Uranium238sGetting a RCE — CTF WayRecently I was invited to a private program of a company. As a fresh start, I decided to look around and see what I could find. This…Dec 5, 20171Dec 5, 20171
Uranium238sDeveloper Luminate IDORContinuing on my work in Yahoo’s bug bounty program, another app i tested was: Luminate Developer app. In this application, I can create…Aug 30, 2017Aug 30, 2017
Uranium238sLuminate Store Basics defacement and potential takeoverThis vulnerability was found when testing the Stores Basic service of Luminate. In this service, we can create a store from where we can…Aug 30, 20171Aug 30, 20171
Uranium238sHack more, learn more, earn more and get invited more.This blog is not a writeup for a bug but instead is something that all hackers should know when they are reporting a bug. All platform like…Aug 27, 20171Aug 27, 20171
Uranium238sPrivacy issue of FB employeesSometimes while testing or just using an application, being aware of the environment that you are in is actually helpful. On the day of…Jul 31, 2017Jul 31, 2017
Uranium238sLevelUp-online security conferenceFirst, I want to make things clear: I do not own property to any image or content that is in this blog. This is the property of Bugcrowd…Jul 13, 2017Jul 13, 2017
Uranium238sContent type mishap allowing any file upload in cabana.yahoo.comWhile doing a security research on Yahoo Inc. systems, I decided to analyze its iOS apps and see how they were handled. Yahoo in general…Jul 12, 2017Jul 12, 2017
Uranium238sinWebSec CTFWebSec Nepal Official ResultsThis week from June 7, 2017 to June 8, 2017 a 24 hour CTF was conducted by WebSec CTF for Nepali hackers. Our goal was to train them and…Jul 8, 2017Jul 8, 2017
Uranium238sOrganizing a local CTF — my 2 centsCTF or also known as Capture the Flag competition in my opinion help security professionals or people interested in the field to challenge…Jul 3, 2017Jul 3, 2017