Amal Murali

Welcome.

My name is Amal Murali. I currently work as Manager, Security Operations at Bugcrowd. I’m interested in web application security and occasionally write about security and CTFs. You can learn more about me here.

Recent posts

All posts

CVE-2025-4664: Exploiting a Chrome 0day to Leak Session Tokens

A while ago, I stumbled across this intriguing tweet from security researcher Vsevolod Kokorin (@slonser_). The three-line snippet was almost boring - create an image element, point the src at a user-controlled URL, drop it into the DOM. In the replies of the …

This CTF is Still on IRC — IRCPuzzles 2024 Writeup

Cluelessly staring at a vague hint for hours, relentlessly going down multiple rabbit holes, the joy of finally finding a solution… what’s not to love? After all, this is fairly similar to a regular day in information security. I decided to check out this …

Pwning Tetris: Exploiting a Weak RNG

The challenge was hosted at this URL. Upon visiting the link, I was greeted with a game. At first glance, it resembled the familiar Tetris game, but something was noticeably off. Instead of the usual four blocks per piece, this game featured five. Curious …

Exploiting CVE-2024-32002: RCE via git clone

A new RCE in Git caught my attention on a recent security feed, labeled CVE-2024-32002. Given Git’s ubiquity and the widespread use of the clone command, I was instantly intrigued. Could something as routine as cloning a repository really open the door to …