Open in app

Sign in

Write

Sign in

Rikesh Baniya
Rikesh Baniya

1.1K followers

Home

About

Account Takeover using SSO Logins

Companies often provide various login methods for users to authenticate their accounts.

Dec 12, 2024
10
Account Takeover using SSO Logins
Account Takeover using SSO Logins
Dec 12, 2024
10

User info extraction abusing placeholder injection in Zendesk

In this blog, I will share how I found template injection affecting Zendesk customers with default configuration.

Oct 31, 2024
1
User info extraction abusing placeholder injection in Zendesk
User info extraction abusing placeholder injection in Zendesk
Oct 31, 2024
1

Authorization bypass due to cache misconfiguration

This writeup is about one of my favorite findings as it was a very unexpected issue.

Aug 21, 2024
21
Authorization bypass due to cache misconfiguration
Authorization bypass due to cache misconfiguration
Aug 21, 2024
21

Abusing auto mail responders to access internal workplaces

When ever you send an email to a company address support@example.com , contact@example.com you might have noticed you will be greeted with…

Jun 8, 2024
3
Abusing auto mail responders to access internal workplaces
Abusing auto mail responders to access internal workplaces
Jun 8, 2024
3
PenTester Nepal

Published in

PenTester Nepal

Facebook email disclosure and account takeover

I have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…

Sep 8, 2021
3
Facebook email disclosure and account takeover
Facebook email disclosure and account takeover
Sep 8, 2021
3
PenTester Nepal

Published in

PenTester Nepal

Facebook Email/phone disclosure using Binary search

So in December I decided to hunt on Facebook, and chose to go with the Facebook Android App

Jul 9, 2021
Facebook Email/phone disclosure using Binary search
Facebook Email/phone disclosure using Binary search
Jul 9, 2021

JavaScript analysis leading to Admin portal access

I love hunting on small scoped websites cause i can be assured that i have seen every corner and analyzed every endpoint of the that…

Dec 16, 2020
Dec 16, 2020

How I dumped PII information of customers in an ecommerce site?

Like every website, the most interesting endpoint is always the image upload section. So I fired my burp and was checking how the images…

Dec 10, 2020
3
How I dumped PII information of customers in an ecommerce site?
How I dumped PII information of customers in an ecommerce site?
Dec 10, 2020
3

How I was able to do Mass Account Takeover[Bug Bounty]

This was one of the interesting bug that i found on a target.

Aug 5, 2020
How I was able to do Mass Account Takeover[Bug Bounty]
How I was able to do Mass Account Takeover[Bug Bounty]
Aug 5, 2020
Rikesh Baniya

Rikesh Baniya

1.1K followers

give me bugs

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech