My name is Amal Murali. I currently work as Manager, Security Operations at Bugcrowd. I’m interested in web application security and occasionally write about security and CTFs. You can learn more about me here.
A while ago, I stumbled across this intriguing tweet from security researcher Vsevolod Kokorin (@slonser_). The three-line snippet was almost boring - create an image element, point the src at a user-controlled URL, drop it into the DOM. In the replies of the …
Google CTF releases some really cool challenges every year. This year was no exception. onlyecho was one of the relatively easier ones, but it ended up being a lot of fun to solve. I was intrigued by the challenge and decided to dive right in.
Cluelessly staring at a vague hint for hours, relentlessly going down multiple rabbit holes, the joy of finally finding a solution… what’s not to love? After all, this is fairly similar to a regular day in information security. I decided to check out this …
The challenge was hosted at this URL. Upon visiting the link, I was greeted with a game. At first glance, it resembled the familiar Tetris game, but something was noticeably off. Instead of the usual four blocks per piece, this game featured five. Curious …
A new RCE in Git caught my attention on a recent security feed, labeled CVE-2024-32002. Given Git’s ubiquity and the widespread use of the clone command, I was instantly intrigued. Could something as routine as cloning a repository really open the door to …