Kanishk Dadhich
@kanishkdadhich
I find and responsibly report API authorization and business-logic vulnerabilities.
What I'm looking for
I break APIs for a living and report what I find responsibly, with a focus on authorization and business-logic flaws across HackerOne and Bugcrowd programs.
I've identified a cross-tenant BOLA/BFLA chain in a GraphQL mutation, a Broken Function Level Authorization flaw that allowed lower-privilege users to lock out admins, and a Self-XSS chain that led to full account takeover. My work includes API pentesting, GraphQL security testing, IDOR-driven data exposure, privilege escalation, recon, and responsible disclosure.
I also build tools for the process itself. I created Mass PII & Secret Finder, an open-source JavaScript recon tool with 90+ secret-detection patterns, Wayback Machine discovery, and scope-enforced scanning, and SentinelAI, a Go, Python, and React API security recon tool for mapping endpoints that touch backend data.
I'm currently pursuing a B.Tech in Computer Science at Geetanjali Institute of Technical Studies, Udaipur, while treating bug bounty as a serious parallel track. I test only with explicit scope and authorization.
Experience
Work history, roles, and key accomplishments
Started bug bounty hunting on Bugcrowd, focused on web application vulnerabilities and building a foundation in real-world offensive testing. - Practiced structured vulnerability discovery and reporting against live production targets - Built core skills in authorization testing, business-logic analysis, and responsible disclosure Skills: Web Application Security, Vulnerability Assessment (VAPT),
Independent security researcher across HackerOne and Bugcrowd programs, specializing in API authorization flaws.
- Identified and reported a cross-tenant BOLA/BFLA vulnerability in a GraphQL mutation (no rate limiting, notification-bombing potential)
- Found a Broken Function Level Authorization bug allowing privilege escalation via role manipulation
- Conducted recon surfacing exposed API keys on
Top 3% globally. Practiced offensive techniques including SMB enumeration, NTLMv2 cracking, Evil-WinRM, and XXE injection to build real-world exploitation skill outside CTF walls.
Education
Degrees, certifications, and relevant coursework
Geetanjali Institute of Technical Studies, Udaipur
Bachelor of Technology - BTech, Computer Science
2023 - 2027
Geetanjali Institute of Technical Studies
Bachelor of Technology, Computer Science
2023 - 2027
Pursuing a Bachelor of Technology in Computer Science, with a focus on building a strong foundation in software and security principles.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Kanishk?
You can contact Kanishk and 90k+ other talented remote workers on Himalayas.
Message KanishkGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
