InQuince TechbyAvinash Jain (@logicbomb)·Feb 13Beyond Checkboxes: How Quince Reinvented Vendor Security AssessmentsWhen the Weakest Link Isn’t Human, It’s Your Vendor
Avinash Jain (@logicbomb)·Oct 27, 2022A bug worth 1.75Lacs — AWS SSRF to RCEHow I escalated well known AWS SSRF to perform Remote Code Execution (RCE) in one of the India’s growing startups.A response icon4A response icon4
Avinash Jain (@logicbomb)·Feb 2, 2022A misconfigured Apache Airflow to AWS Account CompromiseThis is about how I was able to exploit a security misconfig of Apache Airflow and escalated it to access sensitive pages & credentials!
Avinash Jain (@logicbomb)·May 18, 2021Shift Left with AWS Codepipleine — Scanning every single code changeIn the agile world, where continuous iteration of development and testing happens throughout the SDLC (software development lifecycle)…
Avinash Jain (@logicbomb)·Jan 27, 2021OTP Bypass Account Takeover to Admin Panel — Ft. Header InjectionIt looks like this year has great promises at least the starting is good. Already 3 bug bounty in the pipeline(just showing off:P) and…A response icon2A response icon2
Avinash Jain (@logicbomb)·Nov 17, 2020Tale of 3 vulnerabilities to account takeoverThe whole writeup in 1 liner, I bypassed the rate limiting by bypassing cloudflare by reaching to orgin sever IP via SSRF xmlrpc.php…A response icon2A response icon2
Avinash Jain (@logicbomb)·Oct 7, 2020Securing Container using Threat Modelling— STRIDEThe increased adoption of containers has given rise to a wide range of potential threats to microservices apps that run in containers. If…
InLambda by BlinkitbyAvinash Jain (@logicbomb)·Jul 29, 2020How Continuous Github Code Hacking Keeps Grofers SecureSecurity shouldn’t be treated as an after-thought.
Avinash Jain (@logicbomb)·May 28, 2020Phone Number Privacy? We don’t do that here: Google Hangout CallGoogle Hangout Calls and Exposing Phone NumbersA response icon1A response icon1
Avinash Jain (@logicbomb)·Apr 9, 2020Docker Registries and their secretsNever leave your docker registry publicly exposed! Recently, I have been exploring dockers a lot in search of misconfigurations that…