Rohit kumar·Jan 28, 2025Opengrep : A Hype and Marketing Gimmick, let’s rename it to Privategrep.Recently, OpenGrep made headlines as a new open-source project touted as a “revival” of static application security testing (SAST) tools…
Rohit kumar·Jun 16, 2023Detecting, Fixing, and Defending Against XXE Attacks in Python and JavaIntroduction:
Rohit kumar·Jun 11, 2023How to Detect and Mitigate SSRF Vulnerabilities in the Early Coding Cycle: A Comprehensive GuideIntroduction:
Rohit kumar·May 20, 2021CSRF from which we can create a support ticket in Victim’s Account (500$)Complete Details ===11
Rohit kumar·May 20, 2021Victim’s Anti CSRF Token could be exposed to Third-party Applications installed on user’s Device…Complete Details === During my investigation, I found that a user’s DTSG token can be exposed to a third-party application because of a…
Rohit kumar·Aug 31, 2020Page shops with a hidden Product in “Featured product section” which could be controlled by…Product Area
Rohit kumar·Jun 5, 2020[IDOR] Delete saved credit cards from any Business Manager Account.Business manager is having an option to add and manage credit cards. However, this functionality is limited to authorized “Admins” of that…
Rohit kumar·May 2, 2020Private Dashboards were accessible by other Admins in Analytics DashboardPrivate dashboards can be accessed by other Admins, which leads to sensitive data exposure.
Rohit kumar·Oct 12, 2019Whitehat test accounts can act as Hidden Admin with Business manager / Ad Accounts.Again this will be a copy/paste of my whole report nothing fancy gifs and memes in this report 😐
Rohit kumar·Aug 15, 2019ByPassing fix of Domain Blocking feature in Business ManagerA few months back I reported this vulnerability Demoted business admin could apply blocklist to all ad accounts and FB rewarded me 500$…