Sivanesh Ashok

292 posts

Sivanesh Ashok

Sivanesh Ashok

@sivaneshashok

Security Researcher | Google VRP

เข้าร่วม Nisan 2015
390 กำลังติดตาม1.5K ผู้ติดตาม
Sivanesh Ashok รีทวีตแล้ว
inspector-ambitious
inspector-ambitious@inspector_amb·
My first memory corruption report. Believe it or not, I didn't use AI to find the vulnerability or to write the exploit. I used it only to learn faster. Took me 5 months. It will be my last, starting new projects...
inspector-ambitious tweet media
English
56
94
3.5K
105.9K
Sivanesh Ashok รีทวีตแล้ว
OmerAF
OmerAF@omer_asfu·
👼GatewayToHeaven (CVE-2025-13292). I discovered a cross-tenant vulnerability in @GoogleCloud's #Apigee, allowing me to access other organizations' data (and sometimes even plaintext JWTs of end users). Below is the full breakdown of the exploit chain⛓️
OmerAF tweet mediaOmerAF tweet media
English
12
110
559
64K
Sivanesh Ashok
Sivanesh Ashok@sivaneshashok·
The sandbox inheritance trick is gold! Loved this episode🔥
Critical Thinking - Bug Bounty Podcast@ctbbpodcast

HackerNotes TLDR for episode 151! — blog.criticalthinkingpodcast.io/p/hackernotes-… ►⠀Null Origin Bypasses: Sandbox iframes with null origins bypass event.origin checks against window.origin because string comparison of "null" passes validation. ►⠀CHIPS Partitioning: Cookies with the partitioned attribute are keyed by scheme + eTLD+1 + iframed host, not just domain. ►⠀Sandbox Inheritance: window.open() from sandboxed iframes inherits sandbox properties (except allow-top-level-navigation). ►⠀Client-Side Routes: Single-page applications expose their entire routing logic in JavaScript - reverse engineer route definitions to discover parameters and endpoints.

English
0
0
5
912
Justin Gardner
Justin Gardner@Rhynorater·
Which bug bounty hunters do you know of specialize in cloud security?
English
15
4
109
13.6K
skull
skull@brutecat·
Wrapping up an amazing time at Google #bugSWAT Mexico 2025. It was a privilege meeting so many brilliant people including @epereiralopez, @kl_sree, @sivaneshashok and more. Thrilled that my report was featured in init.g and used to inspire students. That's truly rewarding.
skull tweet media
English
10
6
73
13.5K
Sivanesh Ashok รีทวีตแล้ว
Eduardo Vela
Eduardo Vela@sirdarckcat·
An in depth summary of the consequences of the reward changes we made in 2024! arxiv.org/abs/2509.16655
English
1
16
46
7.8K
Avi
Avi@_naaash_·
@sivaneshashok @sudhanshur705 I opened it, and felt like a sketchy site with multiple fake “download now” buttons 😭
English
2
0
2
497
Sivanesh Ashok
Sivanesh Ashok@sivaneshashok·
Disingenuous to copy @sudhanshur705 's bug and not give him any credit. Especially when you are driving traffic to the ads in your blog.
English
3
2
25
5.2K
sudi
sudi@sudhanshur705·
@sivaneshashok No suprise , all of their blogposts are a copy 🤡
English
1
0
4
411