Open in app

Sign In

Write

Sign In

Mario
Mario

839 Followers

Home

About

Dec 1, 2022

Investigate Phone Number In Indonesia

This post heavily focus on phone number investigation in Indonesia but this method can be used in general too. Phone number in Indonesia usually have 10 to 12 numbers depend on the operator/provider. Indonesia country code is +62. 0813-445x-xxxx First four number is operator code (0812, 0813, 0823, 0818, 0819 etc)…

Osint

4 min read

Investigate Phone Number In Indonesia
Investigate Phone Number In Indonesia
Osint

4 min read


Nov 23, 2022

Create Sock Puppet Profile For OSINT Investigation

It’s been a while since my last post in this blog. Two years back I got lost in OSINT so I’ll post here what I’ve learn so far. I’ve been using OSINT in my work such as doing investigation with news gathering team, protecting company brand with legal team etc. …

Osint

3 min read

Create Sock Puppet Profile For OSINT Investigation
Create Sock Puppet Profile For OSINT Investigation
Osint

3 min read


Published in InfoSec Write-ups

·Jun 26, 2018

Server Side Request Forgery (SSRF) Testing

Well this story is just for fun testing SSRF not a bounty write up. I found a random web that vulnerable to SSRF but in order to exploit it i should convert my input to base64. Here is the site http://playfreedownloadgames.com:2483/proxy.php?url=aHR0cDovL3d3dy50b3A4MHNnYW1lcy5jb20vc2l0ZS9jb250ZW50L3BhY21hbg==. …

Nginx

2 min read

Server Side Request Forgery (SSRF) Testing
Server Side Request Forgery (SSRF) Testing
Nginx

2 min read


Published in InfoSec Write-ups

·Feb 5, 2018

SQL injection with load file and into outfile

Well this submission make me get the patient badge on h1 coz it’s more then 6 month (1 year) hehehehehe. I got sqli vulnerability when test with apostrophe (‘). Sorry for the redacted guys. 😛 I do register as affiliate on the web as usual. Then got redirect to POST…

Sql

2 min read

SQL injection with load file and into outfile
SQL injection with load file and into outfile
Sql

2 min read


Published in InfoSec Write-ups

·Jan 15, 2018

Command Injection PoC

So back in December 2017 i found a command injection vulnerability in one of job listing site. Here is the simple proof of concept. The vulnerable parameter is filename. I do test with this command `sleep 5` and the response is delayed for 5–6 seconds (6.113 millis). …

Rce

3 min read

Command Injection PoC
Command Injection PoC
Rce

3 min read


Jun 22, 2017

Cross-Site Scripting in Geovision GeoHttpServer

While doing recon in Shodan, i found that Geovision GeoHttpServer script is vulnerable to Cross-Site Scripting (XSS). I don’t know which version who vulnerable with this. By using POST method i was able to execute XSS payload. I have check on cvedetails in this one and this one and there…

Security

2 min read

Cross-Site Scripting in Geovision GeoHttpServer
Cross-Site Scripting in Geovision GeoHttpServer
Security

2 min read


Jun 6, 2017

Cookie-Based Cross-Site Scripting (XSS)

This vulnerability counts as low to medium risk. All you need is install Cookies Manager+ addon in firefox or any other addon/plugin used to manipulate cookie. Browse the page as usual. Open Cookies Manager+ and search for vulnerable cookie parameter, in this example is C_UL parameter. Double click on it and change the content with XSS payload and Save it.

Security

1 min read

Cookie-Based Cross-Site Scripting (XSS)
Cookie-Based Cross-Site Scripting (XSS)
Security

1 min read


Jun 6, 2017

LFI to RCE via access_log injection

Hi guys Just wanna share a trick from Local File Inclusion/File Path Traversal to Remote Code Execution by injecting the access_log. I have a target http://proqualitycontrol.com/index.php?page=aboutus and it’s vulnerable to LFI/FPT. It’s a live website. Inject the target with ../../../../../../../../../../../../../../../etc/passwd%00 payload. Now change with /etc/httpd/conf/httpd.conf. Not all httpd.conf path is…

Bug Bounty

2 min read

LFI to RCE via access_log injection
LFI to RCE via access_log injection
Bug Bounty

2 min read

Mario

Mario

839 Followers

Security Researcher & OSINT Enthusiast

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech