Imran Parray(@imranparray101) 's Twitter Profileg
Imran Parray

@imranparray101

Founder - @snap_sec

ID:865990152446853121

linkhttps://snapsec.co calendar_today20-05-2017 17:58:36

2,6K Tweets

5,8K Followers

673 Following

Imran Parray(@imranparray101) 's Twitter Profile Photo

Introducing SnapSec's advanced vulnerability management system!

Say goodbye to tedious PDF reports from vendors.

Our innovative solution centralizes collaboration, consultation, and prioritization for hassle-free security management.

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

During the presentation, I introduced a highly structured approach to discover 'Privilege Escalation and Access Control issues' in modern Web applications.

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

Discovering Log4shell & 5 privilege escalations on Agorapulse.

Check out our blog post for the full details: snapsec.co/blog/Hacking-A…

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

Writing blogs is a time-consuming task, and anyone who invests their time in writing them deserves appreciation and gratitude.

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

5 Tips to Find DOM based XSS Vulnerabilities

1) Manual Code Review to look for sources and sinks
2) Using DOM invader by PortSwigger
3) Look for User Controlled Inputs
4) Taint Analysis
5) Parameter Manipulation

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

Just wrapped up a short but insightful podcast with VAIDIK PANDYA ! We covered key topics like:

💻 Infosec entry points
🐛 Bug bounty hunting vs penetration testing
📚 Advice for newcomers to appsec

Check out the full video here: youtu.be/P3ZtUVi0OvE

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

The file upload functionalities in web apps continue to be one of the most vulnerable features.

Read out blogpost to discover 10 distinct attacks that can be use to exploit file upload vulnerabilities in your web applications.

snapsec.co/blog/Attacking…

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

It is important for Bug Bounty platforms to require that both researchers and triagers engage in discussions that are informed and based on reasoning from both sides.

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

One of the aspects of that I dislike is when triagers or program owners lower the severity of a report without providing any explanation.

Things could have been much easier if they would have been obliged to add some explanation to why they are doing so.

account_circle
Snap Sec(@snap_sec) 's Twitter Profile Photo

Cybersecurity threats are increasingly prevalent and dangerous. Preventing and mitigating these threats require proactive steps like educating employees, regular assessments and testing, strong access controls etc

Cybersecurity threats are increasingly prevalent and dangerous. Preventing and mitigating these threats require proactive steps like educating employees, regular assessments and testing, strong access controls etc #cybersecuritytips #pentesting #infosec
account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

Ramadan Mubarak to all the Muslims around the globe.

May this holy month of Ramadan bring you peace, blessings and happiness.

2023

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

Cloudclear is an automated tool designed to receive a list of domains as input and then identify and remove all the domains that have cloudflair and cloudfront protection.

account_circle
Imran Parray(@imranparray101) 's Twitter Profile Photo

After dealing with Spread sheets for almost 3 years now, i came to a conclusion that tsv format is far better than csv.

account_circle