BUG BOUNTY · PENTEST · VULNERABILITY RESEARCH

Cybersecurity Blog

Bug bounty write-ups, penetration testing guides, and vulnerability research by Piyush Kumawat.

PIYUSH KUMAWAT · August 14, 2024

🛠️ Reconnaissance and Vulnerability Scanning Script🛡️

In the fast-paced world of cybersecurity, staying ahead of potential threats requires thorough reconnaissance and vulnerability assessments. This blog post introduces you…

PIYUSH KUMAWAT · February 22, 2024

LLM Agents can Autonomously Hack Websites ?

Based on the research paper (https://arxiv.org/pdf/2402.06664.pdf), the study delves into the autonomous hacking capabilities of Large Language Models (LLMs), particularly focusing on…

PIYUSH KUMAWAT · February 19, 2024

$600 Simple MFA Bypass – Graphql

Welcome to my blog! In this post, I'll delve into my recent security testing adventure focusing on multi-factor authentication (MFA) implementation in…

PIYUSH KUMAWAT · January 3, 2024

Exploring Application Security with SAST, DAST, SCA, and IAST

Welcome to today's blog, where we'll explore the world of software security testing. In an era where cyber threats are on the…

PIYUSH KUMAWAT · November 21, 2023

Top Recon Tools for Bug Bounty Hunters

In this blog, we explore top-tier reconnaissance tools that empower bug bounty hunters. From Shodan's IoT device insights to Waymore's web application…

PIYUSH KUMAWAT · August 14, 2023

Mastering WordPress Penetration Testing: A Step-by-Step Guide

In this comprehensive guide, we'll explore various aspects of WordPress penetration testing. Starting with gathering information using tools like Wappalyzer and WPintel.…

PIYUSH KUMAWAT · August 12, 2023

Enhance WordPress Security: Comprehensive Guide

In this guide, we'll unravel the crucial aspects of WordPress security, from user access management and update strategies to SSL implementation and…

PIYUSH KUMAWAT · August 5, 2023

How to Write a Killer Pentest Report

Hey there! So, you're ready to dive into the world of pentest reporting? Awesome! In this section, we'll introduce you to the…

PIYUSH KUMAWAT · July 15, 2023

ZeusCloud – OpenSource Cloud Security Platform

As the adoption of cloud technology continues to surge, businesses are embracing its benefits by migrating their workloads from on-premises to the…

PIYUSH KUMAWAT · March 11, 2023

Threat Modeling : Everything You Need to Know for Web Application Security

Web applications are a crucial part of today's online landscape, with businesses relying on them to provide services to their customers. However,…

PIYUSH KUMAWAT · February 11, 2023

How to Conduct a Successful Penetration Test: A Step-by-Step Guide

Penetration testing is an essential component of a comprehensive cybersecurity strategy. It involves simulating an attack on an organization's systems and applications…

PIYUSH KUMAWAT · January 30, 2023

OSV-Scanner: Protecting Your Open-Source Dependencies

In today's digital age, cyber security threats are becoming increasingly prevalent and sophisticated. As a result, organizations need to have robust security…

PIYUSH KUMAWAT · January 23, 2023

Dastardly – Web Application Security Scanner – CI/CD

Introduction As a Security engineer, ensuring the security of your application is of the utmost importance. With the advent of Dastardly, a…

PIYUSH KUMAWAT · January 17, 2023

Metlo – Open Source API Security Platform

APIs have become an essential part of modern business operations, connecting different systems and services to create seamless digital experiences for customers.…

PIYUSH KUMAWAT · January 12, 2023

All about Burp Suite

Welcome to our blog post on "All About Burp Suite", a powerful and versatile tool used by security professionals and organizations for…

PIYUSH KUMAWAT · December 28, 2022

Top Burp Suite Extensions used by Penetration Testers

Burp Suite is a powerful tool for web application security testing. One of the key features of Burp Suite is its ability…

PIYUSH KUMAWAT · December 20, 2022

Cloud Security Configuration Review: A Comprehensive Guide

In this post, I will provide a detailed, step-by-step guide to conducting a cloud security configuration review. We will cover the importance…

PIYUSH KUMAWAT · December 15, 2022

The Importance of Secure Coding: Best Practices for Developers

The growing number of security breaches in recent years is a clear indication that we must prioritize code security. By writing better…

PIYUSH KUMAWAT · December 10, 2022

ChatGPT: The Ultimate Tool for Penetration Testers

As a penetration tester or bug bounty hunter, you know the importance of having the right tools at your disposal. ChatGPT is…

PIYUSH KUMAWAT · September 10, 2022

All about Ethical Hacking

This article seeks to serve as a thorough introduction to Ethical Hacking. Ethical hacking refers to the practice of using computer security…

PIYUSH KUMAWAT · September 10, 2022

Extract Android Application’s Database

This article aims to be a comprehensive guide on how you can extract android application's database. In this article, I will show…