Tinkering the kernel

Blog revolving around breaking everything to fundamentals and getting down to it's nitty-gritty. Untold hacking tales, exploits, tools and much more.

Piyush Raj

OS Command Injection on Node.JS Jison module

Finding OS Command Injection vulnerability which allows arbitrary shell command execution through a crafted command-line argument on Jison in parser ports began when I started receiving lots of invites over Hackerone. An injection vulnerability manifests when application code sends untrusted user input to an interpreter as…

Jump into →
Piyush Raj

The generic "Hello, world" — 0x48piraj

Today, I'm happy to announce the launch of this blog, all shiny and brand spanking new! It’s been two to three weeks in the decision making and coding and I'm really happy that the community can finally see it. There are still many major changes that have to be implemented in the website, but for now, it is…

Jump into →