Open in app

Sign In

Write

Sign In

Dewanand Vishal
Dewanand Vishal

415 Followers

Home

About

Nov 20, 2022

How i found 29 stored XSS in modern framework

XSS is a most common vulnerability. It is easy to learn for a beginner but when it comes to modern applications then it makes hard for us to find and exploit. In this article i will share my story, how i was able to find a lot of XSS in…

3 min read

How i found 29 stored XSS in modern framework
How i found 29 stored XSS in modern framework

3 min read


Mar 31, 2022

Digilocker user’s phone numbers exposed [Fixed]

DigiLocker is an Indian digitization online service provided by Ministry of Electronics and Information Technology (MeitY), Government of India under its Digital India initiative. This is a story about how I was able to disclose the mobile number of any digilocker user. Issue 1 - Sign in with OTP In 2020, I noticed a new sign (Sign…

Bug Bounty

2 min read

Digilocker user’s phone numbers exposed [Fixed]
Digilocker user’s phone numbers exposed [Fixed]
Bug Bounty

2 min read


Sep 29, 2021

Force Browsing bug at Facebook business plan ($500 Bounty)

Hi bug hunters! this article is about my last finding on Facebook. I regularly check Facebook for the latest updates and features. In April I noticed they add a feature called Business Plan for page admin. you can read below how I was able to abuse this feature. While testing…

Bug Bounty

3 min read

Force Browsing bug at Facebook business plan ($500 Bounty)
Force Browsing bug at Facebook business plan ($500 Bounty)
Bug Bounty

3 min read


Apr 28, 2021

How did I earn €€€€ by breaking the back-end logic of the server

Hello bug hunters! I am back with another blog. I found these cool bugs in one of the private programs at intigriti. So will not disclose the program name, I will use example.com instead of the original domain name. Issue 1: Bypassing input validation via `null` value The target program is a self-developed customer portal from Hotels High…

Bug Bounty

3 min read

How did I earn €€€€ by breaking the back-end logic of the server
How did I earn €€€€ by breaking the back-end logic of the server
Bug Bounty

3 min read


Dec 8, 2020

Finding bugs at limited scope programs (Single Domain Websites)

Hi hunters, I am back with another write-up. Finding bugs in large scope is easy and its provide a large attack surface for hunters to test the applications in many different ways but when it comes to a small or limited scope then it is quite difficult to hunting for…

Bug Bounty

5 min read

Finding bugs at limited scope programs (Single Domain Websites)
Finding bugs at limited scope programs (Single Domain Websites)
Bug Bounty

5 min read


May 10, 2020

Remote Code Execution Vs Command Execution

Hi! Bug hunters, I am back with another writeup. I will try to simplify Remote Code Execution and Command Execution. Many people think both are the same vulnerability but it’s not. Don’t be confused! Code Evaluation, Arbitrary Code Injection, and Code Execution are synonyms of Code Injection. OS injection, Command…

Bug Bounty

3 min read

Remote Code Execution Vs Command Execution
Remote Code Execution Vs Command Execution
Bug Bounty

3 min read


May 3, 2020

How to write bug bounty report

Hi! Bug hunters, thanks for appreciating my previous article, I know there are many write-ups about “how to write a good bug report” but one thing I notice that’s all are intermediate and advance level and it is very difficult to understand for a beginner. In this write-up, we will…

Bug Bounty

3 min read

How to write bug bounty report
How to write bug bounty report
Bug Bounty

3 min read


Jan 26, 2020

My Bug Hunting Journey with IDORs Part 2

This is Part 2 of my first write-up Part 1, If you have not read yet that then read it first. In this write-up, I will discuss with you about all various kind of IDORs which I was discovered during my research. I have categorized these with the base on…

Bug Bounty

4 min read

My Bug Hunting Journey with IDORs Part 2
My Bug Hunting Journey with IDORs Part 2
Bug Bounty

4 min read


Oct 27, 2019

My Bug Hunting Journey with IDORs Part 1

Hi, Bug hunters, In this write-up, I want to share my story, how I accidentally became a bug-hunter. It’s all about my journey how I started. I want to tell you that I am not good at English, I apologise, if I do any mistakes in the write-up. It was…

Java Script

3 min read

My Bug Hunting Journey with IDORs Part 1
My Bug Hunting Journey with IDORs Part 1
Java Script

3 min read

Dewanand Vishal

Dewanand Vishal

415 Followers

Security Researcher | Bug Bounty Hunter

Following
  • Orwa Atyat

    Orwa Atyat

  • Sudhanshu Rajbhar

    Sudhanshu Rajbhar

  • Bipin Jitiya

    Bipin Jitiya

  • Anand Prakash - PingSafe

    Anand Prakash - PingSafe

  • Ansar Uddin

    Ansar Uddin

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech