Skip to content
View Rishurana2867's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Rishurana2867

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Rishurana2867/README.md

Hi, I'm Rishu Rana 👋

Cybersecurity Researcher • Bug Bounty Hunter • Offensive Security Enthusiast


Passionate about discovering and responsibly disclosing security vulnerabilities in modern web applications through real-world bug bounty and vulnerability disclosure programs.

I specialize in web application security testing with a strong focus on reconnaissance, attack surface mapping, vulnerability assessment, and responsible disclosure. I approach every target with a researcher's mindset — not just scanning, but understanding how the application works and where it breaks.

Actively exploring security programs on YesWeHack, Bugcrowd, and HackerOne.

With a solid foundation in networking, Linux, operating systems, and cryptography, I enjoy going deep into how systems are built — because understanding systems is the first step to breaking them responsibly.


🛠️ Technical Skills

Security & Offensive Testing Web Application Security · Vulnerability Assessment & Analysis · Reconnaissance & Enumeration · OSINT & Attack Surface Discovery · API Security Testing

Tools Burp Suite · Nmap · Nuclei · Metasploit · Subfinder · httpx · ffuf · gobuster · Waybackurls · gau · katana

Systems & Development Kali Linux · Ubuntu · Networking & OS Fundamentals · Python · Bash Scripting · Git & GitHub


🎯 Current Focus

  • Hunting real-world vulnerabilities across active bug bounty programs
  • Deepening expertise in web application and API penetration testing
  • Building recon automation tools to improve testing efficiency
  • Writing and publishing technical security research publicly
  • Working toward professional red teaming and OSCP certification

📌 Why This Profile Exists

I believe in learning in public. Everything I discover, report, and build gets documented — on GitHub and on LinkedIn. This profile is a live record of that journey.


📬 Connect

🔗 linkedin.com/in/rishurana2867


"Security is not just finding vulnerabilities — it's understanding systems deeply enough to think beyond their intended behavior."

Popular repositories Loading

  1. Phishing-detector Phishing-detector Public

    Python-based phishing URL detector that detects malicious and suspicious links using domain extraction, subdomain analysis and similarity matching.

    Python 3

  2. recon-methodology-wiki recon-methodology-wiki Public

    A phase-by-phase web app recon methodology — built from real bug bounty experience

    3

  3. price-manipulation-guide price-manipulation-guide Public

    A complete bug bounty guide on Price Manipulation & Business Logic vulnerabilities — Basic to Ninja level, Attack Chaining, Mobile Testing, Bypasses, Report Templates & Checklist.

    3

  4. password-strength-checker password-strength-checker Public

    A Python-based command-line tool that analyzes password strength and generates secure passwords using cryptographic randomness.

    Python 2

  5. first-contributions first-contributions Public

    Forked from firstcontributions/first-contributions

    🚀✨ Help beginners to contribute to open source projects

    2

  6. html-injection-notes html-injection-notes Public

    Complete HTML Injection research notes for bug bounty hunters — payloads, bypass techniques, testing methodology and report templates.

    2