Amal Murali Profile
Amal Murali

@amalmurali47

Followers
2K
Following
1K
Media
66
Statuses
2K

Manager - Security Operations at @Bugcrowd. Interested in Information Security. BBAC certified. Opinions are my own. He/him.

India
Joined May 2010
Don't wanna be here? Send us removal request.
@amalmurali47
Amal Murali
1 month
Just published a blog post about this Chrome 0day discovered by @slonser_. It covers how the exploit works, a demo setup simulating a common ATO scenario (with video), and the PoC GitHub repo.
Tweet card summary image
amalmurali.me
A while ago, I stumbled across this intriguing tweet from security researcher Vsevolod Kokorin (@slonser_). The three-line snippet was almost boring - create an image element, point the src at a...
@slonser_
slonser
3 months
Today I used a technique that’s probably not widely known in the community. In what cases could code like this lead to a vulnerability? ->
Tweet media one
2
32
143
@amalmurali47
Amal Murali
5 days
RT @sw33tLie: Super glad to have collaborated on @albinowax’s research this year with @bsysop and @_medusa_1_. Funny enough, it all started….
0
6
0
@amalmurali47
Amal Murali
5 days
RT @albinowax: The whitepaper is live! Learn how to win the HTTP desync endgame. and why HTTP/1.1 needs to die:
Tweet card summary image
http1mustdie.com
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
0
238
0
@amalmurali47
Amal Murali
22 days
Just completed 4 years at @Bugcrowd! How time flew!. Thankful to the incredible team I get to work with every day, and of course, the researcher community :). #ItTakesACrowd.
9
1
98
@amalmurali47
Amal Murali
1 month
If you’re curious, I highly recommend checking out the @ctbbpodcast episode about this bug too. @rez0__ and @Rhynorater did a great job at covering everything from the timeline to the additional attack vectors!.
0
0
3
@amalmurali47
Amal Murali
2 months
This is really cool! Amazing work @S1r1u5_. First time seeing DNS rebinding used to bypass SOP in a real-world crit! Very clever.
@S1r1u5_
s1r1us
2 months
Hacking Windsurf: I asked the AI for the shell, it said yes. new video’s out. I show how I could’ve hacked you… just by getting you to click my link. Link posted below.
Tweet media one
0
0
1
@amalmurali47
Amal Murali
2 months
RT @VolerionSec: Launching today!. Volerion transforms raw CVEs into structured and instant insights. #CVE #CyberSecurity #infosec https://….
0
17
0
@grok
Grok
16 hours
"A girl in a flowing white dress floating gracefully into a dreamy sky filled with stars and colorful clouds at sunset.". Try Grok Imagine, free for a limited time:.
14
7
81
@amalmurali47
Amal Murali
2 months
At this point, I’m very excited about how AI is going to transform our lives in the future.
0
0
2
@amalmurali47
Amal Murali
4 months
The Wire may be one of my all-time favorite shows. Surprised I didn't watch it sooner, but now I'm sad it ended.
1
0
1
@amalmurali47
Amal Murali
5 months
Great writeup, @Rhynorater and @0xLupin!.
@0xLupin
Lupin
5 months
In a few hours we are going to release a new article with @Rhynorater. We hacked Google’s A.I Gemini and leaked its source code (at least some part). I'm so excited to release this one ! Huge thanks to @GoogleVRP for the help coordinating the disclosure 🔥
Tweet media one
0
0
2
@amalmurali47
Amal Murali
5 months
Some personal news: I was promoted to Manager - Security Operations at @Bugcrowd back in November!. Huge shoutout to my fantastic team at Bugcrowd and our researcher community! :).
13
1
122
@amalmurali47
Amal Murali
7 months
In case you want to check it out:. Blog post: YouTube video: HTB box:
0
0
7
@amalmurali47
Amal Murali
7 months
Something that made my day recently. While going through @ippsec's recent video for an HTP box he was solving, I noticed he came across my git RCE analysis during his research. As someone who's learned a ton from his HTB content, that was unexpectedly cool to see! :D
Tweet media one
3
11
177
@amalmurali47
Amal Murali
10 months
RT @albinowax: I've just hit ten years of web security research at PortSwigger! Massive thanks to @PortSwigger for the opportunity, and the….
0
19
0
@amalmurali47
Amal Murali
1 year
So cool!.
@rickyrobinett
Ricky
1 year
What can an 8-year-old build in 45 minutes with the assistance of AI?. My daughter has been learning to code with @cursor_ai and it's mind-blowing🤯. Here are highlights from her second coding session. In 45 minutes she built a chatbot powered by @CloudflareDev Workers AI 👀
0
0
2
@amalmurali47
Amal Murali
1 year
RT @GithubProjects: | ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄|.| Don't Push To Production On Friday |.|_________________|. \ (•◡•) /….
0
16K
0
@amalmurali47
Amal Murali
1 year
RT @sw33tLie: This is one of the most widespread and impactful bugs I've ever found in my career. Great collab with @bsysop and @_medusa_1_….
0
68
0
@amalmurali47
Amal Murali
1 year
Ever played a CTF on IRC? . I published a detailed walkthrough for all the 22 challenges in @ircpuzzles 2024. Check it out here: It's almost a book at this point, so please use the table of contents to find what interests you!. #ircpuzzles #ctf #puzzle.
Tweet card summary image
amalmurali.me
Cluelessly staring at a vague hint for hours, relentlessly going down multiple rabbit holes, the joy of finally finding a solution... what's not to love? After all, this is fairly similar to a...
0
0
3