How to Pass the kWAPTA Exam - Insights from a Reviewer
I recently served as a reviewer for the kWAPTA (Certified Web App Penetration Testing Apprentice) exam. Reviewing candidate performance gave me a very clear picture of what works,...
Active
Tareq is a founding member of the Knight Squad community and is part of Knight Squad Academy as an Offensive Security Researcher. He takes classes and contributes to certification design and assessment development, with a focus on web application security, practical testing, and responsible vulnerability research. He has responsibly reported vulnerabilities to organizations and projects including Meta (Facebook), Yahoo, Mozilla, Nextcloud, and Apache Airflow, and his research work includes 3+ published CVEs. He holds recognized certifications including eJPT, CRTA, CAPen, and C-APIPen, and supports hands-on learning by creating CTF challenges for KnightCTF and BDSec CTF.
Public records with concise research context.
CVE-2023-47037
We failed to apply CVE-2023-40611 in 2.7.1 and this vulnerability was marked as fixed then. Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.
View advisoryCVE-2023-39955
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
View advisoryThe latest published writing from Md. Tareq Ahamed Jony.
I recently served as a reviewer for the kWAPTA (Certified Web App Penetration Testing Apprentice) exam. Reviewing candidate performance gave me a very clear picture of what works,...