SpiderSec Profile Banner
spidersec Profile
spidersec

@SpiderSec

Followers
6K
Following
704
Media
83
Statuses
329

- Suvadip Kar

Down to Earth
Joined December 2016
Don't wanna be here? Send us removal request.
@SpiderSec
spidersec
6 years
HTTP Request Smuggling in one Screenshot. 🙂
Tweet media one
15
675
2K
@SpiderSec
spidersec
4 months
If you’re around for Black Hat Asia Singapore ( April 1-4 ), let’s catch up!.
0
0
2
@SpiderSec
spidersec
4 years
RT @payloadartist: ⚙️ A lesser known tool, Osmedeus is the closest to Nuclei, that comes with an amazing web UI. You can use custom YAML wo….
0
57
0
@SpiderSec
spidersec
4 years
Nice one!.
@sidxparab
Siddhesh Parab
4 years
Just Updated my Subdomain Enumeration Guide with new techniques, fixes, etc. Have a look 😊.Boost your Recon game !!🚀🚀. #bugbounty #infosec
Tweet media one
0
4
11
@SpiderSec
spidersec
4 years
RT @nnwakelam: This is fucking bananas and I can't believe I missed it.
0
78
0
@SpiderSec
spidersec
4 years
RT @J0hnnyXm4s: hashcat -w 4
Tweet media one
0
107
0
@SpiderSec
spidersec
4 years
RT @Dinosn: Exploiting Redis Through SSRF Attack
0
97
0
@SpiderSec
spidersec
4 years
RT @0x4148: Just created a working POC for CVE-2021-40444 with folks @EG_CERT
0
31
0
@SpiderSec
spidersec
4 years
RT @redragonvn: Our Pre-Auth RCE exploit for Atlassian Confluence (CVE-2021–26084) was leaked after reporting it to @VMware. They have refu….
0
392
0
@SpiderSec
spidersec
4 years
Hard work, new car 🙂🧘
Tweet media one
11
0
166
@SpiderSec
spidersec
4 years
RT @CySuite_: Yet another Account Takeover technique. Seperator:.email=victim@mail.com,hacker@mail.com.email=victim@mail.com%20hacker@mail….
0
162
0
@SpiderSec
spidersec
4 years
If ip based rate Limiting is implemented, you can block a legitimate user from accessing the website. Client-Ip: Victim-Ip-Address -> 500 request -> Blocked.
0
0
8
@SpiderSec
spidersec
4 years
This is mostly effective on : "Ip Based Rate Limiting".
1
0
6
@SpiderSec
spidersec
4 years
Rate Limiting Bypass : (429 Too many Requests). Append the headers to a request where the server is responding with 429. Client-Ip: IP -> 200.X-Client-Ip: IP -> 200.X-Forwarded-For: IP -> 200.X-Forwarded-For: 127.0.0.1, IP -> 200. IP = Random IP Address that you want to spoof. 🙂.
8
107
332
@SpiderSec
spidersec
4 years
Rick and morty 1000 years.
Tweet media one
6
3
75
@SpiderSec
spidersec
4 years
My grandfather, The late Dhananjay kar spent 14 years of his life in cellular Jail, infamously known as kalapani. The freedom of india didn't came so easily, we "the new generation" will never understand the struggle behind it. #IndependenceDay #IndiaAt75 #स्वतंत्रतादिवस
Tweet media one
12
6
132
@SpiderSec
spidersec
4 years
Happy independence day 🙌🏼
Tweet media one
0
1
25
@SpiderSec
spidersec
4 years
RT @h1pmnh: If you can get SpEL injection but can't get RCE, try exfiltrating a file with B64 encoding: T(java.util.Base64).getEncoder().en….
0
10
0
@SpiderSec
spidersec
4 years
RT @brutelogic: JS Payload w/o Parentheses #XSS. [].pop.constructor`alert\x281\x29```.
0
64
0
@SpiderSec
spidersec
4 years
RT @0xsapra: This is how I found sql-Injection 100% of the time.For /?q=1./?q=1'./?q=1"./?q=[1]./?q[]=1./?q=1`./?q….
0
673
0