Rikesh Baniya·Dec 12, 2024Account Takeover using SSO LoginsCompanies often provide various login methods for users to authenticate their accounts.A response icon13A response icon13
Rikesh Baniya·Oct 31, 2024User info extraction abusing placeholder injection in ZendeskIn this blog, I will share how I found template injection affecting Zendesk customers with default configuration.A response icon2A response icon2
Rikesh Baniya·Aug 21, 2024Authorization bypass due to cache misconfigurationThis writeup is about one of my favorite findings as it was a very unexpected issue.A response icon21A response icon21
Rikesh Baniya·Jun 8, 2024Abusing auto mail responders to access internal workplacesWhen ever you send an email to a company address support@example.com , contact@example.com you might have noticed you will be greeted with…A response icon4A response icon4
InPenTester NepalbyRikesh Baniya·Sep 8, 2021Facebook email disclosure and account takeoverI have a preference for apps over web when it comes to hunting, so in January I decided to dive deep into apk endpoints hoping to find…A response icon3A response icon3
InPenTester NepalbyRikesh Baniya·Jul 9, 2021Facebook Email/phone disclosure using Binary searchSo in December I decided to hunt on Facebook, and chose to go with the Facebook Android AppA response icon1A response icon1
Rikesh Baniya·Dec 16, 2020JavaScript analysis leading to Admin portal accessI love hunting on small scoped websites cause i can be assured that i have seen every corner and analyzed every endpoint of the that…A response icon1A response icon1
Rikesh Baniya·Dec 10, 2020How I dumped PII information of customers in an ecommerce site?Like every website, the most interesting endpoint is always the image upload section. So I fired my burp and was checking how the images…A response icon3A response icon3
Rikesh Baniya·Aug 5, 2020How I was able to do Mass Account Takeover[Bug Bounty]This was one of the interesting bug that i found on a target.A response icon1A response icon1