Open in app

Sign In

Write

Sign In

Jatin Nandwana
Jatin Nandwana

85 Followers

Home

About

Apr 28, 2021

A tale of Html to Pdf converter ssrf and various bypasses

Hey hackers, hope you are all doing good in this pandemic, this is a story of a ssrf I found in a private program through the html to pdf converter functionality and was able to read internal files, aws metadata and some internal debug ports with juicy customer information. …

Bug Bounty

5 min read

A tale of Html to Pdf converter ssrf and various bypasses
A tale of Html to Pdf converter ssrf and various bypasses
Bug Bounty

5 min read


Jul 12, 2020

Self stored xss to full account takeover

Hey, Today I will share you my recent finding which was a self xss but I turned it into a full account takeover using various other misconfigurations and features already available on the website. EXPLOITATION SCENARIO : Self stored xss Google login csrf to good xss Logout of attacker account …

Bug Bounty

5 min read

Bug Bounty

5 min read


Mar 5, 2020

My OSCP story

My OSCP story So it all began in 2018 when I saw this certification on the internet which seemed like a challenging one and a good entry level pentesting certification. So I set a goal for myself that I want to achieve it in end of 2019. …

Oscp

5 min read

Oscp

5 min read


Jul 4, 2019

Story of a stored xss to full account takeover vulnerability(N/A to accepted)

Story of a stored xss to full account takeover vulnerability(N/A to accepted) Hey everyone, This is one of my most best finds ever which took me some days to exploit but when I finally exploited it, it was the best feeling in the world!! So lets begin, I got a…

JavaScript

6 min read

Story of a stored xss to full account takeover vulnerability(N/A to accepted)
Story of a stored xss to full account takeover vulnerability(N/A to accepted)
JavaScript

6 min read


Jun 2, 2019

Story of a uri based xss with some simple google dorking

Story of a uri based xss with some simple google dorking Hey everyone, This is a old xss bug which I found in a private program on hackerone by doing some google recon. Because it was a private program I will the name the site as www.example.com everywhere. So lets…

Security

2 min read

Security

2 min read


Aug 25, 2018

My first valid xss(@Hackerone)

Hey today I will share my first ever valid xss bug which was a reflected xss on a public program on hackerone. So lets start, I was very new to hackerone and I took a random program to start and I started to do some recon by finding the subdomains…

Security

2 min read

Security

2 min read

Jatin Nandwana

Jatin Nandwana

85 Followers

Web application pentester

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech