Naresh Dhanuk / @n4r3sh
ApplicationSecurityAnalyst
Application security analyst and bug bounty hunter focused on finding and responsibly disclosing high-impact vulnerabilities in modern web applications and APIs.
- Based
- Nepal
- Focus
- Web · API · Logic flaws
- Programs
- Public & private
Security is a mindset, not a checklist.
I'm Naresh Dhanuk, an application security analyst and bug bounty hunter based in Nepal. I spend my days probing web applications and APIs for the flaws that scanners miss.
My work sits at the intersection of offensive testing and pragmatic defense — finding critical bugs, writing clear reports, and helping teams ship safer software.
Where I work.
Application Security Analyst
CurrentLeading application security testing across DishHome customer-facing platforms and internal systems. Conducting VAPT, secure code reviews, and threat modelling. Identifying and remediating critical vulnerabilities before production releases.
Areas I go deep on.
Web & API Security
Deep testing of authn/authz, business logic, injection, SSRF and access-control flaws across web apps and REST/GraphQL APIs.
Bug Bounty Research
Recon-driven hunting on public and private programs, chaining lower-severity issues into meaningful impact.
WordPress & Plugin Security
Reviewing plugins and CMS code for vulnerabilities — e.g. a privately reported fix shipped in SureForms 1.4.1.
Responsible Disclosure
Clear, reproducible reports that help vendors ship fixes fast.
Recognised by the teams I've helped secure.
Verified credentials.
Notes from the field.
Got an app worth breaking? Let's talk.
Open to security consulting, private programs, and collaboration.
