Skip to main content

Posts

Featured

How I got 'Hall of fame' from Avalara security team?

My name is Mohsin Khan and I am a security researcher who learn things everyday, today I will explain how I got recognition from "Avalara security team" here i will explain everything like what tool and steps I used during my research. This is my one of the critical vulnerability finding which exposed email address,phone numbers, customer details and many sensitive information that can also be editable and anyone can also be add or delete. In this finding there is no rocket science, It just need a hacker mindset like how you observe things,There is no need to have programming knowledge for this exploit but only awareness how you can perform exploitation. So lets start what i did.. I used "Assetfinder tool" to get all subdomain of "avalara.com" by giving command ./assetfinder --subs-only avalara.com I got lots of subdomain then I saw a subdomain which looks interesting and that was "registration.avalara.com" and after opening this subdomain I got ...

Latest posts

How to secure myself online?

What search engine we should use for using Tor browser?

How do I file an online complaint for cyber crime?

How can I check whether my email is listed on the dark web or not?

What are the other ways other than doing an MTech to become an ethical hacker?

What are interesting facts, real stories, and incidences about Indian hackers?

What do you know that most people don’t?

What are some must have Android apps?

What can I learn/know right now in 10 minutes that will be useful for the rest of my life?

What are some good computer tricks that are not commonly known?