Open to security work

Naresh Dhanuk / @n4r3sh

ApplicationSecurityAnalyst

Application Security Analyst

Application security analyst and bug bounty hunter focused on finding and responsibly disclosing high-impact vulnerabilities in modern web applications and APIs.

Based
Nepal
Focus
Web · API · Logic flaws
Programs
Public & private
About01

Security is a mindset, not a checklist.

I'm Naresh Dhanuk, an application security analyst and bug bounty hunter based in Nepal. I spend my days probing web applications and APIs for the flaws that scanners miss.

My work sits at the intersection of offensive testing and pragmatic defense — finding critical bugs, writing clear reports, and helping teams ship safer software.

Based in NepalSpeaks English, Hindi
01
2+
Years at DishHome
02
35+
Reports on YesWeHack
03
4+
Vendor acknowledgements
04
2024
JustCall Hall of Fame
Experience02

Where I work.

Application Security Analyst

Current
DishHomeNepal2024 – Present

Leading application security testing across DishHome customer-facing platforms and internal systems. Conducting VAPT, secure code reviews, and threat modelling. Identifying and remediating critical vulnerabilities before production releases.

What I do03

Areas I go deep on.

01

Web & API Security

Deep testing of authn/authz, business logic, injection, SSRF and access-control flaws across web apps and REST/GraphQL APIs.

02

Bug Bounty Research

Recon-driven hunting on public and private programs, chaining lower-severity issues into meaningful impact.

03

WordPress & Plugin Security

Reviewing plugins and CMS code for vulnerabilities — e.g. a privately reported fix shipped in SureForms 1.4.1.

04

Responsible Disclosure

Clear, reproducible reports that help vendors ship fixes fast.

Burp SuiteOWASP Top 10OWASP ASVSWeb App PentestingAPI SecurityIDOR / BOLAXSSSSRFSQLiAuthenticationBusiness LogicGraphQLWordPress SecurityNetwork TestingRecon / OSINTNucleiPythonBashHTTP internals
07 — Contact

Got an app worth breaking? Let's talk.

Open to security consulting, private programs, and collaboration.