Open in app

Sign In

Write

Sign In

Vaibhav Kumar Srivastava
Vaibhav Kumar Srivastava

427 Followers

Home

About

May 15

The Cost of Neglect: HTML Injection

I understand that you have already read several blogs on HTML injection, but this one is not solely focused on HTML injection. Instead, it discusses the negligence of developers and how you can include this aspect as a test case during testing. I was about to test a web application…

Cybersecurity

2 min read

The Cost of Neglect: HTML Injection
The Cost of Neglect: HTML Injection
Cybersecurity

2 min read


Jan 30

Account Takeover (Insecure Design+ Response manipulation)

Hey Everyone! Let’s learn something new as it is going to be fun learning today. Lets assume that the testing domain is “www.example.com” and it has the functionality to Sign-In/Register accounts. Step 1: Register two accounts (Attacker: vamp9006 Victim: vamp8896) on the application using the register functionality.

Bug Bounty

3 min read

Account Takeover (Insecure Design+ Response manipulation)
Account Takeover (Insecure Design+ Response manipulation)
Bug Bounty

3 min read


Oct 7, 2022

PSScriptAnalyzer: SAST Tool for PowerShell Script

PowerShell Script Analyzer, also known as PSScriptAnalyzer, is a static code analysis tool (SAST tool), which examines the PowerShell written code and evaluates it for various machine-measurable best practices. The module accomplishes this through rules, each of which defines a best practice and tells the engine how to scan for…

Powershell

3 min read

PSScriptAnalyzer: SAST Tool for PowerShell Script
PSScriptAnalyzer: SAST Tool for PowerShell Script
Powershell

3 min read


Jun 26, 2022

Bypassing Cloudflare WAF with Host header manipulation

Hey Folks! Thanks for your responses on my last blog. Let’s learn something new today as it is going to be damn interesting one. If you have been into web application Pentesting you must have encountered or got stopped by Cloudflare for sure. Cloudflare secures and ensures the reliability of…

Bug Bounty

3 min read

Bypassing Cloudflare WAF with Host header manipulation
Bypassing Cloudflare WAF with Host header manipulation
Bug Bounty

3 min read


Jun 19, 2022

Account Takeover by OTP bypass

Hey everyone! This bypass is little bit interesting and you will get to learn a lot hopefully. So I was going through this website which actually deals with teacher’s login and education stuff (Government website). Let’s call this website “example.com”.

Bug Bounty

3 min read

Account Takeover by OTP bypass
Account Takeover by OTP bypass
Bug Bounty

3 min read


Jun 18, 2022

Frauds on Instagram (Part 1)

I would love to call them Frauds instead of hackers because they are using cheap social engineering tricks to manipulate naïve people and taking over their account. I’m damn sure that you all have encountered frauds over the internet. I have recently encountered one of the scenario which I would…

Instagram

4 min read

Frauds on Instagram (Part 1)
Frauds on Instagram (Part 1)
Instagram

4 min read


Jan 16, 2022

Bug Type: HTML injection in confirmation Email !

Hey Everyone! This is about another low-hanging fruit (I’m still not a pro) in one of the web applications listed by OpenBugbounty. For those of you who don’t know about OpenBugBounty, it is a responsible disclosure platform that allows independent security researchers to report XSS and similar security vulnerabilities on…

Cybersecurity

3 min read

Bug Type: HTML injection in confirmation Email !
Bug Type: HTML injection in confirmation Email !
Cybersecurity

3 min read


Dec 3, 2021

Bug type: Stored Cross Site Scripting (XSS) and HTML Injection — Part 2

Hey Everyone! This is my second write-up and I have successfully caught another low-hanging fruit in one of the prominent online reseller’s web applications (Cannot disclose the name of the website, the issue is not resolved yet). I was exploring this web application manually which is running a self-hosted vulnerability…

Bug Bounty

2 min read

Bug type: Stored Cross Site Scripting (XSS) and HTML Injection — Part 2
Bug type: Stored Cross Site Scripting (XSS) and HTML Injection — Part 2
Bug Bounty

2 min read


Nov 27, 2021

Bug type: Stored Cross Site Scripting (XSS) and HTML Injection.

Hey Everyone! I have recently started my vulnerability disclosure journey and this is my first write-up (many more to come. PS: Pray for me ). Instead of directly jumping into Bug bounty platforms I was looking for targets (Mostly the low hanging fruits to boost my confidence) through google dorks…

Bug Bounty

3 min read

Bug type: Stored Cross Site Scripting (XSS) and HTML Injection.
Bug type: Stored Cross Site Scripting (XSS) and HTML Injection.
Bug Bounty

3 min read


May 12, 2021

Order Receipt: Gateway to Phishing

When it comes to data security, every minor detail is considered to be very important. In our daily life, we may be following some guidelines to protect our Digital private information on the various online platforms but the same awareness has faded away when it comes to the security of…

Cybersecurity

2 min read

Order Receipt: Gateway to Phishing
Order Receipt: Gateway to Phishing
Cybersecurity

2 min read

Vaibhav Kumar Srivastava

Vaibhav Kumar Srivastava

427 Followers

Penetration Tester | Masters in Information Security

Following
  • Alexandru Cambose

    Alexandru Cambose

  • Vickie Li

    Vickie Li

  • Thexssrat

    Thexssrat

  • Renganathan

    Renganathan

  • vFlexo

    vFlexo

See all (33)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams