Rakesh Mali profile picture

Hello, I'm

Rakesh Mali

Security Researcher and Penetration Tester

LinkedIn profile Twitter profile Medium Blog Page

Get To Know More

About Me

Experience icon

Experience

5+ years
Application Security

Education icon

Education

B.E Bachelors Degree

As a Security Researcher and Penetration Tester, I am responsible for conducting vulnerability assessments, penetration testing, and secure code reviews across web, API, network, and cloud applications. With over 5 years of experience in ethical hacking, I specialize in identifying vulnerabilities and strengthening the security of digital infrastructures across various sectors. I hold OSCP and CRTP certifications and have hands-on experience with tools such as FortiDAST for dynamic application security testing. My expertise includes external network penetration testing, REST API security assessments, and developing proof-of-concept (PoC) exploits, including zero-day vulnerabilities, using Python. Additionally, I am currently working on a short film focused on hacking and scams to help educate the public about cybersecurity risks.

Explore My

Skills

Checkmark icon

Web App Security

Checkmark icon

API Security

Checkmark icon

Network Security

Checkmark icon

Mobile App Security

Checkmark icon

Ethical Hacking

Explore My

Experience

Penetration Testing Staff Engineer

SonicWall

Jan 2026 - Present

Working as a Staff Engineer focusing on penetration testing, vulnerability assessments, and securing enterprise network and cloud environments. Conducting advanced security testing and providing remediation strategies.

Security Researcher and Penetration Tester

Fortinet

Mar 2021 - Jan 2026

At Fortinet, I serve as a Security Researcher and A skilled hacker with expertise in various security domains, including Web Application Penetration Testing, Mobile Application Penetration Testing, Network Penetration Testing, and API Penetration Testing. and I have hands-on experience with tools like FortiDAST, a Dynamic Application Security Testing tool, and have worked on External Network Penetration Testing and REST API reviews, also involved in writing Zero Day Exploit POCs in Python for FortiCART, conducting Product Security Testing (DAST) for Fortinet products, and scripting in Lua for Fortinet’s scripting engine. Additionally, I engaged in research on Fuzzer and crawler enhancements..

Explore My

Certifications

Explore My

Writing

Account Takeover by OTP Bypass blog post

Account Takeover by OTP Bypass

O'Auth Misconfiguration blog post

How I Earned $3000 From HTML Injection to Blind XSS

O'Auth Misconfiguration blog post

Account Takeover via CSRF in Google OAuth Binding

O'Auth Misconfiguration blog post

O'Auth Misconfiguration

Host Header Injection blog post

Host Header Injection to Account Takeover

Access Token Leakage blog post

Access Token Leakage To Account Takeover

Hacked Premium Account blog post

I hacked and Purchased the Premium Account at Rupees

OTP Bypass in Oneplus blog post

OTP Bypass in Oneplus

Get in Touch

Contact Me

Copyright © 2024 Rakesh. All Rights Reserved.