Logo
Header Main navigation
  • Who we are
    • About
      • About TO THE NEW
      • GenAI in Action
      • Leadership
      • Partners
      • Newsroom
      • Awards & Analyst Relations
      • CSR
      • Events
    • Insights
      • Case Studies
      • Whitepapers
      • Webinars
      • Newsletter
      • Podcasts
      • Blogs
      • Articles
      • Brochure
      • Testimonial
      • Video
  • What we do
    • Services
      • Generative AI
      • Digital Engineering
      • Quality Engineering
      • Cloud
      • Data
      • Digital Experience
      • Digital Marketing
    • Industries
      • Technology
      • Media & Entertainment
      • Financial Services
      • Insurance
      • Healthcare
      • iGaming
    • Solutions
      • HAWK | Infra monitoring & Log Analytics
      • Prism | AI-based Test Automation
      • Nimbus | Custom Data Ingestion Solution
      • VideoReady | OTT & Video CMS framework
      • BOLT | Faster AEM Development
      • Technologies
  • Careers
    • Careers
  • InfAInite GPT
    • Generative AI
    • GenAI in Action

 

Contact us

Careers
 
Home > Insights > Blogs > Ankit Giri

Blogs

Told you, we love sharing!

Ankit Giri
DevOps

Application SecurityDevOps

Preventing cryptographic protocols from “DROWN attack”

DROWN is an abbreviation for Decrypting RSA with Obsolete and Weakened encryption and is seems to be applicable on servers using SSLV2. Just like Heartbleed, it may impact more than 11 million websites using OpenSSL.This blog explains Preventing cryptographic protocols from "DROWN attack". What this vulnerability can do? DROWN...

Ankit Giri
Ankit Giri March 7, 2016
Read→

Application SecurityTechnology

Understanding the CSRF(Cross-site request forgery) Vulnerability

The basic principle of CSRF vulnerability Whenever we are accessing an application, the browser is sending a request to the server and the server responds to the request by sending some data to the browser called response. This two-way communication continues as we continue using the application. When we login to the application, the...

Ankit Giri
Ankit Giri January 23, 2016
Read→

Application SecurityTechnology

Experience at SANS Delhi Community Night, 2016

TO THE NEW has been organizing conferences and actively participating in various conferences as well. I was invited to attend a presentation at SANS Community Night in Delhi, India on 14th Jan 2016. The topic of the talk was “DIY vulnerability discovery with DLL Side Loading“, and it's use as stealthy persistence technique for malware...

Ankit Giri
Ankit Giri January 15, 2016
Read→

Application SecurityTechnology

How I discovered RCE through a Misconfigured plugin

We have seen a lot of applications where some sub-domains or sub-directories are publicly exposed (intently or by mistake). So, with experience from our past pentests we have made a habit of testing  for vulnerable or accessible sub-domains. During one of such testing, I was manually testing the URLs of different sub-domains of the...

Ankit Giri
Ankit Giri January 13, 2016
Read→

Application SecurityTechnology

Malicious exploitation of Unauthenticated Request submissions

During a recent penetration test on one of our client's application, we came across a case of malicious file propagation through the application server. The attack does not require an authenticated session. The vulnerable section is accessible by unauthenticated users. The attack involves an attacker submitting a malicious request (a...

Ankit Giri
Ankit Giri January 13, 2016
Read→

Application SecurityAWS

Why compromised Jenkins can lead to a disaster?

I was recently searching for something on Google and came across this instance of what might be a logical vulnerability prevailing across multiple web applications. I was searching for publicly accessible Jenkins console through Google Dorking. My search query listed some of the websites that had Jenkins as a part of their domain...

Ankit Giri
Ankit Giri December 4, 2015
Read→

Application SecurityTechnology

Android 6.0(Marshmallow) : What’s new in Security

Android has been the most used mobile operating system till date. With the huge base of end-users, Android has been guilty of hosting numerous security related bugs in the past. With the latest version of Android 6.0 namely Marshmallow being released, I expected to see a few changes in the security model. Change in the permissions...

Ankit Giri
Ankit Giri November 26, 2015
Read→

Application SecurityTechnology

An essence of Application Security in E-commerce

Hackers and cyber criminals identify E-commerce sites as a source of information, such as credit cards and other PII (Personally identifiable information). To protect customers, it's necessary to know how to protect the application and the sensitive customer data it has. All this involves user's trust and assurance on the brand and...

Ankit Giri
Ankit Giri October 19, 2015
Read→

Application SecurityTechnology

Exploring iThemes Security Plugin to Secure WordPress websites – 2

In my previous blog on Ithemes Security, we went through Dashboard, Configuration and Global Settings. In this second part of the blog series,  A detailed understanding of sections 404 Detection, Away Mode, Banned Users will be covered. 404 Detection Hackers are always looking for vulnerabilities that can be exploited. Some...

Ankit Giri
Ankit Giri October 16, 2015
Read→

Application Security

An essence of Application Security in Healthcare Sector

Hackers and cyber criminals identify healthcare organizations as a source of assets, similar in a way that a bank has monetary assets. In case you have any doubt about the previous statement, I would like to reassure you that healthcare information has a monetary value and worth. And yes, it is at risk. What is wrong with the Healthcare...

Ankit Giri
Ankit Giri October 6, 2015
Read→

Application Security

Exploring iThemes Security Plugin to Secure WordPress websites

WordPress websites are mostly an easy target for attacks due to improper file permissions and vulnerable plugins being installed. Different factors that lead to attack on WordPress sites are :- Weak Passwords Vulnerable Plugins Obsolete version of WordPress being used Possible Solution Securing WordPress is a process and it...

Ankit Giri
Ankit Giri September 23, 2015
Read→

Application Security

Sleepy Puppy Tutorial : An XSS Payload Management Framework

Sleepy Puppy is a payload management framework for Cross Site Scripting that enables security engineers to simplify the process of capturing, managing, and tracking XSS propagations. Delayed XSS (a variant of stored XSS) Delayed XSS testing is testing that can be used to extend the scope of attack beyond the immediate effect of...

Ankit Giri
Ankit Giri September 7, 2015
Read→

Post navigation

Older posts
Archive
  • 2026
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
  • 2025
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2024
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2023
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2022
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2021
    • Feb
    • Mar
    • May
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2020
    • Mar
    • Jul
  • 2019
    • Jan
    • Mar
    • May
    • Jun
    • Jul
    • Aug
    • Dec
  • 2018
    • Jan
    • Feb
    • Mar
    • Apr
    • Jun
    • Nov
  • 2017
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2016
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2015
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2014
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2013
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2012
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2011
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2010
    • Jan
    • Feb
    • Mar
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2009
    • Jan
    • Mar
    • Apr
    • May
    • Jul
    • Aug
    • Sep
    • Oct
    • Nov
    • Dec
  • 2008
    • Feb
    • Apr
    • May
    • Jun
    • Jul
    • Aug
    • Sep
Who we are
  • About TO THE NEW
  • Leadership
  • Awards
  • Events
  • Privacy Policy
  • Press Releases
  • Media Coverage
  • Partners
  • CSR
  • Modern Slavery Statement
What we do
  • Services
  • Technologies
  • Solutions
  • Industries
Knowledge
  • Blogs
  • Success Stories
  • Whitepapers
  • Webinars
  • Podcasts
  • Newsletter
  • Article
  • Brochure
  • Testimonial
  • Video
Contact Us
  • Career
  • Join us!
  • Request for Services
  • Media Queries
  • Responsible Disclosure
Follow us on
  • ln
  • twt
  • fb
  • Glassdoor
 
TO THE NEW logo
TO THE NEW logo

©2026 TO THE NEW

Tips for writing a blog

Learn how to write a caption