Himanshu Anand's Avatar

Himanshu Anand

@noob

Capturing some flags!! https://himanshuanand.com jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e

39
Followers
194
Following
46
Posts
06.06.2023
Joined
Posts Following

Latest posts by Himanshu Anand @noob

The lack of common sense among the people, it should be called "uncommon sense".

14.09.2025 14:56 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Which companies are forcing staff into the office during the tube strike? #London

11.09.2025 21:38 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

How do you get this info?
(Some 3rd party IP is reaching out to some xyz IP)
Help a noob

11.09.2025 21:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Don't forget our Call for Papers (also Rookies and Workshops) is still open!
Have you got something original and interesting to share, but need somewhere to do it?
➑️ #BSidesLDN2025

More information and to submit your proposal: cfp.bsides.london/bsides-londo...

#Security #BSides #London

20.08.2025 07:36 πŸ‘ 6 πŸ” 8 πŸ’¬ 0 πŸ“Œ 0

Now I know why my teeth glow at night .

20.08.2025 10:41 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1
Preview
Over 150K websites hit by full-page hijack linking to Chinese gambling sites We estimate that approximately 150,000 websites have been impacted by this campaign. The script defines an array of keywords related to betting, gambling, and casino brands both in English and Chinese...

A web malware campaign tracked as ZuizhongJS has now hijacked over 150,000 websitesβ€”and countingβ€”to insert ads and redirect users to Chinese gambling sites: cside.dev/blog/over-15...

This campaign started last month: cside.dev/blog/over-35...

27.03.2025 08:58 πŸ‘ 10 πŸ” 6 πŸ’¬ 0 πŸ“Œ 0

I thiywe need more people to acknowledged it.
It seems most of the time people and companies try to hush it down. πŸ€·β€β™‚οΈ

19.03.2025 11:17 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Never realised there is a visa requirement for delivery training as well. Is this something new?

28.02.2025 11:12 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Browsers only read the CSP when a page initially loads. This means that adding or modifying a <meta> tag afterward won’t affect or weaken the policy. Additionally, secure sites typically define the CSP in the HTTP header, which browsers enforce immediately and ignore any attempts to override.

26.02.2025 16:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I had an stupid thought: since a CSP (Content Security Policy) can be implemented using a <meta> tag, what’s stopping JavaScript from rewriting these meta tags to bypass the CSP?
I knew it was not possible but why not?

26.02.2025 16:25 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Poor handwriting.
πŸ₯²

12.02.2025 00:10 πŸ‘ 6 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Hey cybersecurity folks! As a direct or indirect consequence of the US (and others) cutting foreign aid, there are many who have done cybersecurity for NGOs and at-risk groups who are or will be looking for a job. They often have broad experience, from research to incident response to education 1/2

03.02.2025 20:38 πŸ‘ 112 πŸ” 49 πŸ’¬ 2 πŸ“Œ 1

Hey Brian
I was the one who found this. Feel free to let me know if I can be of any help.

Cheers

31.01.2025 23:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Hackers are hijacking WordPress sites to push Windows and Mac malware A cybersecurity company says hackers are pushing Mac and Windows malware through sites that are using outdated versions of WordPress. Β© 2024 TechCrunch. All rights reserved. For personal use only.

Hackers are hijacking WordPress sites to push Windows and Mac malware

29.01.2025 22:07 πŸ‘ 63 πŸ” 29 πŸ’¬ 4 πŸ“Œ 7
Preview
Hackers are hijacking WordPress sites to push Windows and Mac malware | TechCrunch A cybersecurity company says hackers are pushing Mac and Windows malware through sites that are using outdated versions of WordPress.

Honored to be quoted in @techcrunch.com 's latest article on the hijacking of WordPress sites to distribute Windows and Mac malware. It's crucial for website owners to stay vigilant and implement robust security measures. Read more: techcrunch.com/2025/01/29/h...

30.01.2025 09:56 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

We found 2 more domains associated with the same attack:

iogamesl[.]xyz
wp-cdn[.]top

In today we have identified a little over 500 websites that were impacted.

29.01.2025 19:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I was expecting a crash, but I guess the system's a bit rusty…

29.01.2025 12:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
10,000 WordPress Websites Found Delivering MacOS and Windows Malware We identified over 10,000 WordPress loading showing fake Google browser update leading to malware downloads.

WP infected website infecting windows users with SocGholish and Mac Users with AMOS.

cside.dev/blog/10-000-...

28.01.2025 22:15 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Government and university websites targeted in ScriptAPI[.]dev client-side attack Yesterday we discovered another client-side JavaScript attack targeting +500 websites, including governments and universities. The injected scripts create hidden links in the Document Object Model (DO...

Black hat SEO, compromised gov and university websites.

cside.dev/blog/governm...

24.01.2025 22:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Over 5,000 WordPress sites caught in WP3.XYZ malware attack We’ve uncovered a widespread malware campaign targeting WordPress websites, affecting over 5,000 sites globally. The malicious domain: "https://wp3.xyz/plugin[.]php".

Over 5,000 WordPress sites caught in WP3.XYZ malware attack
cside.dev/blog/over-5k...

13.01.2025 20:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 1

This is crazy, everything I say BOTS 1 new bot follows me. πŸ˜…πŸ€£

13.01.2025 16:41 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Post about BOTS get more BOTS. πŸ₯²

13.01.2025 15:42 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I got more bots followers than real people. πŸ€·β€β™‚οΈ

13.01.2025 11:35 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

When to expect next Ivanti 0day?

> My prediction 1 more this quarter.

09.01.2025 12:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

New year/quarter is incomplete without Ivanti 0day.

08.01.2025 23:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

French authorities are asking for the proof.
Can I show them this screenshot?

03.01.2025 23:20 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Waiting for the list!!

03.01.2025 22:50 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Happy CVE-2025-0001

31.12.2024 15:49 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

A bit old but I was quoted :D

28.12.2024 21:05 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Bluesky BOTS: bluebots

12.12.2024 15:34 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0