Rakesh Mali profile picture

Hello, I'm

Rakesh Mali

Security Researcher and Penetration Tester

LinkedIn profile Twitter profile Medium Blog Page

Get To Know More

About Me

Experience icon

Experience

4+ years
Application Security

Education icon

Education

B.E Bachelors Degree

As a Security Researcher and Penetration Testing, I am responsible for conducting vulnerability assessments, penetration testing, and secure code reviews across Web, API, Network, and Cloud applications. With over 4 years of experience in Ethical Hacking, I excel in discovering new bugs and vulnerabilities, safeguarding digital infrastructures and assets for various sectors

Explore My

Skills

Checkmark icon

Web App Security

Checkmark icon

API Security

Checkmark icon

Network Security

Checkmark icon

Mobile App Security

Checkmark icon

Ethical Hacking

Explore My

Experience

Security Researcher and Penetration Tester

Fortinet

Mar 2021 - Present

At Fortinet, I serve as a Security Researcher and A skilled hacker with expertise in various security domains, including Web Application Penetration Testing, Mobile Application Penetration Testing, Network Penetration Testing, and API Penetration Testing. He holds OSCP and CRTP certifications and is currently working on a short film about hacking and scams to educate the public. Rakesh has hands-on experience with tools like FortiDAST, a Dynamic Application Security Testing tool, and has worked on External Network Penetration Testing and REST API reviews. He is also involved in writing Zero Day Exploit POCs in Python for FortiCART, conducting Product Security Testing (DAST) for Fortinet products, and scripting in Lua for Fortinet’s scripting engine. Additionally, he is engaged in research on Fuzzer and crawler enhancements.

Explore My

Certifications

Explore My

Writing

Account Takeover by OTP Bypass blog post

Account Takeover by OTP Bypass

O'Auth Misconfiguration blog post

How I Earned $3000 From HTML Injection to Blind XSS

O'Auth Misconfiguration blog post

Account Takeover via CSRF in Google OAuth Binding

O'Auth Misconfiguration blog post

O'Auth Misconfiguration

Host Header Injection blog post

Host Header Injection to Account Takeover

Access Token Leakage blog post

Access Token Leakage To Account Takeover

Hacked Premium Account blog post

I hacked and Purchased the Premium Account at Rupees

OTP Bypass in Oneplus blog post

OTP Bypass in Oneplus

Get in Touch

Contact Me

Copyright © 2024 Rakesh. All Rights Reserved.