Open in app
Home
Notifications
Lists
Stories

Write
Caesar Evan Santoso
Caesar Evan Santoso

Home

Apr 9

The Journey to get “SQL Injection” at BluePay (BLUE Indonesia BluePay) — 2019

Hello, In this article i want to share my experience getting SQL Injection on BluePay (BLUE Indonesia BluePay), I found this vulnerability in 2019 when I was still a Vocational High School and this machine was very popular in my school, and that’s when I tried do Pentest on this…

Sql Injection

3 min read

The Journey to get “SQL Injection” at BluePay (BLUE Indonesia BluePay) — 2019
The Journey to get “SQL Injection” at BluePay (BLUE Indonesia BluePay) — 2019

Jan 18

How I Get ZeroDay Attack UFU leads to RCE on one of the Vendors.

Hello, In this article I want to tell you a little about how I accidentally discovered the Unrestricted File Upload attack leads to Remote Code Execution on one of the vendors affected by this attack… Little Story Previously, I really didn’t know that those affected by the vulnerability that I found were…

Unrestricted File Upload

4 min read

How I Get ZeroDay Attack UFU leads to RCE on one of the Vendors.
How I Get ZeroDay Attack UFU leads to RCE on one of the Vendors.

Aug 27, 2021

SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection

Hello, here I just want to tell about my experience finding a real IP using CloudFlare through “SSRF External Interaction” and getting a form login for Admin and there is a SQL Injection bug. Little Story Previously I had also found SQLi vulnerabilities on this website but this time it felt a…

Bypass

4 min read

SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection
SSRF External Service Interaction for Find Real IP CloudFlare and Leads to SQL Injection

Mar 1, 2021

Bypass WAF 500 Unauthorized Access! to Reflected XSS (Cross Site Scripting)- Developer BCA

Hello, here I just want to share my experience regarding finding the XSS (Cross site scripting) bug at one of the banks in Indonesia, namely BCA (Bank Central Asia). Little Story I previously got this URL from 17 May 2019 and it comes from an email from Bank BCA, namely “Developer BCA”

Bug Bounty

3 min read

Bypass WAF 500 Unauthorized Access! to Reflected XSS (Cross Site Scripting)- Developer BCA
Bypass WAF 500 Unauthorized Access! to Reflected XSS (Cross Site Scripting)- Developer BCA

Dec 6, 2020

Found a simple “Price Parameter Tampering” on IT Bootcamp (Indonesia)

Hello, here I just want to give a little story about the finding of the bug “Price Parameter Tampering” on one of the IT Bootcamp websites in Indonesia. Summary The Parameter tampering attack relies on the manipulation of parameters changed by the user so as to change application information like user…

Parameter Tampering

3 min read

Found a simple “Price Parameter Tampering” on IT Bootcamp (Indonesia)
Found a simple “Price Parameter Tampering” on IT Bootcamp (Indonesia)

Oct 2, 2020

Full Path Disclosure at Digital Payments Indonesia

Bismillah. Assalamualaikum wr wb, teman teman ^-^)/ Disini saya hanya ingin membagikan pengalaman Berburu Bug saya pada salah satu website Pembayaran Digital Indonesia, Sebelumnya terima kasih banyak kepada pak Zul Amri yang sudah memforward Laporan saya ke Team dari website tersebut. Tentang Full Path Disclosure : Kerentanan Full Path Disclosure (FPD)…

Bug Bounty

3 min read

Full Path Disclosure at Digital Payments Indonesia
Full Path Disclosure at Digital Payments Indonesia

Apr 15, 2020

Penetration Testing using Nmap & GIT Dumper/Extractor

(PenTesting From Termux) — Hallo teman teman… Perkenalkan saya adalah Caesar dan disini saya hanya ingin membagikan pengalaman saya saja melakukan PenTesting pada salah satu website pembelajaran Cyber Security, dengan menggunakan Aplikasi Termux dan beberapa Tools yang biasa digunakan untuk melakukan PenTesting… Note :*untuk nama website disini saya akan sensor dan beberapa hal yang…

3 min read

Penetration Testing using Nmap & GIT Dumper/Extractor
Penetration Testing using Nmap & GIT Dumper/Extractor

Apr 15, 2020

Hello World

Hellow — Hi

1 min read


Jun 29, 2019

how i found bug on genetics.bwh.harvard.edu

Hellow friends… ^-^ i want to share my Write Up because i found Bug Vulnerability on the Harvard.edu subdomain website that is addressed to genetics.bwh.harvard.edu i open the website http://genetics.bwh.harvard.edu/pph2/index.shtml 2. then i open the “Batch Query” menu, url “http://genetics.bwh.harvard.edu/pph2/bgi.shtml"

Bug Hunter

2 min read

how i found bug on genetics.bwh.harvard.edu
how i found bug on genetics.bwh.harvard.edu
Caesar Evan Santoso

Caesar Evan Santoso

No One Knows Who I Am

Following
  • Dhamotharan

    Dhamotharan

  • Hack Hub

    Hack Hub

  • Jefferson Gonzales

    Jefferson Gonzales

  • Alfa Anarki

    Alfa Anarki

  • Dhanvesh Saini

    Dhanvesh Saini

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable