Sivanesh Ashok

289 posts

Sivanesh Ashok

Sivanesh Ashok

@sivaneshashok

Security Researcher | Google VRP

Katılım Nisan 2015
389 Takip Edilen1.5K Takipçiler
Sivanesh Ashok retweetledi
OmerAF
OmerAF@omer_asfu·
👼GatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chain⛓️
OmerAF tweet mediaOmerAF tweet media
English
12
111
562
63.1K
Sivanesh Ashok
Sivanesh Ashok@sivaneshashok·
The sandbox inheritance trick is gold! Loved this episode🔥
Critical Thinking - Bug Bounty Podcast@ctbbpodcast

HackerNotes TLDR for episode 151! — blog.criticalthinkingpodcast.io/p/hackernotes-… ►⠀Null Origin Bypasses: Sandbox iframes with null origins bypass event.origin checks against window.origin because string comparison of "null" passes validation. ►⠀CHIPS Partitioning: Cookies with the partitioned attribute are keyed by scheme + eTLD+1 + iframed host, not just domain. ►⠀Sandbox Inheritance: window.open() from sandboxed iframes inherits sandbox properties (except allow-top-level-navigation). ►⠀Client-Side Routes: Single-page applications expose their entire routing logic in JavaScript - reverse engineer route definitions to discover parameters and endpoints.

English
0
0
5
848
Justin Gardner
Justin Gardner@Rhynorater·
Which bug bounty hunters do you know of specialize in cloud security?
English
15
4
111
13.6K
skull
skull@brutecat·
Wrapping up an amazing time at Google #bugSWAT Mexico 2025. It was a privilege meeting so many brilliant people including @epereiralopez, @kl_sree, @sivaneshashok and more. Thrilled that my report was featured in init.g and used to inspire students. That's truly rewarding.
skull tweet media
English
10
6
64
12.2K
Sivanesh Ashok retweetledi
Eduardo Vela
Eduardo Vela@sirdarckcat·
An in depth summary of the consequences of the reward changes we made in 2024! arxiv.org/abs/2509.16655
English
1
16
46
7.8K
Avi
Avi@_naaash_·
@sivaneshashok @sudhanshur705 I opened it, and felt like a sketchy site with multiple fake “download now” buttons 😭
English
2
0
2
497
Sivanesh Ashok
Sivanesh Ashok@sivaneshashok·
Disingenuous to copy @sudhanshur705 's bug and not give him any credit. Especially when you are driving traffic to the ads in your blog.
English
3
2
25
5.1K
sudi
sudi@sudhanshur705·
@sivaneshashok No suprise , all of their blogposts are a copy 🤡
English
1
0
4
411
Justin Gardner
Justin Gardner@Rhynorater·
We're gonna have a really fun guest on the podcast within the next couple weeks...
Justin Gardner tweet media
English
2
7
107
12.4K