
pranav
@zerodaywo1f
Followers
280
Following
1K
Media
19
Statuses
604
offensive security • research
Joined March 2015
Excited to share I've been awarded a $$$$ bounty 💰 on @Hacker0x01 for critical vulnerabilities, now ranked as #1 🥇 Top Hacker in the program! 😄 💡Tip: Dive into JS files, automation isn't all. Extract URLs 🌐, fuzz for hidden parameters 🔎 #BugBounty #BugBountyTips #InfoSec
12
12
151
I admitted my son to a hospital today. I have a ₹1.2 crore Acko Platinum Health Plan the one with no room rent limit. @ACKOIndia @duavarun Guess what? The hospital flat out denied me a suite room. 👇🏻
1K
4K
17K
Recently ran an experiment and found out how alarmingly easy it was to compromise users via npm lifeycycle hooks. Read about it here - https://t.co/4dwAWtjiAA
#supplychain #security #opensource #npm #hacking
zerodaywolf.sh
How attackers weaponize npm to make organizations weep and how my experiment opened my eyes to the fragility of the open source ecosystem. Supply chain security …
0
0
1
I recently upgraded my homelab from a single-node cluster to a multi node k3s cluster. Check out the blog: https://t.co/0vnXoYRaKv
#kubernetes #cilium #gitops #cloud #k3s
zerodaywolf.sh
Ever feel like your single-node cluster is just…lonely? I ditched kubeadm for a multi-node K3s party, wired it up with GitOps, MetalLB, Tailscale, and Cilium, …
1
0
1
Block ads & trackers on Android 11+ natively using Private DNS. I've been experimenting with public DNS providers which block annoying ads & trackers and I think the best one is https://t.co/9IglZAFM7v . Haven't seen any app crashes for a while. LMK if you know a better one.
adguard-dns.io
Create your ad-blocking DNS server that will protect your personal data, prevent tracking and allow you to control access to specific content on the Internet.
0
0
1
I've been having a blast solving the Wiz Ultimate Cloud Security Championship challenges! I haven’t touched CTFs in quite a while, but jumping back in has been such a breath of fresh air. Thank you @wiz_io for the cool challenges! https://t.co/soj5ZtsQU7
1
0
10
Reading chromium bug reports gives me peace. I don't know why and I don't know how.
0
0
0
Today, Linus Torvalds told a Google engineer that his code (updating RISC-V support in the Linux kernel) is “garbage” which “makes the world actively a worse place to live”. Adding that the Google engineer’s code needs to “get bent”. As you might have guessed, Torvalds has
844
1K
18K
All the blogs I want to read are finally organized on my reader. Glad I stumbled upon https://t.co/laQgymY51f. This is a neat solution to not give out your email to newsletters. Plus I no more have to scroll through my email to look for any latest tech news I missed out on.
0
0
0
I enjoy debugging problems and decided to document them —
zerodaywolf.sh
I enjoy troubleshooting problems and decided to document it for fun.
0
0
0
TIL Google Docs has a feature to paste as markdown and have it rendered automatically. One of the best features so far.
1
0
2
Spent two full days troubleshooting with ChatGPT but didn’t get anywhere. Took half a day to dig into the docs and troubleshoot it myself—just like the old days—and I’m happy to say my Pi-hole DNS on k8s is finally reachable on my Tailnet 😄
0
0
2
| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄| | Don't Push To Production On Friday | |_________________| \ (•◡•) / \ / —— | | |_ |_
416
16K
77K
@thebinarybot Bypasses for the following WAFs: Amazon Web Services WAF Cisco Secure WAF Cloudflare Web Application Firewall Citrix Netscaler F5 BIG-IP Advanced WAF Fortinet's Fortiweb WAF Akamai Web Application Firewall Sophos Firewall Broadcom Radware https://t.co/DVzulEOorZ
0
1
9
When bug bounty hunting, assume you are blocked by a WAF. What are the common ways you can evade WAF and continue hunting? Curious to know? Checkout this thread 👇🧵
3
32
151
These resources are all you need to become at least an intermediate level Smart Contract Security Researcher🧐 When I started learning I wasn't lucky enough to have these resources. But now you have it and should take advantage. Let's take a look at them👇🏼
4
17
92
Get Ready with Your AWS Accounts because @Zero0x00 @abhicarmel and me will be delivering training @seasides_conf on 21 September. "Fundamentals of attacking and defending AWS" Attached is a clip of what you can expect at our training. https://t.co/3fKTarlm4M
#cloudsecurity
3
18
37
We found two 0-day vulnerabilities in @Ubuntu kernel and it all started by reading descriptions of old CVEs 📖 Thread about the discovery of #GameOverlay 🧵👇🏼
14
443
2K