Appsec

application security

January 26, 2026

Unknown AZURE SSRF endpoint

With the rise in AI usage, many llm self hosted dashboard solutions started providing cloud templates which you can host in your azure, gcp or aws. Everyone knows 169.254.169.254 cloud endpoint which works with most clouds, We will talk...

Read More
May 7, 2021

Hundred ways to exploit LFI

Recently, I took more than 40 interviews, and while most of the candidates said they knew about LFI, many didn’t know about difference between directory traversal and LFI. How to exploit an LFI. Hence, I thought of writing this...

Read More