper@0xdabbad00·
AWS just released RCP examples to prevent OIDC misconfigurations from many third-party vendors. 😍 #specific-example-controls-for-tenancy-within-multi-tenant-oidc-providers-with-a-shared-issuer-url" target="_blank" rel="nofollow noopener">github.com/aws-samples/re… This prevents the problem I wrote about here: wiz.io/blog/avoiding-…
English
0
13
80
3.9K
Ayush Pathak retweetledi
Devansh (⚡, 🥷)
Devansh (⚡, 🥷)@0xAsm0d3us·
I tested over 10 LLM models against a unique, yet basic Trojan source code. All failed to detect the Trojan except for Grok2. This is surprising, given the rise in companies offering AI-powered secure code reviews. If they can't even catch this simple behavior, then "AGI" is still far off. This issue could directly lead to supply chain attacks, where malicious code slips past AI code reviewers. That’s all for now—thank you for coming to my TED talk! Read my full article here: devanshbatham.hashnode.dev/trojan-war-aga…
Devansh (⚡, 🥷) tweet media
English
3
7
46
5K
Ayush Pathak
Ayush Pathak@ehayushpathak·
Ahaan! Nice.
Ayush Pathak tweet media
Filipino
0
0
0
48
Ayush Pathak
Ayush Pathak@ehayushpathak·
Service Update - @airtelindia is still working to resolve the technical issue 3 days later while extending the given timeline on every deadline. :)
Ayush Pathak tweet media
English
3
0
2
176
Ayush Pathak retweetledi
Ngo Wei Lin
Ngo Wei Lin@Creastery·
Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtain environment variables from a production container and to achieve remote code execution in GitHub Enterprise Server: starlabs.sg/blog/2024/04-s…
English
5
84
241
40K
Nick Frichette
Nick Frichette@Frichette_n·
As someone involved in the AWS offsec space, I want to share why I strongly do NOT recommend the HackTricks AWS Red Team Expert course. The author of it is a plagiarist, stealing content from other creators and is directly profiting off of it through sponsorships. A 🧵
English
7
75
328
119.7K
Ayush Pathak retweetledi
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
The fact that they developed a complete zero-click to kernel chain, JUST to then force the device to open a web page to trigger the "real" chain, is the most bureaucratic exploit I can imagine 🙈 koeln.ftp.media.ccc.de/congress/2023/…
LiveOverflow 🔴 tweet media
English
20
298
1.7K
164.8K
X S C O R P
X S C O R P@xscorp7·
[CVE-2023-46604] ActiveMQ Insecure Deserialization RCE Analysis Writeup In my attempts to learn more about vulnerability research, here is my analysis on the recent ActiveMQ vulnerablity and its exploitation. shashankbarthwal.com/articles/cve-2…
X S C O R P tweet media
English
2
16
36
4.3K
FlipkartSupport
FlipkartSupport@flipkartsupport·
@ehayushpathak We're sorry to hear about your experience with the order delivery. We'd like to help you with your concern. Please share the order details with us through a private chat so that we can lend support. Awaiting your response. (1/2)
English
1
0
0
55
Ayush Pathak
Ayush Pathak@ehayushpathak·
Hey @Flipkart @flipkartsupport that's a quick delivery!!!! Also, thank you for NOT resolving the issue but giving a new date every time I asked for an update on the provided date.
Ayush Pathak tweet media
English
2
3
3
366
Ayush Pathak retweetledi
Bipin Jitiya
Bipin Jitiya@win3zz·
Here is my detailed write-up on exploiting some vulnerabilities in Industrial Cellular Router. Don't miss it! #CyberSecurity #Hacking @win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf" target="_blank" rel="nofollow noopener">medium.com/@win3zz/inside…
English
1
37
119
13K
Ayush Pathak retweetledi
egre55
egre55@egre55·
It's important for learning to be available to all. Kickstart your cybersecurity journey with 𝗙𝗥𝗘𝗘 𝗵𝗮𝗻𝗱𝘀-𝗼𝗻 AWS security labs from @PwnedLabs . We will always have a good collection of free cloud security labs. Please retweet and share with friends and colleagues
egre55 tweet media
English
4
43
92
12.1K