Security Researcher · eJPT Certified

Dinesh Kumar
Goud.

Mobile & Web Application Penetration Tester

Security Researcher with hands-on experience in Web, Mobile, and API Security Testing. Reported 120+ security vulnerabilities across public and private vulnerability disclosure programs, including findings related to SQL Injection, Cross-Site Scripting (XSS), Insecure Direct Object References (IDOR), Broken Access Control, Authentication Flaws, and Business Logic Vulnerabilities.

Recognized by organizations including Amazon, Jio, Dominos, GEA Group, GE Appliances, CultFit, Broadcom, Tata Play, NCIIPC, Hocalwire, Droom, and numerous other programs for responsible vulnerability disclosure. Experienced in bug bounty hunting and penetration testing.

120+
Accepted vulnerability reports
Public & Private Programs
7
Hall of Fame
recognitions from top companies
Top 2
CYBERNEXA CTF
national ranking
hands-on experience
Mobile · Web · API
Career

Experience

Feb 2026 – Present
Cyraacs · Bengaluru
Technical Services Intern
  • Perform Android and iOS mobile application penetration testing using JADX, Ghidra, MobSF, Frida, and reFlutter on rooted/jailbroken devices.
  • Conduct Flutter app security assessments by re-enabling Dart debugging via reFlutter and performing dynamic analysis on patched binaries.
  • Developed custom scripts automating SSL pinning and root detection bypass, enabling deep analysis of hardened production applications.
  • Web API penetration testing targeting OWASP API Top 10 — BOLA/IDOR, broken authentication, and injection flaws.
  • Black-box and grey-box assessments on banking and e-commerce applications in production and UAT environments.
  • Produce structured VAPT reports with clear Proof-of-Concepts and actionable remediation guidance for every finding.
Apr 2025 – Sep 2025
Security Lit · Remote
Associate Penetration Tester
  • VAPT on web applications and network targets following OWASP and PTES methodologies.
  • Manual and automated penetration testing — identified critical authentication bypass, access control flaws, and business logic vulnerabilities.
  • Run Nessus scans, and delivered detailed remediation reports with full PoCs.
Expertise

Technical Arsenal

📱
Mobile Penetration Testing
JADX Ghidra MobSF Frida reFlutter Magisk/Shamiko SSL Pinning Bypass Root Detection Bypass Android Emulators iOS Jailbreak Flutter VAPT
🌐
Web & API Security
Burp Suite OWASP API Top 10 BOLA/IDOR SQLMap Nuclei Nikto dalfox ffuf Broken Auth Business Logic
🔍
Recon & OSINT
Subfinder httpx katana Shodan FOFA Censys VirusTotal gowitness jsluice CertSpotter
🛠️
Network & Infrastructure
Nmap Nessus Wireshark Metasploit Kali Linux Windows Server Azure Splunk
💻
Languages & Scripting
Python Bash JavaScript PHP SQL Frida JS Custom Automation
📋
Methodology & Reporting
OWASP MSTG PTES Black-box Testing Grey-box Testing PoC Development VAPT Reports CVE Analysis
Responsible Disclosure

Bug Bounty Programs

Amazon HackerOne VDP
High
Jio Responsible Disclosure
Critical
Broadcom Bug Bounty Program
High
UPS HackerOne VDP
Medium
Zepto Responsible Disclosure
High
Tata Play Responsible Disclosure
High
CultFit Responsible Disclosure
Medium
GEA Group Responsible Disclosure
High

Accepted reports, bounty confirmations & acknowledgement emails available on request.

📁 View Evidence (Google Drive)
Impact Overview

120+ Accepted Reports

Vulnerability classes discovered and responsibly disclosed across web applications, APIs, and mobile platforms through authorized bug bounty and VDP engagements.

💉
SQL Injection
Database extraction, authentication bypass, and blind SQLi via parameter tampering in web apps and APIs.
Critical / High
🔓
Broken Access Control
Horizontal and vertical privilege escalation — accessing other users' data and admin-only endpoints without authorization.
Critical / High
🪪
BOLA / IDOR
Object-level authorization flaws allowing unauthenticated or unauthorized access to sensitive resources via manipulated identifiers.
High
📝
Cross-Site Scripting (XSS)
Reflected and stored XSS enabling session hijacking, cookie theft, and client-side code execution in production apps.
High / Medium
🔑
Broken Authentication
Weak session management, OTP bypass, account takeover via password reset flaws, and token reuse vulnerabilities.
Critical / High
📱
Mobile Security Flaws
Hardcoded secrets, insecure data storage, SSL pinning issues, debuggable production builds, and exported activity abuse.
High / Medium
⚙️
Security Misconfiguration
Exposed .env files, misconfigured CORS, verbose error messages leaking stack traces, and open admin panels.
High / Medium
🔁
Business Logic Flaws
Price manipulation, coupon abuse, race conditions, and workflow bypass in e-commerce and banking applications.
High / Medium
Recognition

Hall of Fame

Zepto · Security Acknowledgment
CultFit · Hall of Fame
GEA Group · Responsible Disclosure
Droom · Security Acknowledgment
Broadcom · Hall of Fame
Domino's · Security Acknowledgment
GE Appliances · Hall of Fame
Zepto · Security Acknowledgment
CultFit · Hall of Fame
GEA Group · Responsible Disclosure
Droom · Security Acknowledgment
Broadcom · Hall of Fame
Domino's · Security Acknowledgment
GE Appliances · Hall of Fame
HOF
GE Appliances
Hall of Fame · 2026
🔗 View Hall of Fame
HOF
Domino's
Security Acknowledgment-PENDING· 2026
🔗 View Hall of Fame
HOF
Zepto
Security Acknowledgment · 2025
🔗 View Hall of Fame
HOF
GEA Group
Responsible Disclosure · 2025
🔗 View Hall of Fame
HOF
CultFit
Security Acknowledgment · 2024
🔗 View Hall of Fame
HOF
Cricket-21
Responsible Disclosure · 2024
🔗 View Hall of Fame
HOF
Droom
Security Acknowledgment · 2024
🔗 View Hall of Fame
HOF
Broadcom
Hall of Fame · 2024
🔗 View Hall of Fame
Competitions

CTF & Achievements

🥈
CYBERNEXA CTF Ranked Top 2 Nationally
#55
TryHackMe Hackfinity 2025 Global red team simulation · Top 55 worldwide
Top 15
Deccan CTF — IIIT Hyderabad Ranked Top 15 nationally
Top 20
AppSec Hackathon 2024 — DSCI Telangana Top 20 globally in application security CTF
Top 100
NCIIPC-AICTE Pentathon 2024 Grand Finale participant · Top 100 in India
🏆
University Hackathon — NRCM College Winner of 24-hour hackathon
🎖️
Anveshanam-24 IIT Jammu & DRDO · Ministry of Defence, Govt. of India
🎓
Null Hyderabad Community Active member · Security Boat · The Hackers Meetup
Credentials

Certifications

Certified Junior Penetration Tester (eJPTv2)
INE Security
Certified AppSec Practitioner v2
The SecOps Group
Ethical Hacking & Penetration Testing
BERRY9 IT
Foundations of Cybersecurity
Coursera — Google
Microsoft Security Operations Analyst
SkillUp with LevelUp
Get In Touch

Let's Connect

Open to security internships, bug bounty collaborations, and VAPT engagements. If you're building something that needs to be secure — or want to know if it already is — reach out.

Send an Email