
Amal Murali
@amalmurali47
Followers
2K
Following
1K
Media
66
Statuses
2K
Manager - Security Operations at @Bugcrowd. Interested in Information Security. BBAC certified. Opinions are my own. He/him.
India
Joined May 2010
Just published a blog post about this Chrome 0day discovered by @slonser_. It covers how the exploit works, a demo setup simulating a common ATO scenario (with video), and the PoC GitHub repo.
amalmurali.me
A while ago, I stumbled across this intriguing tweet from security researcher Vsevolod Kokorin (@slonser_). The three-line snippet was almost boring - create an image element, point the src at a...
Today I used a technique that’s probably not widely known in the community. In what cases could code like this lead to a vulnerability? ->
2
32
143
RT @sw33tLie: Super glad to have collaborated on @albinowax’s research this year with @bsysop and @_medusa_1_. Funny enough, it all started….
0
6
0
RT @albinowax: The whitepaper is live! Learn how to win the HTTP desync endgame. and why HTTP/1.1 needs to die:
http1mustdie.com
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
0
238
0
Just completed 4 years at @Bugcrowd! How time flew!. Thankful to the incredible team I get to work with every day, and of course, the researcher community :). #ItTakesACrowd.
9
1
98
If you’re curious, I highly recommend checking out the @ctbbpodcast episode about this bug too. @rez0__ and @Rhynorater did a great job at covering everything from the timeline to the additional attack vectors!.
0
0
3
This is really cool! Amazing work @S1r1u5_. First time seeing DNS rebinding used to bypass SOP in a real-world crit! Very clever.
Hacking Windsurf: I asked the AI for the shell, it said yes. new video’s out. I show how I could’ve hacked you… just by getting you to click my link. Link posted below.
0
0
1
RT @VolerionSec: Launching today!. Volerion transforms raw CVEs into structured and instant insights. #CVE #CyberSecurity #infosec
https://….
0
17
0
Great writeup, @Rhynorater and @0xLupin!.
In a few hours we are going to release a new article with @Rhynorater. We hacked Google’s A.I Gemini and leaked its source code (at least some part). I'm so excited to release this one ! Huge thanks to @GoogleVRP for the help coordinating the disclosure 🔥
0
0
2
Some personal news: I was promoted to Manager - Security Operations at @Bugcrowd back in November!. Huge shoutout to my fantastic team at Bugcrowd and our researcher community! :).
13
1
122
RT @PortSwiggerRes: The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
portswigger.net
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
0
297
0
Something that made my day recently. While going through @ippsec's recent video for an HTP box he was solving, I noticed he came across my git RCE analysis during his research. As someone who's learned a ton from his HTB content, that was unexpectedly cool to see! :D
3
11
177
RT @albinowax: I've just hit ten years of web security research at PortSwigger! Massive thanks to @PortSwigger for the opportunity, and the….
0
19
0
So cool!.
What can an 8-year-old build in 45 minutes with the assistance of AI?. My daughter has been learning to code with @cursor_ai and it's mind-blowing🤯. Here are highlights from her second coding session. In 45 minutes she built a chatbot powered by @CloudflareDev Workers AI 👀
0
0
2
RT @GithubProjects: | ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄|.| Don't Push To Production On Friday |.|_________________|. \ (•◡•) /….
0
16K
0
RT @sw33tLie: This is one of the most widespread and impactful bugs I've ever found in my career. Great collab with @bsysop and @_medusa_1_….
0
68
0
Had fun with some Google CTF challenges last weekend! Published a writeup for one that I really enjoyed solving:. . #ctf #writeup #GoogleCTF.
amalmurali.me
Google CTF releases some really cool challenges every year. This year was no exception. `onlyecho` was one of the relatively easier ones, but it ended up being a lot of fun to solve. I was intrigued...
4
5
33
Ever played a CTF on IRC? . I published a detailed walkthrough for all the 22 challenges in @ircpuzzles 2024. Check it out here: It's almost a book at this point, so please use the table of contents to find what interests you!. #ircpuzzles #ctf #puzzle.
amalmurali.me
Cluelessly staring at a vague hint for hours, relentlessly going down multiple rabbit holes, the joy of finally finding a solution... what's not to love? After all, this is fairly similar to a...
0
0
3