Tirth Parmar 🫯

94 posts

Tirth Parmar 🫯 banner
Tirth Parmar 🫯

Tirth Parmar 🫯

@thetirthparmar

Cyber Security Engineer | Full-Stack Developer | Founder @levythonhq

India Katılım Nisan 2020
49 Takip Edilen590 Takipçiler
Adv.Vineet Jindal
Adv.Vineet Jindal@vineetJindal19·
This email from a girl student was received yesterday. While the CBSE portal shows that copies of all her answer sheets have been uploaded and provided, she has neither received them nor is she able to download one of them . This is just one example showing that the CBSE portal is still not functioning properly. I have received numerous complaints regarding the same issue from students across the country. @cbseindia29, students are continuously writing to you but are not receiving any response. Kindly look into these issues and resolve them immediately. @EduMinOfIndia
Adv.Vineet Jindal tweet media
English
14
73
220
10.4K
Tirth Parmar 🫯 retweetledi
Sarthak Sidhant
Sarthak Sidhant@sidhant_sarthak·
@ni5arga @cbseindia29 good morning CBSE, you said you used scanners to scan these copies, now since the copies are out to the public view, do you mind explaining which copies when scanned through a scanner, have a drop shadow? and these 3 folds? did you really use scanners?
Sarthak Sidhant tweet media
English
116
1.6K
5.3K
179.8K
Not Afraid
Not Afraid@ohyeah_xdd·
@thetirthparmar Very good write-up. We need more of these 🙂. Recently a relative's mobile got hacked after they installed SBI yono apk from WhatsApp but unfortunately I deleted the Apk and hence couldn't decompile/inspect it.
English
1
0
3
442
Tirth Parmar 🫯
Tirth Parmar 🫯@thetirthparmar·
So I busted a fake RTO website yesterday (as I teased). Here's the full technical breakdown, it gets way wilder than I expected. 🧵 (1/12) #malware #cybersecurity
English
6
34
185
9.2K
Tirth Parmar 🫯
Tirth Parmar 🫯@thetirthparmar·
@ContactVVR Exactly! Indian expats in Saudi still have Indian bank accounts. So one infected phone = UPI PIN stolen (Indian savings) + Saudi bank SMS monitored (salary). Both countries’ finances compromised in one click
English
1
2
3
105
The Solitary Reaper @YonSolitary is my old account
@thetirthparmar So they are basically scamming Indians living in Saudi Arabia with fake challan. The currency restriction to Riyal was a deadgiveaway. Thank you for your meticulous work & a detailed thread. Sad that the authorities won't bother about this either.
English
1
2
3
49
sidharth
sidharth@sidharthify·
almost every single OnMark portal built by EduTek is fundamentally insecure, and CBSE is lying to you about the safety of student data. we found default passwords, URL-based RCEs, and raw MD5 hashes. millions of students are at risk. read the blog here: sidharthify.tech/blogs/blog-31-…
sidharth tweet media
English
15
352
1.3K
31K
Apollyon
Apollyon@0xApollyon·
@thetirthparmar lmfao you have shell access ??? 🤣 who did the security for this shit bruh
English
1
0
3
356
Apollyon
Apollyon@0xApollyon·
@thetirthparmar hey tirth, i wouldnt recommend doing this. while its funny as hell and the authorities equally incompetent, by defacing stuff you are giving them an easy target to make an example out of
English
1
0
7
1.1K
Tirth Parmar 🫯
Tirth Parmar 🫯@thetirthparmar·
@krutikvirani rto-seva[.]online/parivahan/app/ ata011.b-cdn[.]net/final-2d0d6519.apk MD5: 88699d567254fa954f0394347317e1df
English
1
0
3
202
Tirth Parmar 🫯
Tirth Parmar 🫯@thetirthparmar·
Just busted a fake RTO website + Android app distributing malware and scamming thousands of people. Did a quick analysis and the whole thing is wilder than I expected. Will be publishing a full technical breakdown and report here soon.
English
5
29
243
5.6K
Tirth Parmar 🫯
Tirth Parmar 🫯@thetirthparmar·
IOCs: - rto-seva[.]online/parivahan/app/ - ata011.b-cdn[.]net/final-2d0d6519.apk - MD5: 88699d567254fa954f0394347317e1df - fir-[REDACTED]-rtdb.firebaseio.com Reported to Google + CERT-In & Bunny CDN If you get a challan SMS with a link DO NOT click. (12/12) #AndroidMalware
English
2
5
26
972
Tirth Parmar 🫯
Tirth Parmar 🫯@thetirthparmar·
C2 evolution: Phase 1 (dead): jsonserv[.]xyz → .biz → .live → jsonapi[.]biz Express.js servers behind Cloudflare. All routes return 404. Phase 2 (live): Firebase RTDB No server to maintain. Google infra. Encrypted transport. Much harder to seize. (11/12)
English
1
1
13
976