
Bipin Jitiya
337 posts

Bipin Jitiya
@win3zz
Founder of @Cuberks. Maker, hacker, security researcher. Love nature and psithurism. Tweets mostly about hacking, tech, entrepreneurship, and other geeky stuff.
Ahmadabad City, India Katılım Ocak 2014
146 Takip Edilen7.8K Takipçiler
Sabitlenmiş Tweet

As I previously promised I would publish a writeup on how I managed to find the SSRF bug on the biggest social media website, Facebook.
So I wrote a blog about that finding. I hope you like it. 🍷
#BugBounty #Infosec
link.medium.com/smZtjTvTV6
English

New writeup!
Google Cloud Shell Takeover: 3 Auto Execution Bugs
gist.github.com/win3zz/56e5077…



English


Logout Endpoint Redirection Fuzz List
gist.github.com/win3zz/4d45898…
English

Sandbox bypass → arbitrary code exec → OS cmd exec in GenAI dev platform.
Found js.map, used SourceMapper to extract JS, analysed logic, used prototype pollution + object traversal to bypass.
Got creds incl private keys, cloud, GitHub, DB, mail, other secrets.

English

Remember this post?
I am working on a detailed write-up for it.
My last write-up (Google Cloud Shell Container Escape) got an amazing response, so I decided to work on another detailed one.
I will publish it tomorrow at 10:30 AM (IST).
Bipin Jitiya@win3zz
Sandbox bypass → arbitrary code exec → OS cmd exec in GenAI dev platform. Found js.map, used SourceMapper to extract JS, analysed logic, used prototype pollution + object traversal to bypass. Got creds incl private keys, cloud, GitHub, DB, mail, other secrets.
English

@yangO760305 Do you see any error while running:
ip link add xyz type dummy
OR
ip link add xyz type tun?
English

@imranhossain404 This is only for opensource projects, specifically those hosted on GitHub
English

@retweet_Winn It needs human reasoning, context, and logic to understand how models interpret language, policies, and intent
English












