Open in app

Sign In

Write

Sign In

Jinson Varghese
Jinson Varghese

75 Followers

Home

About

Published in InfoSec Write-ups

·Jul 30, 2020

What’s on my .htaccess?

Some of the security issues commonly seen on a website can be taken care of using the .htaccess (hypertext access) file. In this article, I am gonna be showing the .htaccess configuration from my WordPress website and explain the security issues sorted out using it. However, before we get into…

Htaccess

9 min read

What’s on my .htaccess?
What’s on my .htaccess?
Htaccess

9 min read


Published in The Startup

·Dec 1, 2019

Prevent WordPress Username Enumeration

A guide on how to fix your vulnerable WordPress website. — Introduction One of the first things you do when auditing a WordPress website is checking for ways to enumerate the admin username. …

Word Press

4 min read

Prevent WordPress Username Enumeration
Prevent WordPress Username Enumeration
Word Press

4 min read


Published in ASTRA Security

·Mar 14, 2019

Cross Site Request Forgery: An Explanation with a Real Life Example

An Explanation with a Real Life Example — When I was trying to learn what CSRF is during my educational days, all I could find was theoretical stuff with examples of Bob and Alice and their transactions, which was good enough for the time being but not in gaining an idea of the real world approach to this…

Security

7 min read

Cross Site Request Forgery: An Explanation with a Real Life Example
Cross Site Request Forgery: An Explanation with a Real Life Example
Security

7 min read


Published in ASTRA Security

·Nov 26, 2018

Cybersecurity: How I got access to 16,000 customer transaction details

Something rather simple, yet potentially critical that a developer should take note of. — TL;DR: Improper configuration of robots.txt and the web server, resulted in me getting access to my client’s highly sensitive files containing the transaction details of around 16,000 customers each. Introduction This time around, it is not a price manipulation vulnerability like in the last story, rather it is a combination of…

Cybersecurity

4 min read

Cybersecurity: How I got access to the transaction details of around 16,000 customers
Cybersecurity: How I got access to the transaction details of around 16,000 customers
Cybersecurity

4 min read


Published in ASTRA Security

·Oct 22, 2018

Cybersecurity: How I hacked my client to save 75 USD on shipping charges

And what you can do to be more secure. — TL;DR: While pen-testing one of Astra’s customers, I found a way to change their set shipping charge to zero by manipulating the parameters in the POST request, and successfully make the order to any country of my choice. Introduction As an Information Security Analyst at Astra, I get to deal with…

Security

4 min read

Cybersecurity: How I hacked my client to save 75 USD on shipping charges
Cybersecurity: How I hacked my client to save 75 USD on shipping charges
Security

4 min read

Jinson Varghese

Jinson Varghese

75 Followers

Cybersecurity Researcher and Ethical Hacker

Following
  • Michael Whittle

    Michael Whittle

  • Sebastian Scholl

    Sebastian Scholl

  • Vickie Li

    Vickie Li

  • @radekk

    @radekk

  • Aakanchha Keshri

    Aakanchha Keshri

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech