Skip to content
View pand-coder's full-sized avatar
🎯
Focusing
🎯
Focusing

Organizations

@re-bin-d-22ucys

Block or report pand-coder

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
pand-coder/README.md
 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—    β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—
β–ˆβ–ˆβ•”β•β•β•β•β• β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β•β•šβ•β•β–ˆβ–ˆβ•”β•β•β•    β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘
β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•‘       β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘
β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β•šβ•β•β•β•β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘       β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘
β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘       β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•‘
 β•šβ•β•β•β•β•β• β•šβ•β•  β•šβ•β• β•šβ•β•β•β•β•β• β•šβ•β•β•β•β•β•β•   β•šβ•β•       β•šβ•β•β•šβ•β•  β•šβ•β•β•β•

☠️ I don’t hack systems. I perform surgery on them. ☠️

Typing SVG

GitHub followers


🧬 WHO AM I?

class BugHunter:
    def __init__(self):
        self.name        = "Pavan Shanmukha Madhav Gunda"
        self.alias       = "The One They Didn't Patch In Time"
        self.role        = ["Bug Bounty Hunter", "Security Researcher", "Digital Locksmith"]
        self.status      = "Currently inside your network  πŸ‘€  (just kidding... maybe)"
        self.superpower  = "Seeing what developers hoped no one would ever see"
        self.motto       = "CVE me in, or CVE me out β€” I find them either way."

    def current_mission(self):
        return "Making the internet safer, one responsible disclosure at a time πŸ”"

    def threat_to(self):
        return ["Misconfigured servers", "Unpatched endpoints", "False sense of security"]

    def NOT_a_threat_to(self):
        return ["Your data", "Your users", "The good guys"]

me = BugHunter()
print(me.current_mission())
# Output: Making the internet safer, one responsible disclosure at a time πŸ”

πŸ† THE KILL BOARD β€” HALL OF FAME

β€œEvery logo below is a company that trusted the internet. I showed them why they shouldn’t β€” then showed them how to fix it.”

🎯 TARGET πŸ”“ STATUS πŸ’€ VERDICT
🏒 Cognizant SECURED βœ… Hall of Fame
πŸŽ“ Amrita University SECURED βœ… Acknowledged
🏠 Havelock SECURED βœ… Acknowledged
πŸ’Ό Talentd SECURED βœ… Acknowledged
πŸ•ΉοΈ Retro SECURED βœ… Acknowledged
πŸŽ“ Geethanjali College of Engg & Tech SECURED βœ… Acknowledged
πŸ“Š Plotly SECURED βœ… Hall of Fame
πŸ‘Ÿ Nike (Duplicate) REPORTED 🟑 Beaten by seconds
πŸ’» Dell (Duplicate) REPORTED 🟑 Beaten by seconds

πŸ’¬ Nike and Dell: I found it. Someone else just found it 0.001 seconds before me. The bug was real. The timing was cruel. That’s bug bounty.


βš”οΈ ARSENAL β€” TOOLS OF THE TRADE

╔══════════════════════════════════════════════════════════════════╗
β•‘                    πŸ”§ OFFENSIVE TOOLKIT                         β•‘
╠══════════════════════════════════════════════════════════════════╣
β•‘  Recon     β†’  Subfinder β€’ Amass β€’ theHarvester β€’ Shodan         β•‘
β•‘  Scanning  β†’  Nmap β€’ Nuclei β€’ Nikto β€’ Burp Suite Pro            β•‘
β•‘  Fuzzing   β†’  ffuf β€’ dirsearch β€’ wfuzz β€’ GoBuster               β•‘
β•‘  Exploits  β†’  Custom Scripts β€’ Manual Analysis β€’ Big Brainβ„’     β•‘
β•‘  Reporting β†’  Markdown β€’ PoC Videos β€’ Responsible Disclosure    β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

BurpSuite Linux Kali Python Bash OWASP Wireshark


🧠 VULNERABILITY CLASSES I SPEAK FLUENTLY

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                                                                  β”‚
β”‚   XSS β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ 100%  πŸ’‰ Injected.                  β”‚
β”‚   IDOR β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ  95%  πŸ‘οΈ Seen what you hid.          β”‚
β”‚   SSRF β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ   90%  πŸ” Rerouted your trust.        β”‚
β”‚   SQLi β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ     80%  πŸ—„οΈ Read your DB.               β”‚
β”‚   Auth Bypass β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ 85%  πŸ”‘ Who needs a password?       β”‚
β”‚   Open Redirect β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ 75%  β†ͺ️ I'll take that redirect.    β”‚
β”‚   Recon β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ ∞%  πŸ•΅οΈ I never stop.              β”‚
β”‚                                                                  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“‘ PHILOSOPHY

β€œA hacker with ethics is just a security engineer

who hasn’t filed the paperwork yet.”

I don't break things.
I find the cracks that were already there
β€” before someone with worse intentions does.

Every bug I report is a disaster that didn't happen.
Every responsible disclosure is a user who didn't get compromised.
Every Hall of Fame mention is proof:
the best offense is a good defender.

🌐 CONNECT β€” IF YOU DARE

LinkedIn Twitter HackerOne Bugcrowd Email


πŸ“Š GITHUB WAR STATS

GitHub Stats

Top Langs

Streak


⚠️ LEGAL DISCLAIMER

╔══════════════════════════════════════════════════════════════════╗
β•‘  ⚠️  ALL SECURITY RESEARCH CONDUCTED ETHICALLY & LEGALLY  ⚠️   β•‘
β•‘                                                                  β•‘
β•‘  β†’ All findings reported through proper disclosure channels      β•‘
β•‘  β†’ No unauthorized access. Ever. Full stop.                      β•‘
β•‘  β†’ This profile is a portfolio, not a threat.                    β•‘
β•‘  β†’ If you're a company: your bug bounty program is welcome       β•‘
β•‘                                                                  β•‘
β•‘  "With great recon comes great responsibility." β€” Pavan, prob.   β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                                                               β”‚
β”‚   "Locks exist to keep honest people honest.                 β”‚
β”‚    I just make sure yours actually works."                   β”‚
β”‚                                                               β”‚
β”‚              β€” Pavan Shanmukha Madhav Gunda                  β”‚
β”‚                 Bug Bounty Hunter | Security Researcher       β”‚
β”‚                                                               β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Pinned Loading

  1. MetaStego MetaStego Public template

    StegaVault is a tool for embedding and extracting hidden messages in images, along with detailed metadata extraction capabilities.

    Python 22 5

  2. TOOLKIT TOOLKIT Public

    Collection of tools required for every Student

    2 2

  3. QueryDorker QueryDorker Public

    QueryDorker is an advanced tool designed to generate and save Google Dorks for web security assessments. It allows penetration testers and security researchers to quickly identify potential vulnera…

    Python 1