whoami
> Raunak Gupta a.k.a. B1scuit
> Freelance Security Researcher & Bug Bounty Hunter
> Specializing in: Android β’ Web β’ API β’ Thick-Client Security
> Also into: Open-Source β’ AI β’ LLMs
> Location: Rajasthan, India
> Status: Available for hire π’
- π― Bug Bounty Hunter on HackerOne & YesWeHack β featured in 18+ Hall of Fames
- π οΈ Building open-source security tools for the community
- πΉ Running B1scuit Security on YouTube β hacking tutorials & writeups
- βοΈ Writing on Medium β bug bounty tips, resources & POCs
- π Udemy instructor with 8,400+ learners
- π¬ Running an active Discord community for security researchers
- π Personal site: b1scuit.pro
| Company | Severity | Vulnerability Type |
|---|---|---|
| π΅ Supabase | π΄ High | BAC + Insecure API (rate limiting & input flaws) |
| π Zerodha | π΄ High | Android + Business Logic + Security Misconfigurations |
| β« Cert-wm.nl | π΄ High | Stored XSS via Unrestricted File Upload |
| π£ Thinkst Canary | π‘ Medium | Mass PII Leak |
| π’ Substack | π‘ Medium | Race Condition β Atomic Increment Manipulation |
| π’ GeeksForGeeks | π‘ Medium | Mass Assignment Vulnerability |
| π΅ Wibmo.com | π‘ Medium | IDOR β Email Disclosure |
| π EC-Council | π‘ Medium | Email Verification Bypass |
| π€ Inflectra.com | π‘ Medium | Open Redirect + PII Leak via Input Validation Flaw |
| π£ Skillmate.ai | π‘ Medium | Security Bypass + Insecure API |
| π΅ Samsung | π΅ Low | Misconfigured AWS S3 Bucket β Data Leak |
| βοΈ Chess.com | π΅ Low | CWE-657: Insecure Design Violation |
| π Arcjet.com | π΅ Low | CWE-657: Insecure Design Violation |
| π₯ CK Birla Hospital | π΅ Low | Security Bypass + Insecure API |
| π₯ Sir Ganga Ram Hospital | π΅ Low | Security Bypass + Insecure API |
| π₯ Max Healthcare | π΅ Low | Security Bypass + Insecure API |
| π‘ Com Olho | π΅ Low | Security Bypass + Insecure API |
| π‘ Brandmuscle.com | π΅ Low | Security Bypass + Insecure API |
π° Also earned a $1,000+ bounty via private YesWeHack program (Android app β Forgot Password flow)
| Project | Description | Stars |
|---|---|---|
| My CyberSecurity Store | Curated collection of infosec tools, resources & references | β |
| Bug Bounty GitBook | Playbook: tools, methodologies, writeups, labs & checklists | β |
| Learn Android Bug Bounty | Complete guide to Android application pentesting & bug bounty | β |
| Learn Beyond Web | Comprehensive guide to Thick-Client security testing | β |
| Elite Google Dorks Search | Smart Google dorks to surface hidden assets & information | β |
| Project | Description |
|---|---|
| APKDig | Deep APK analysis β extracts security-relevant info |
| analyze_manifest | AndroidManifest.xml analyzer β permissions, deep links, exported components |
| AndroidExportViewer | View & analyze exported Android components |
| DecompileAllAPK-s | Batch APK decompiler with analysis features |
| PullAPKFromPure | Extract APKs directly from Android devices |
| Project | Description |
|---|---|
| Bruteforce JWT Secret | Brute-force weak JWT secrets to test auth |
| Elite Burp Suite Analyzer | Advanced HTTP history analyzer with enhanced filtering |
| GitHub Recon Tool | GitHub recon & repo analysis tool |
| Tor IP Changer | Auto-rotate IP via Tor network |
| Single Script Tools | One-script installer for multiple cybersecurity tools |
| CloneAllRepo | Clone all repos from a GitHub user/org |
| Extension | Description |
|---|---|
| AutoTabSorter | Auto-organize Burp tabs for workflow efficiency |
| CVSS Calculator | Integrated CVSS scorer inside Burp Suite |
- π From JS Recon to HTML Injection β JS recon uncovering HTML injection
- π Hacking Hospital: Mass PII Leak β Healthcare system vulnerability case study
- π The Thousand Dollar Bug β $1000+ bounty writeup via private YesWeHack program
- π 30 Must-Read Books to Learn Hacking β Curated reading list
- π 55 YouTube Channels to Learn Hacking β Best channels for bug bounty
Target Surfaces: Web Apps β’ REST/GraphQL APIs β’ Android Apps β’ iOS Apps β’ Thick-Client Apps Techniques: IDOR β’ BAC β’ Race Conditions β’ Mass Assignment β’ SQLi β’ XSS β’ JWT Attacks β’ SSL Pinning Bypass β’ Root Detection Bypass β’ Business Logic Flaws β’ AWS Misconfigurations
Udemy Instructor β Security Researcher and Bug Bounty Hunter
- π 8,400+ total learners
- π Active courses on cybersecurity, bug bounty & ethical hacking
- π Beginner-friendly content paired with real-world examples





