<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://serdire.github.io/</id><title>YASH MAHESHWARI</title><subtitle>Don't Stock, I'll Investigate</subtitle> <updated>2026-09-28T06:08:22+08:00</updated> <author> <name>YASH MAHESHWARI</name> <uri>https://serdire.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://serdire.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://serdire.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 YASH MAHESHWARI </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Dependency Confusion Attack: A Route to RCE</title><link href="https://serdire.github.io/posts/dependency/" rel="alternate" type="text/html" title="Dependency Confusion Attack: A Route to RCE" /><published>2025-05-12T13:00:00+08:00</published> <updated>2026-09-28T02:56:31+08:00</updated> <id>https://serdire.github.io/posts/dependency/</id> <content type="text/html" src="https://serdire.github.io/posts/dependency/" /> <author> <name>YASH MAHESHWARI</name> </author> <category term="web" /> <summary>Hello, amazing hackers! Today, I’m explaining one of my recent findings: the dependency confusion attack and how it can lead to remote code execution. This vulnerability was discovered during a private pen-test engagement. What is Dependency Confusion? A Dependency Confusion attack or supply chain substitution attack occurs when a software installer script is tricked into pulling a ...</summary> </entry> <entry><title>Dependency Confusion Attack: A Route to RCE</title><link href="https://serdire.github.io/posts/dependency/" rel="alternate" type="text/html" title="Dependency Confusion Attack: A Route to RCE" /><published>2025-05-12T13:00:00+08:00</published> <updated>2026-09-28T02:56:31+08:00</updated> <id>https://serdire.github.io/posts/dependency/</id> <content type="text/html" src="https://serdire.github.io/posts/dependency/" /> <author> <name>YASH MAHESHWARI</name> </author> <category term="web" /> <summary>Hello, amazing hackers! Today, I’m explaining one of my recent findings: the dependency confusion attack and how it can lead to remote code execution. This vulnerability was discovered during a private pen-test engagement. What is Dependency Confusion? A Dependency Confusion attack or supply chain substitution attack occurs when a software installer script is tricked into pulling a ...</summary> </entry> <entry><title>Dependency Confusion Attack: A Route to RCE</title><link href="https://serdire.github.io/posts/dependency/" rel="alternate" type="text/html" title="Dependency Confusion Attack: A Route to RCE" /><published>2025-05-12T13:00:00+08:00</published> <updated>2026-09-28T02:56:31+08:00</updated> <id>https://serdire.github.io/posts/dependency/</id> <content type="text/html" src="https://serdire.github.io/posts/dependency/" /> <author> <name>YASH MAHESHWARI</name> </author> <category term="web" /> <summary>Hello, amazing hackers! Today, I’m explaining one of my recent findings: the dependency confusion attack and how it can lead to remote code execution. This vulnerability was discovered during a private pen-test engagement. What is Dependency Confusion? A Dependency Confusion attack or supply chain substitution attack occurs when a software installer script is tricked into pulling a ...</summary> </entry> <entry><title>XPATH Injection - Exploiting Error-based SQL Injection</title><link href="https://serdire.github.io/posts/XPATH-Injection/" rel="alternate" type="text/html" title="XPATH Injection - Exploiting Error-based SQL Injection" /><published>2025-03-16T21:00:00+08:00</published> <updated>2026-09-28T02:56:31+08:00</updated> <id>https://serdire.github.io/posts/XPATH-Injection/</id> <content type="text/html" src="https://serdire.github.io/posts/XPATH-Injection/" /> <author> <name>YASH MAHESHWARI</name> </author> <category term="mobile" /> <summary>Hey hackers!! Today, I’m explaining the exploitation of the error-based SQL injection via XPATH injection. This vulnerability was discovered during a private pen-test engagement. Understanding the UPDATEXML and EXTRACTVALUE Functions Let’s first understand the UPDATEXML and EXTRACTVALUE XML functions, as they are helpful for exploiting the error-based SQL injection. Here, we are tak...</summary> </entry> <entry><title>XPATH Injection - Exploiting Error-based SQL Injection</title><link href="https://serdire.github.io/posts/XPATH-Injection/" rel="alternate" type="text/html" title="XPATH Injection - Exploiting Error-based SQL Injection" /><published>2025-03-16T21:00:00+08:00</published> <updated>2026-09-28T02:56:31+08:00</updated> <id>https://serdire.github.io/posts/XPATH-Injection/</id> <content type="text/html" src="https://serdire.github.io/posts/XPATH-Injection/" /> <author> <name>YASH MAHESHWARI</name> </author> <category term="mobile" /> <summary>Hey hackers!! Today, I’m explaining the exploitation of the error-based SQL injection via XPATH injection. This vulnerability was discovered during a private pen-test engagement. Understanding the UPDATEXML and EXTRACTVALUE Functions Let’s first understand the UPDATEXML and EXTRACTVALUE XML functions, as they are helpful for exploiting the error-based SQL injection. Here, we are tak...</summary> </entry> </feed>
