कलाको प्रस्फुटित हुने अचम्मको तरिका छ। तहै-तहले लुकेको छ – भाषाको तह, कलम अनि मशीको तह, क्यानभासको तह । त्यो अभिव्यक्ति खोतलेपछी सुनिन्छ, प्यास तृप्तहुँदाको अनुभव – भलै सेकेन्ड ह्यान्ड किन नहोस। मर्म भने बिलाएर जानछ, रहन्छ त बस् संदेश – जाऊ आफै घुट्की लेउ, प्यास मेटाउ, मेरो तृप्तिको उधारो अनुभव प्रेरणा बनोस तिम्रो आफ्नै… Continue reading अभिव्यक्ति
Author: Abhikaf
बराला
आज दिउँसो हिंडीरहेंथ्ये, उद्देश्यहीन भएर, बराला हुनुको अर्थ बुझ्न – अर्को भाषामा आंफैभित्र नियाल्न । सुरुवात भने बाहिरी हेराईबाट प्रेरित भयो । हाँसहरु पानीमा निश्चल रुपमा पौडीरहँदा म नजीक आएको देखेपछि बेजोडसँग उडेको दृश्यले दङ्ग बनायो । बथान निकै माथिसम्म उड्ने रहेछन । सधैँ आफुपछाड़ीको झाडीबाट खस्याक-खुसुक हुँदा आफ्नो हिंडाइ तीब्र बनाउने खुट्टाहरुलाई रोकेर, फर्केर… Continue reading बराला
मैले आज लेखिन
m मलाई स्वीकार्य छ – मेरो सिर्जनात्मक शक्तिको अल्पता। मलाई स्वीकार्य छ – मेरो कल्याणिकीको सीमितता। मलाई स्वीकार्य छ – बहुलट्रोपनमा डुबेर लेखिएका मेरा शब्दहरूको निस्सारता। मलाई स्वीकार्य छ – मैलेले जकडिएको खनिजुरूपी सोचबाट टिलिक्क टल्केको धातुरूपी सहज सिर्जनसिलता नखाने फगत प्रयासहरू। किनकी पिकाशो एक रातमा जन्मेनेन्। देवकोटा भिखारी देखि मन्त्रीसम्म हुँदा बल्ल मार्मिक सिर्जनाको… Continue reading मैले आज लेखिन
Deleting/Modifying Google Drive file with Read only access
Read only permission (which is all the drive applications) could have deleted and updated your files.
Entry Level Information Security Questions mind-map
Throughout last year, I interviewed with more than 12 companies for an entry level infosec related position. Most of the positions were advertised as general infosec/appsec related positions. I have created a mind-map summarizing the most frequent categories and some sample questions.
Opera URL Spoofing POC
Following is the POC for CVE 2016-4075: The POC is here The issue has been reported and fixed.
Modifying/Deleting Google Drive files
This is a short write up of a bug in OAuth 2.0 implementation of Google API. This bug could have allowed an application to delete/write on user’s any of the file(s) in google drive, although the user permitted the application to access only those files that were created by the application. For an instance, an… Continue reading Modifying/Deleting Google Drive files
Stored XSS on facebook and twitter!
I and my colleague Prakash were testing random stuffs to find a target that would be worth looking into. We found a new feature on Facebook which allows a user to visit the website of page-owner.The “Shop-now” feature looked interesting with different restrictions for different input fields. The app-link field caught my eyes, because “deep-link”… Continue reading Stored XSS on facebook and twitter!
How I hacked your unverified facebook accounts !
Here’s a little write-up on how I was able to delete any unverified account in facebook. By unverified, I mean those accounts who didnot yet verify their email address linked to facebook. All (or most) of my bugs have been authentication related to many vendors, this was no different. Here is how I did it:… Continue reading How I hacked your unverified facebook accounts !
Going back to wordpress!
Github pages ain’t it. This is a test post.