Divyanshu·Feb 25How I Found a Path Traversal in the Rancher Dashboard via HAR ReplayThe issue is considered as a hardening gap by the Rancher Security team, as it resides within a feature limited to dev mode in Rancher…
Divyanshu·Nov 8, 2025EKS Moved To containerd, GuardDuty’s Runtime Alert Stayed Behind. Here’s Why That Matters.Why this matters especially for startups relying on AWS GuardDuty?
InInfoSec Write-upsbyDivyanshu·Sep 12, 2024Threat Modeling 102: Applying STRIDE to Payments ArchitectureCredit : This solution is my solution to the Threat Modeling exercise provided in the repository Security Engineering Training, created by…A response icon2A response icon2
InInfoSec Write-upsbyDivyanshu·Aug 13, 2024Threat Modelling 101: Mapping OWASP Top 10 to STRIDEThis blog provides only the foundational overview of threat modelling concepts including OWASP top 10 2024 mapping to STRIDE. It serves as…
Divyanshu·Jul 3, 2024Generative AI Web App using Python Flask with Amazon BedrockIn this blog , let’s create a generative AI-enabled web application from scratch using Python Flask. The application will provide a cloud…
InLive With GratitudebyDivyanshu·Mar 22, 2023How Yoga & Ayurveda Helped Me To Handle BurnoutAs a member of the infosec community, I have observed that many individuals are experiencing exhaustion and burnout for various reasons…A response icon3A response icon3
InInfoSec Write-upsbyDivyanshu·Mar 17, 2023Alibaba Cloud WAF Command Injection Bypass via Wildcard Payload in All 1,462 Built-in Rule SetAlibaba WAF version 3.0 was tested and very common payload was found bypassing command injection.A response icon1A response icon1
InInfoSec Write-upsbyDivyanshu·Jun 28, 2022HTML and Hyperlink Injection via Share Option In Microsoft Onenote ApplicationHyperlink Injection it’s when attacker injecting a malicious link when sending an email invitation. HTML injection attack is injecting HTML…A response icon1A response icon1
InInfoSec Write-upsbyDivyanshu·Jun 1, 2022Kubernetes 101 | Setting up Kubernetes Cluster LocallyThis blog is about setting the local Kubernetes cluster for learning & testing using multiple tools like Kind, Minikube, Kubeadm & K3s.
InInfoSec Write-upsbyDivyanshu·May 25, 2022Module-3 | Introduction -Pentesting & Bypassing AWS/Azure/GCP Cloud WAF Fun & Profit1. Setting up Vulnerable Application For AWS WAFA response icon1A response icon1