mallocsys Profile Banner
Rojan Rijal Profile
Rojan Rijal

@mallocsys

Followers
931
Following
74
Media
13
Statuses
57

Offensive security research & building @OphionSecurity

Joined May 2019
Don't wanna be here? Send us removal request.
@mallocsys
Rojan Rijal
3 months
I just got access to an attacker's daily diary. Here is what I learned ๐Ÿ‘‡. ๐Ÿ•˜ 9:00 AM: Clock in. ๐Ÿ”Ž 9:12 AM: Google Dork says is still alive. ๐Ÿ˜Ž 9:30 AM: No rate limits, no auth. Just vibes. ๐Ÿ—ƒ 10:00 AM: Dumped staging DB from
0
0
0
@mallocsys
Rojan Rijal
5 months
I hacked UberEats in 2017. Here is the story. #ubereats #hacking #uber #cybersecurity #bugbounty
2
0
1
@grok
Grok
22 days
"A medieval knight in full armor riding a motorcycle through a misty jungle trail.". Try Grok Imagine, free for a limited time.
514
891
4K
@mallocsys
Rojan Rijal
5 months
It was amazing to present at @_kernelcon_ today. Thank you for the gift KernelCon team! #kernelcon #offensivesecurity #researchontheroad
Tweet media one
0
0
4
@mallocsys
Rojan Rijal
5 months
๐Ÿ’ฅ Q1 Update from the Field: Real-World Hacking with Orion ๐Ÿ’ฅ . In Q1, we pointed Orion, our offensive Attack Surface Management platform, at a large enterprise to see what it could uncover. The results speak for themselves: .๐Ÿ” ๐Ÿต ๐˜ƒ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐—ถ๐—ฒ๐˜€ ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฒ๐—ฑ.
0
0
2
@mallocsys
Rojan Rijal
5 months
RT @uraniumhacker: We are doing #VibeSecurityForAI. If you are an AI startup (pre-seed or seed ) we will test your application for free. Weโ€ฆ.
0
1
0
@mallocsys
Rojan Rijal
6 months
Not yet a full multiplayer but doing some basic "Simon Says" style game with increasing difficulties. Will add leaderboard style system soon. Open to ideas to improve it further @levelsio
taptastic.app
Test your memory with Taptastic!
0
0
0
@mallocsys
Rojan Rijal
6 months
tj-actions compromise is a great reminder that pinning the action/dependency to a commit SHA instead of a version tag is safer and securer. We monitor repositories of some public organizations, and most of them are safe because they use a SHA like.
@charliermarsh
Charlie Marsh
6 months
Oh wow, a popular GitHub Action (tj-actions/changed-files) was fully compromised. Someone committed a base64-encoded payload that runs a script that in turn prints out encoded secretsโ€ฆ. Stay safe out there!.
0
0
4
@mallocsys
Rojan Rijal
6 months
๐Ÿšจ Continuous Monitoring Prevents Million-Dollar Breaches ๐Ÿšจ. In cybersecurity, threats evolve but so should our defenses. At Ophion Security, we continuously monitor Fortune 500 companiesโ€™ public assets not just domains and IPs, but also SaaS services, cloud assets, and web.
0
0
2
@mallocsys
Rojan Rijal
6 months
I reached level 11 in Taptastic! ๐ŸŽฎ. Final speed: Super Fast.Tiles: 9. The pattern that defeated me: ๐ŸŸฉ ๐ŸŸจ ๐ŸŸจ ๐ŸŸจ ๐ŸŸฆ ๐ŸŸฆ ๐ŸŸฆ ๐ŸŸจ ๐ŸŸฆ ๐ŸŸฉ ๐ŸŸฉ ๐ŸŸจ. Can you beat my score? #Taptastic #memorygame #challenge
taptastic.app
Can you beat the Taptastic score of 11?
0
0
1
@mallocsys
Rojan Rijal
6 months
๐Ÿงต Securing Your @DecagonAI Chat Bot ๐Ÿงต. We've seen a growing number of organizations using s chat bot to enhance customer support with AI. A quick post on how to make sure you deploy it securely based on a recent issue we saw. ๐Ÿšจ The issue?.If.
0
0
0
@mallocsys
Rojan Rijal
6 months
Announcing: Ask Us Anything Security - A free security advisory for startups . Security often gets pushed to the back burner at startups until something breaks or a big deal requires it. But what if you could get expert security guidance without the overhead? . At Ophion.
0
0
1
@mallocsys
Rojan Rijal
7 months
RT @OphionSecurity: Live chat histories contain treasure trove of data. From answers to security questions to credentials and more. We founโ€ฆ.
Tweet card summary image
ophionsecurity.com
In July 2024, we identified a vulnerability that resulted in access to millions of live customer support messages for organizations using Cisco Webex Connect.
0
1
0
@mallocsys
Rojan Rijal
8 months
As we build Orion actively, we run it against real world targets with disclosure policy. We did the same for Microsoft. Checkout the demo page to see how we are monitoring more than 4,000 users and 160,000 repositories of Microsoft and other organizations.
0
0
1
@mallocsys
Rojan Rijal
8 months
RT @0xdabbad00: I looked at all the AWS OIDC integrations I could find to identify how they might be misconfigured and to understand the vaโ€ฆ.
Tweet card summary image
wiz.io
Secure AWS OIDC integrations by avoiding common misconfigurations. Discover key IAM trust policy conditions for popular SaaS vendors to protect your cloud.
0
26
0
@mallocsys
Rojan Rijal
9 months
๐ŸฆŠ๐ŸŒŠ Proud to have contributed to a safer digital world in 2024! 23 vulnerabilities reported, including 9 critical findings. Special thanks to @Hacker0x01 for providing the platform to make this impact possible. Here's to more secure systems in 2025! ๐Ÿ”’ #BugBounty #CyberSecurity.
0
0
6
@mallocsys
Rojan Rijal
10 months
Ahhh yeah the classic top tier boxing move. the hug is back. #NetflixFight #TysonPaul.
0
0
0
@mallocsys
Rojan Rijal
10 months
With HackerOne's Scotland Live Hacking Event now slowly wrapping up, I am excited to have had the opportunity to participate this time. I focused primarily on hacking AWS while collaborating on it with @itscachemoney. Currently, we are ranked in the top 10 for AWS based on our
Tweet media one
1
3
34
@mallocsys
Rojan Rijal
10 months
One of the best part of security research that I love is that it exposes you to learn about different technologies. Randomly, I have learned about different techs that I can reference and help tell organizations how to setup the product like I am an expert on it.
0
0
10