Open in app

Sign In

Write

Sign In

Ajay Gautam
Ajay Gautam

768 Followers

Home

About

Published in

MokshyaProtocol

·Feb 22

Learning Move And Building on Aptos While Contributing to Open-Source

Are you interested in learning Move Programming Language and starting to build dApps on Aptos Blockchain? If Yes, this article can be of huge help. Scroll below to learn how you can do so while contributing to open-source protocols like Mokshya. First, learn the basics of move programming from the…

Move

3 min read

Move

3 min read


Published in

MokshyaProtocol

·Feb 16

Using Merkle Tree To Reduce Gas Cost While Minting NFTs on Aptos

Adding a large number of wallet addresses to a whitelist in Aptos can be costly, both in terms of time and gas fees. Using a bucket table and table in Aptos, it can cost around 0.9 APT to add 1,500 addresses to a whitelist. However, this cost increases significantly if…

Mokshya Protocol

2 min read

Mokshya Protocol

2 min read


Published in

Infosec Daily

·Aug 11, 2020

How I was able to find page/personal account disclosure on Instagram

This write-up is about how I was able to find page/personal account disclosure on Instagram. In my previous blog, I had written about Page admin disclosure and I had got much positive feedback on that blog. …

Facebook Bug Bounty

3 min read

How I was able to find page/personal account disclosure on Instagram
How I was able to find page/personal account disclosure on Instagram
Facebook Bug Bounty

3 min read


Published in

Infosec Daily

·Jan 23, 2020

How I was able to take over any users account with host header injection

This article is about a vulnerability I was able to find in the BugCrowd private program. At around midnight I got an alert message that said that I had been invited to pentest a new private program. Taking in regard the scope and reward range of the web application, I…

Host Header Injection

4 min read

How I was able to take over any users account with host header injection
How I was able to take over any users account with host header injection
Host Header Injection

4 min read


Published in

Infosec Daily

·Dec 26, 2019

Bypassing Brand Collabs Manager Eligibility on Facebook

In this week’s blog, I am writing about how I was able to bypass the eligibility criteria for the Brand Collabs Manager and register my page without meeting the criteria and policy. I wasn’t awarded any bounty for this as Facebook’s production team deemed it unqualified for monetary reward. If…

Social Media

3 min read

Bypassing Brand Collabs Manager Eligibility
Bypassing Brand Collabs Manager Eligibility
Social Media

3 min read


Published in

Infosec Daily

·Dec 5, 2019

How I was able to uniquely bypass authentication while web pentesting?

This article is based on a new finding which I was able to discover while doing pentest for a private company. Since I am not allowed to disclose information about the company, let’s assume it as redacted.com. …

Bug Bounty

4 min read

How I was able to uniquely bypass authentication while web pentesting?
How I was able to uniquely bypass authentication while web pentesting?
Bug Bounty

4 min read


Published in

Infosec Daily

·Oct 24, 2019

Session Expiration Bypass in Facebook Creator App

Hello everybody, Welcome back to my medium after many days. Sorry for not publishing anything for a long time, these days I was busy with some personal work. …

Facebook

3 min read

Session Expiration Bypass in Facebook Creator App
Session Expiration Bypass in Facebook Creator App
Facebook

3 min read


Published in

InfoSec Write-ups

·Jun 22, 2019

Page Admin Disclosure | Facebook Bug Bounty 2019

Hello everyone, I have not written a blog for a long time, so I thought of writing it in. Today, I am going to share one of my Facebook valid issue that I discovered in 2019. Vulnerability Type: Privacy / Authorization Product Area: Events Title: Facebook Page admin Disclosure Vulnerability…

Facebook

2 min read

Page Admin Disclosure || Facebook Bug Bounty 2019
Page Admin Disclosure || Facebook Bug Bounty 2019
Facebook

2 min read


Published in

InfoSec Write-ups

·Jan 24, 2019

Antihack.me Blind XSS To PHP File Upload Vulnerability

Hey, thanks for coming again here 😃. If you have not read my previous facebook bug write up then go here, its really awesome. Today i am going to share one of my cool finding at antihack.me . What is Blind XSS? It is a type of stored XSS where…

WordPress

2 min read

Antihack.me Blind XSS To PHP File Upload Vulnerability
Antihack.me Blind XSS To PHP File Upload Vulnerability
WordPress

2 min read


Published in

InfoSec Write-ups

·Jan 11, 2019

Workplace Logo ID to workplace owner name Disclosure Facebook Bug Bounty

Hi It’s me Ajay Gautam, Security Researcher at Nass and currently studying BIT (Hons) Computing. Today, I am going to share one of mine Facebook valid issue that I discovered in 2018. I was able to see the workplace owner name via their logo ID, if the ID of the…

Security

1 min read

Security

1 min read

Ajay Gautam

Ajay Gautam

768 Followers

Co-founder Mokshya

Following
  • Nrepesh

    Nrepesh

  • Immunefi

    Immunefi

  • Bishal Shrestha

    Bishal Shrestha

  • Madhav Dhungana

    Madhav Dhungana

  • subash gautam

    subash gautam

See all (79)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams