DIPESH KUNWAR

Offensive Security Researcher Bug Bounty Hunter Since 2023 Nepal

DipeshKunwar

I hunt the vulnerability that pays — web apps and APIs, boundary to boundary.

View the record

200+ vulnerabilities disclosed · recognized by NASA & the U.S. Department of Defense · first bug at sixteen.

01The Record
200+
Vulnerabilities
disclosed
$10K+
Bounties
earned
100+
Programs
secured
16
Age it
started

Active since 2023 — first bug at sixteen Platforms: HackerOne · YesWeHack · self-hosted

Focus Areas — where the impact lives

  1. 01 Account TakeoverChaining weaknesses to seize full control of a victim's account. CRIT
  2. 02 Auth / Authz BypassWalking straight past authentication and privilege boundaries. CRIT
  3. 03 IDOR / BOLACrossing user and tenant lines to read and modify others' data. HIGH
  4. 04 Business LogicAbusing valid workflows the way developers never intended. HIGH
  5. 05 Cross-Site ScriptingRunning attacker script inside a victim's authenticated session. HIGH
  6. 06 Cache PoisoningTurning a shared cache into a delivery vector for every user. HIGH
  7. 07 API SecurityHunting object- and function-level auth gaps across REST endpoints. HIGH
  8. 08 InjectionBending inputs into commands the backend wrongly trusts. HIGH
03Exhibit B — U.S. Department of Defense
U.S. Department of Defense DIB-VDP Researcher of the Month, January 2025
Open ⤢
Verified credential

Researcher of the Month

Selected by the Defense Industrial Base Vulnerability Disclosure Program as Researcher of the Month for outstanding achievement — awarded January 2025.

Authority
DoD Cyber Crime Center (DC3)
Defense Counterintelligence & Security Agency
Program
DIB-VDP — Defense Industrial Base
Vulnerability Disclosure Program
Awarded
January 2025
04Open Source — Arsenal
All repositories on GitHub →
05Service Record
2023 — PresentBug Bounty Hunter
Independent Researcher
HackerOne · YesWeHack · Self-hosted

Bug Bounty Hunter — Independent Researcher

  • Security testing across web applications and APIs on multiple platforms.
  • 50+ vulnerabilities discovered and responsibly disclosed in real-world targets.
  • Specialized in XSS, IDOR, business-logic flaws, cache poisoning and account takeover.
  • Manual analysis and original proof-of-concept exploitation — no scanner spray.
  • Professional reports with clear impact analysis and remediation guidance.
2023 — 2025Security Researcher
Private engagement

Security Researcher — Self-Hosted Engagement

  • 30+ vulnerabilities reported, measurably improving the platform's security posture.
  • Rewarded and recognized for impactful findings; worked alongside remediation.
  • Collaborated on validation to confirm fixes held across the application.

Toolkit

Burp SuitePythonJavaScriptLinux / WSLBrowser DevToolsGitNmap Web app pentestingAPI security & testingVulnerability assessmentBusiness-logic analysisSession managementPoC development

Also builds and ships full-stack web apps and security-focused projects.

06Contact

Have a target that needs breaking?

Open to bug bounty collaboration, security-research roles and freelance engagements.

Email copied to clipboard