Skip to content

TechKranti

CyberSecurity Revolution

Tag: bug bounty

[Video] HTTP Request Smuggling Explained: Part 1

October 15, 2020 Amey Anekar Cyber Security Gyaan

In this video, I have tried my best to explain the Request Smuggling attack by first explaining how a server handles HTTP requests based on Content-Length and Transfer-Encoding Headers. I will soon follow up with

Continue reading

Delete IDOR on a Fashion eCommerce Website

August 26, 2020 Amey Anekar Bounty Hunting

This is a story of an IDOR I reported on an Asian fashion eCommerce website’s private program. Like most eCommerce websites, this website provided a feature to store addresses in the customer’s account …

Continue reading

What is “Content-Type: application/x-protobuf”: Protobuf Explained For Hackers

April 1, 2020 Amey Anekar Cyber Security Gyaan

Have you ever come across this header:

Content-Type: application/x-protobuf

Read on to know what it means and what are possible attack scenarios.

Continue reading

How I Reported a DoS Vulnerability to AWS

March 11, 2020 Amey Anekar Bounty Hunting

BadBotHoneypotEndpoint is used by AWS customers who do not want bots, unauthorised spiders and scrapers to scan their site. It works by blacklisting IP addresses of such bots. I discovered a vulnerability with this endpoint that could allow an attacker to blacklist random IPs.

Continue reading

How I discovered an SSRF leading to AWS Metadata Leakage

February 10, 2020 Amey Anekar Bounty Hunting

This is the story of a juvenile SSRF bug who did know it had the potential to look at AWS secrets. 😮

Continue reading

About Me

Hey There, I am Amey Anekar - Web and Mobile Application Security Specialist, Bug Bounty Hunter and Author of TechKranti. I love to write and discuss all things Security. Feel free to DM me on Twitter if you would like to have a chat.  

Follow Us

  • Facebook
  • Twitter

Top Posts & Pages

  • What is "Content-Type: application/x-protobuf": Protobuf Explained For Hackers
  • How I discovered an SSRF leading to AWS Metadata Leakage

Categories

  • Bounty Hunting
  • Cyber Security Gyaan
  • Cyber Security News & Updates
  • Malware Reports & Analysis
  • Tips & Tricks

Search TechKranti

WordPress Theme: Mercia by ThemeZee.