Open in app
Home
Notifications
Lists
Stories

Write
Veshraj Ghimire
Veshraj Ghimire

Home
About

Published in Pentester Nepal

·Jun 16

Hacking into WordPress themes for CVEs and Fun.

Hi there! I hope all is well with you. In this writeup, I’ll discuss about the research I did on a WordPress theme, which taught me a lot about WordPress themes/Plugins security. So, this started after ITSNP started their own Q&A platform. I planned to signup and as the initiative…

Cve

3 min read

Hacking into WordPress themes for CVEs and Fun.
Hacking into WordPress themes for CVEs and Fun.

Published in Pentester Nepal

·Apr 21

Open Redirect: Just a redirection?

Greetings, everyone! i’m back with a new article after a long absence. In this writeup, i will attempt to explain everything i know about open redirect. I recently discovered an open redirect on a private program and successfully exploited it to gain access to the account of the victim. …

Bug Bounty

4 min read

Open Redirect: Just a redirection?
Open Redirect: Just a redirection?

Published in Pentester Nepal

·Jan 1

A tale of zero click account takeover

Hello there! I hope everything is going well with you; today I’m back with the story of my first critical discovery on Hackerone, which is also my 1st $$$$ bounty. Initial Recon: As usual, I began with subdomain discovery and began probing it. I was more interested in this target because…

Bug Bounty

4 min read

A tale of zero click account takeover
A tale of zero click account takeover

Published in Pentester Nepal

·Oct 12, 2021

CVE-2021–24563 Unauthenticated Stored XSS [Frontend Uploader <= 1.3.2]

Greetings, Community! In this article, I’ll describe how I discovered Unauthenticated Stored XSS on one of WordPress’s plugins, which affected over 6K sites that used the vulnerable plugin, and how I managed to exploit it. How did it start? So, for a few days, I was trying different WordPress plugins. My research led me…

Bug Bounty

4 min read

CVE-2021–24563 Unauthenticated Stored XSS [Frontend Uploader <= 1.3.2]
CVE-2021–24563 Unauthenticated Stored XSS [Frontend Uploader <= 1.3.2]

Published in Pentester Nepal

·Sep 17, 2021

Why should you start using password manager?

Hey there! Hope you doing good. In this article i will try to explain why you should start using password managers. This isn’t a sponsored post anyways, so i will be explaining more about why using same password everywhere is worst rather marketing about password managers. Because the human mind…

Security

3 min read

Why should you start using password manager?
Why should you start using password manager?

Published in Pentester Nepal

·Sep 2, 2021

Hacking Dutch Government For a lousy T-shirt

Good day, everyone! Greetings, As this is my first post on Pentester Nepal, I’d want to thank you for taking the time to read it. Allow me to begin by providing a brief introduction of myself. I’m Veshraj Ghimire, an infoSec enthusiast who is passionate about offensive security (mostly web…

Infosec

3 min read

Hacking Dutch Government For a lousy T-shirt
Hacking Dutch Government For a lousy T-shirt

Published in InfoSec Write-ups

·Jul 16, 2021

Logical Flaw Resulting Path Hijacking

Hello, amazing people! I hope you are doing well. I am back with my new write-up. In this write-up, I will explain a logical flaw that I found on one target resulting in the hijacking of the path. So let me explain it in short. While testing on redracted.com…

Infosec

2 min read

Logical Flaw Resulting Path Hijacking
Logical Flaw Resulting Path Hijacking

Jul 8, 2021

TryHackMe PreSecurity Review

Hey folks, I am back with my new write-up. In this write-up, I am gonna share my experience on new pathways created by TryHackMe.It is a free room and everyone can join it. So let me quickly explain in brief. What is TryHackMe? TryHackMe is an awesome platform where it…

Ctf

4 min read

TryHackMe PreSecurity Review
TryHackMe PreSecurity Review

Published in InfoSec Write-ups

·Jun 11, 2021

Power Of Recon: Easy Win (Vim Attack)

Hello there, I am Veshraj Ghimire all the way from Nepal. This is my second write up and in this write up, I am going to tell you one of my totally unexpected bounty story which was possible by recon only. So, without wasting your time, Let me quickly tell…

Bug Bounty

4 min read

Power Of Recon: Easy Win (Vim Attack)
Power Of Recon: Easy Win (Vim Attack)

Published in InfoSec Write-ups

·May 10, 2021

My First Bug Bounty: SQL Injection!

Hello there, I am Veshraj Ghimire all the way from Nepal. This is my first bounty write up. In this writeup, I will explain about my 1st critical finding on a site listed at Bugv. So, Let Me Explain my short story about it. Severity: Critical The…

Bug Bounty

3 min read

First Bug Bounty Ever : SQL Injection!
First Bug Bounty Ever : SQL Injection!
Veshraj Ghimire

Veshraj Ghimire

Good Things Takes Time :)

Following
  • Thexssrat

    Thexssrat

  • Bishal Aryal

    Bishal Aryal

  • C M UPPIN

    C M UPPIN

  • Vasanth

    Vasanth

  • Milton Henry

    Milton Henry

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable