GithubHelp home page GithubHelp logo

Hi There 👋

$whoami

  • 🕸 Web Application Penetration Tester
  • 📱 Android & iOS Application Security
  • ☁ Cloud & API security
  • 💻 NCIIPC Contributor
  • 🐱‍👤 Bug Bounty Hunter
  • 🐼 High Severity Bug Submissions in PUBG, Mastercard and many more
  • 😋 Pentesting Automation tools (Bash and Python)
  • 📑 Resume: View

Languages ⌨

  • Python

  • Shell/Bash Scripting

  • C

  • C++

  • Java

Projects & Tools 🛠

  • VulnHunt : Find CVEs, Subdomain Takeovers, XSS, SQLi, Sensitive files/directories and many more. Check Features
  • apknuke : Find vulnerabilities in Android Applications : Static Analysis : Template based Scanning. Check Features
  • JSEnum : Find Secrets, leaks, XSS & more in JavaScript files : Enumerate JS Files of a target & Subdomains. Check Features
  • ApkAnalyzer : Python script to find Vulnerabilities in Android Applications.
  • Shufti : Latest Recon Workflow Framework. NOT "Just another recon tool" . Check Features
  • get-api : Enumerate API Endpoints of multiple targets for further exploitation. Check Screenshots
  • s3extractor : Finds s3 buckets of a target and its subdomains and checks s3 bucket permissions through aws cli.
  • get-GraphQL Enumerate GET-based GraphQL endpoints of multiple targets for further exploitation.
  • All Projects

Blog website 🌐

🌐 utkarsh24122.gitbook.io

I have written a few writeups of some of the intersting vulnerabiities that I have found so far in my penetration tests & bug bounty journey in my gitbook

(It only contains few of the interesting ones so far )

Contents:

  1. Finding Security Vulnerabilities in Android Applications
  2. API Endpoints lead to Sensitive Information Disclosure and PII leakage of Employees
  3. HTTP Dangerous Methods Enabled - P1
  4. Subdomain Takeover
  5. Cross Site Scripting
  6. 2FA bypass - Bruteforce Protection Bypass & Response Manipulation
  7. Account Highjack
  8. OAuth Misconfiguration
  9. Open Redirect - Manual & Automated detection

Social Links 📞

utkarsh24122 | Twitter

utkarsh-sharma | LinkedIn

utkarsh_2.4 | Instagram





Utkarsh Sharma's Projects

apkanalyzer icon apkanalyzer

Python script to Find Vulnerabilities in Android Applications

apknuke icon apknuke

Find vulnerabilities in Android Applications : Static Analysis

get-api icon get-api

Template based scanning for API endpoints for further exploitation

get-graphql icon get-graphql

Template based scanning for GraphQL endpoints for further exploitation.

jsenum icon jsenum

Simple Bash Script to Enumerate and Exploit JavaScript Files of a target and its Subdomains

log4j-scan icon log4j-scan

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

s3extractor icon s3extractor

Bash Script to extract s3 buckets from JS files of the target.

shufti icon shufti

Latest Recon Workflow Framework

urldedupe icon urldedupe

C++ tool to deduplicate URL and query string combination; Debug version of https://github.com/ameenmaali/urldedupe

vulnhunt icon vulnhunt

Finds CVEs, Subdomain Takeovers, XSS, SQLi, Sensitive files/directories and many more

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.