Open in app

Sign In

Write

Sign In

nav1n
nav1n

615 Followers

Home

About

Published in

InfoSec Write-ups

·Pinned

I Helped Prevent a Major PII Leak for India’s Top Health Benefits Management Platform by Ethically Hacking Their SQL Servers and IT Infrastructure

Hello all, Here, with this article, I’m going to show how I was able to alert a major Indian health benefits management platform to protect the contact data, Personally Identifiable Information (PII), insurance claim details, and other sensitive information of thousands of their customers. This article also highlights the negative…

Sql

11 min read

I helped the top Indian health benefits management platform from major PII leak by hacking their…
I helped the top Indian health benefits management platform from major PII leak by hacking their…
Sql

11 min read


Published in

InfoSec Write-ups

·May 20

Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large Online Media Leader

I recently received a private invitation to hack into an EU-based Online Media and Entertainment organization. The target’s scope wasn’t extensive, but it did include a wildcard scope on a main website specific to an EU country, as well as a few web-apps and proprietary tools. As I always say…

Blind Sql Injection

8 min read

Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large EU based Online Media and…
Exploiting SQL Error SQLSTATE[42000] To Own MariaDB of A Large EU based Online Media and…
Blind Sql Injection

8 min read


Published in

InfoSec Write-ups

·Mar 10

I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection Vulnerability.

Thank you for your love and appreciation for my recent blog post on MySQL SQL Injection, which I discovered in a major international retail company. After my initial post, many of you asked me to continue writing. However, it’s not possible for me to do so as I have a…

Graphql Vulnerability

7 min read

I Earned $3500 and  40 Points for A GraphQL Blind SQL Injection Vulnerability.
I Earned $3500 and  40 Points for A GraphQL Blind SQL Injection Vulnerability.
Graphql Vulnerability

7 min read


Published in

InfoSec Write-ups

·Mar 8

How I Gained Access to a Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection

Hello, thank you for stopping by. This is my first article on Medium. Usually, I am not fond of writing blogs these days, as I am actively sharing my bug bounty experiences and tips on Twitter whenever I find something interesting. …

Sqlmap

10 min read

How I Gained Access to a Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection
How I Gained Access to a Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection
Sqlmap

10 min read

nav1n

nav1n

615 Followers
Following
  • InfoSec Write-ups

    InfoSec Write-ups

  • Harsh Bothra

    Harsh Bothra

  • Anton (therceman)

    Anton (therceman)

  • Fat Selimi

    Fat Selimi

  • Sean (zseano)

    Sean (zseano)

See all (17)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams