Himanshu Kohli

26.4K posts

Himanshu Kohli banner
Himanshu Kohli

Himanshu Kohli

@manshu18

Blogger | Tweeter | Social Media Enthusiast | Dreamer | Thinker | Observer | Oracle DBA | B2B | Consultant | Security |

New Delhi Katılım Temmuz 2010
323 Takip Edilen1.1K Takipçiler
Himanshu Kohli retweetledi
Parimal
Parimal@Fintech03·
Look at Chavara on the attached map. In 1909, a German chemist named C.W. Schomberg was walking on these very beaches. He noticed a strange, shimmering black tint in the sand. Most locals thought it was just dirt. Schomberg, a man with a trained eye, realized he was standing on Monazite, the world’s richest source of Thorium. He quietly started shipping the sand back to Germany under the guise of ballast for ships. By the time the British realized what was happening, Germany had built a secret stockpile of Indian Thorium that they hoped would power their future industrial & potentially weaponized ambitions. India’s sand was literally the hidden fuel of the early 20th-century German labs. Also, there is a mineral in that Odisha-Andhra corridor called Zircon. We cannot build a modern nuclear reactor/a stealth jet w/o it. For yrs, Sand Smuggling has been a high-stakes, dangerous underground industry in these corridors. Because a single ton of concentrated sand from these specific blue zones can be worth more than its weight in silver to a country trying to build a secret nuclear program. Image Source: @SputnikInt
Parimal tweet media
English
18
428
1.3K
55.1K
Himanshu Kohli retweetledi
Pramod Kumar Singh
Pramod Kumar Singh@SinghPramod2784·
Nida Khan aka 'Lady Don', 'Lady Boss', the AGM HR, protected her co-religeonists so well that Nashik City Police was forced to send 7 women constables in disguise to unearth the sordid & systematic subjugation of Hindu girls/women employees with TCS Nashik Branch. She is untraceable. #TCS
Pramod Kumar Singh tweet media
English
193
1.5K
3.2K
117.8K
Himanshu Kohli retweetledi
Ashwin Nagar | अश्विन नागर‏
Dear @TCS , I couldn’t find any disclosures in your financial statements about funding to entities like AltNews, Zubair, Mehdi Hassan, or certain Ivy League universities that often speak against our nation or Hindus. Could you clarify which annexure covers this or its private?
Tata Consultancy Services@TCS

#TCSQ4 FY26 results reflect strategic progress in enterprise AI adoption. Hear from our senior leadership on our sequential growth and what comes next. 𝐃𝐨𝐰𝐧𝐥𝐨𝐚𝐝 𝐥𝐢𝐧𝐤𝐬 𝐟𝐨𝐫 Q4FY26 Earnings: USD: on.tcs.com/Q4FY26-PR-USD INR: on.tcs.com/Q4FY26-PR-INR

English
120
2.5K
5.3K
88.3K
Himanshu Kohli retweetledi
Swapna Kumar Panda
Swapna Kumar Panda@swapnakpanda·
Shocking details coming on TCS Nashik Case: 1. Police sources say Tata and TCS Senior Management did everything they could to prevent the case from being filed. 2. Once it went viral, the media was subtly informed that if they wanted Tata advertising revenue to continue, they should not mention TCS by name. 3. TCS in a statement said that it maintains a "zero-tolerance policy" and that the employees under probe have been suspended. 4. Victims reportedly claimed they approached the company's HR earlier, but no action was taken. TCS has remained silent on this allegation. 5. Police already arrested 6 in this case. All were managers and engineers. Asif Ansari, Shafi Sheikh, Shah Rukh Qureshi, Raza Memon, Tausif Attar, Danish Sheikh. 6. HR Nida Khan is on the run and police is still searching for her. My two-cent take: After Ratan Tata, Tata group has lost all its morality. I may be too quick to judge this, but their wordings and workings are totally opposite now.
English
473
3.7K
11.2K
366.8K
Himanshu Kohli retweetledi
John Scott-Railton
John Scott-Railton@jsrailton·
11/ Help starve the ADINT dragnet. Do this now: iPhone: ⚙️Settings➡️Privacy & Security➡️ Tracking Turn off "Allow Apps to Request to Track" Android: ⚙️Settings➡️Privacy ➡️ Ads ➡️Delete Advertising ID It's only a beginning, but you don't owe any of these companies a drop of your data.
John Scott-Railton tweet mediaJohn Scott-Railton tweet media
English
4
159
445
21.9K
Himanshu Kohli retweetledi
Nav Toor
Nav Toor@heynavtoor·
🚨 Someone just open sourced a fully autonomous AI hacker and it's terrifying. It's called Shannon. Point it at your web app, and it doesn't just scan for vulnerabilities. It actually exploits them. Real injections. Real auth bypasses. Real database exfiltrations. Not alerts. Not warnings. Actual working exploits with copy-paste proof-of-concepts. Here's what this thing does autonomously: → Reads your entire source code to plan its attack → Maps every endpoint, API route, and auth mechanism → Runs Nmap, Subfinder, and WhatWeb for deep recon → Hunts for Injection, XSS, SSRF, and broken auth in parallel → Launches real browser-based exploits to prove each vulnerability → Generates a pentester-grade report with reproducible PoCs Here's the wildest part: It follows a strict "No Exploit, No Report" policy. If it can't actually break it, it doesn't report it. Zero false positives. It pointed at OWASP Juice Shop and found 20+ critical vulnerabilities in a single run including complete auth bypass and full database exfiltration. On the XBOW Benchmark (hint-free, source-aware), it scored 96.15%. Your team ships code daily with Claude Code and Cursor. Your pentest happens once a year. That's 364 days of shipping blind. Shannon closes that gap. One command. Fully autonomous. The Red Team to your vibe-coding Blue team. Every Claude coder deserves their Shannon. 10.6K GitHub stars. 1.3K forks. Already trending. 100% Open Source. AGPL-3.0 License.
Nav Toor tweet media
English
212
1K
8.2K
792K
Himanshu Kohli retweetledi
Aircorridor
Aircorridor@_aircorridor·
Cloudflare hides 19.3% of all websites—but not perfectly. CloudRip scans subdomains to find IPs not behind Cloudflare protection, exposing the real origin server: hackers-arise.com/web-app-hackin… @three_cube
Aircorridor tweet media
English
24
222
1.3K
120.4K
Himanshu Kohli retweetledi
Muhammad Fauzan 🇵🇰
Muhammad Fauzan 🇵🇰@Fozisimi143·
Bug : SQL INJECTION Steps: 1) capture Post Request in a burp 2) save into sql.txt file 3) run sqlmap Command: sqlmap -r sql.txt --current-db --level 5 --risk 3 --dbs --force-ssl Vulnerable parameter : username Database: Oracle
Muhammad Fauzan 🇵🇰 tweet media
English
12
187
588
0
Himanshu Kohli retweetledi
Hussein Daher
Hussein Daher@HusseiN98D·
MYSQL Database credentials leaking in PHPINFO , funniest bug I ever found - retweet to share awarness #bugbounty #bugcrowd
Hussein Daher tweet media
Lebanon 🇱🇧 English
2
15
43
0
Himanshu Kohli retweetledi
BRute Logic
BRute Logic@BRuteLogic·
Some MySQL tricks to break some #WAFs out there. SELECT-1e1FROM`test` SELECT~1.FROM`test` SELECT\NFROM`test` SELECT@^1.FROM`test` SELECT-id-1.FROM`test` #SQLi #bypass #bugbountytip
BRute Logic tweet media
English
9
550
1.5K
0
Himanshu Kohli retweetledi
Anton
Anton@therceman·
Bug Bounty Tip You can check if a website is running exactly a MySQL database and is potentially vulnerable to SQL injections by using !!0 as input for numeric parameters in the query string or request body. P.S. Why MySQL thinks that !!0 == 1? Cheers!
Anton tweet media
English
5
101
387
42.2K
Himanshu Kohli retweetledi
Hussein Nasser
Hussein Nasser@hnasr·
Let us indulge in some engineering beauties of MySQL. It rarely gets Love compared to Postgres. Uber reduced their database locks by 94% when they upgraded to MySQL 8.0, thanks to this performance rearchitecture. We know that writing to the index may cause a structure change (btree rebalance) which can cause leaf pages, internal pages and the ROOT to split and update. Allowing a read while the structure is being changed can cause corruptions, so we need to protect the structure and readers via physical locks or a mutexes (I talk about those in my OS course) In version 5.6, MySQL InnoDB opted to do a global exclusive lock (X lock) on entire index when a rebalance is triggered, preventing reads from happening (reads take a shared S lock), even when the reads are going to a different part of the tree. In 8.0 only the pages being restructured or written are X Locked (not the entire index) also a snapshot of those pages are saved so concurrent reads to those pages are allowed. This index is instead locked via a new intent SX Lock which allows shared S locks but prevents X Lock. What better proof of this engineering marvel than Uber upgrading to MySQL 8 and reducing their database locks by 94% ! We know MySQL is struggling recently against Postgres and I covered that in another video but the engineerings marvels must be acknowledged regardless of the state of the product. --- Watch my full deep dive coverage here Advanced MySQL Index Locking Explained youtu.be/MK24y7AmKTc I also try to start crediting the Devs behind the work, this work is done by Zongzhi Chen Read uber’s article uber.com/en-JO/blog/upg…
YouTube video
YouTube
Hussein Nasser tweet media
English
7
40
548
40.5K
Himanshu Kohli retweetledi
Hussein Nasser
Hussein Nasser@hnasr·
MySQL fixed a bug that was causing extra IO during reads. The fix made reads 4x faster (when there are concurrent inserts) Mark found and logged the bug, his blog explains it all. I really enjoy this stuff. There is always room for improvement.
Hussein Nasser tweet media
English
5
70
582
66.2K
Himanshu Kohli
Himanshu Kohli@manshu18·
@BigRock you people are using outdated Mysql versions for shared web hosting. Selling products intentionally with security vulnerabilities.
English
0
0
0
19