Open in app
Home
Notifications
Lists
Stories

Write
jayateertha guruprasad
jayateertha guruprasad

Home

Published in InfoSec Write-ups

·Pinned

Grafana Admin Panel bypass in Google Acquisition(VirusTotal)

I started with usual subdomain recon of a google acquisition(VirusTotal).This time I used a online subdomain finder service https://subdomainfinder.c99.nl/ for finding subdomains quickly. Then I found a subdomain grafana.internal.virustotal.com ,The word internal in the subdomain made me visit that page due to my curiousity. But unfortunately ,It’s only for authorized…

Google Vrp

2 min read

Grafana Admin Panel bypass in Google Acquisition(VirusTotal)
Grafana Admin Panel bypass in Google Acquisition(VirusTotal)

May 6

2FA Bypass in PickMyCareer.in

I found a 2fa bypass recently in a responsible disclosure program — pickmycareer.in . The vulnerability allows an attacker to register any mobile number with his account bypassing OTP verifications. The process is very simple during registration process, attacker gives his own mobile number and receives OTP, enters correct OTP…

Hacking

2 min read

2FA Bypass in PickMyCareer.in
2FA Bypass in PickMyCareer.in

Apr 15

How I passed my CEH (Practical) in first attempt

First of all, I am not a complete beginner in infosec/cyber security community. I have been doing bugbounty for past 3 years and also my current job role is related to security engineer. So, I haven’t prepared much as I already use most of the tools frequently at my workplace/CTFs/BugBounty. …

Infosec

2 min read

How I passed my CEH (Practical) in first attempt
How I passed my CEH (Practical) in first attempt

Feb 25, 2021

Jira Auth Bypass bug in Google Acquisition (Apigee)

I was looking for blogs on GoogleVRP reports as well as noting down it’s popular aquisitions. Then I found a blog (https://tutorgeeks.blogspot.com/2018/08/misconfigured-jira-setting-apigee.html ) which talks about unauthenticated Jira instance leaking dashboard name ,project title and user profile picture by applying filters. It also mentions ,the website supports only logging in…

Infosec

2 min read

Jira Auth Bypass bug in Google Acquisition (Apigee)
Jira Auth Bypass bug in Google Acquisition (Apigee)

Dec 17, 2020

Download Filename Manipulation due to improper rendering of RTLO characters

This is one of the easiest bug that I have found in a private bugbounty program. The program had two of it’s browsers in it’s scope. I was testing for RTLO related bugs,I found that the downloads section of the browser was rendering the rtlo characters in the improper way. …

Bug Bounty

2 min read


Apr 21, 2020

CORS bug on GOOGLE’s 404 page REWARDED!!!

This is a story of CORS bug that I found in one of Google’s aquisition -Kaggle,Where I got rewarded for CORS bug in 404 page. One fine day I was looking at one of the aquisitions of Google-(Kaggle),Kaggle is used worldwide by Machine Learning community and is pretty famous. I…

Bug Bounty

3 min read

CORS bug on GOOGLE’s 404 page  REWARDED!!!
CORS bug on GOOGLE’s 404 page  REWARDED!!!

Apr 9, 2020

WhatsApp Profile Photo Leakage Bug

If You think WhatsApp is totally safe and your Profile Picture is visible to people only in your contacts or depending on your privacy settings then you are totally wrong. I found a bug in WhatsApp through which any 3rd Party App with only read Storage Permission can access your…

Bug Bounty

4 min read

WhatsApp Profile Photo Leakage Bug
WhatsApp Profile Photo Leakage Bug

Sep 15, 2019

GOOGLE REFERER LEAK BUG

This is a low hanging bug ,I discovered in Google ,This blog is going to be to short and to the point. I followed the usual Recon process after enumerating subdomains , I selected https://datastudio.google.com.I tried to check for popular vulnerabilities XSS,CSRF,SSRF and What not!!! But couldn’t find anything .Then…

Security

1 min read

GOOGLE REFERER LEAK BUG
GOOGLE REFERER LEAK BUG

Apr 10, 2019

Multiple xss in *.skype.com (2)

PART 2: So If you have read the part 1, You would have seen that I found a stored-self Xss in manager.skype.com which was getting escalated in the option(“make the USER as admin of group_name”) as group_name was not properly sanitized there. Here’s what I did to affect other users,You…

Security

2 min read

Multiple xss in *.skype.com (2)
Multiple xss in *.skype.com (2)

Apr 10, 2019

Multiple xss in *.skype.com

PART 1: To keep it simple ,I want to make this blog to the point ,instead of writing a script for MahaBharath !!! How It all started? I was thinking of services provided by microsoft, Skype came to my mind. I tested out skype but couldn’t find anything ,Then after…

Security

2 min read

Multiple xss in *.skype.com
Multiple xss in *.skype.com
jayateertha guruprasad

jayateertha guruprasad

Following
  • Vickie Li

    Vickie Li

  • Ashish Jha

    Ashish Jha

  • Sergey Kashatov

    Sergey Kashatov

  • Eray Mitrani

    Eray Mitrani

  • Frans Rosén

    Frans Rosén

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable