...

Hello, I'm

Kullai Metikala

Security Researcher

Get To Know More

About Me

Experience

2+ years
Bug Bounty

Education

Btech in Cyber Security *

I'm a dedicated professional engaged in the realm of cybersecurity as a Bug Bounty Hunter, Hacker, and Security Researcher. I adhere to ethical practices by reporting these vulnerabilities and assisting organizations in resolving their security concerns.

Currently, I am furthering my education at Sree Vidyanikethan Engineering College / Mohan Babu University, pursuing a Bachelor of Technology degree in Computer Science and Cyber Security. My academic endeavors align seamlessly with my passion for cybersecurity, particularly focusing on penetration testing.

I am driven by a profound enthusiasm for cybersecurity, constantly seeking opportunities to enhance my knowledge and skill set. My adaptability to diverse work environments and cultures empowers me to excel in a dynamic and ever-evolving field, where continuous learning is paramount. Additionally, I contribute my insights and experiences by crafting informative articles detailing my discoveries of vulnerabilities, which are published on various platforms including blogs and Medium.

I have secured more than 130+ Companies

Natural ... ... ... ... ... ... ... ... ... Natural Natural

My Skills

Web Application Penetration Testing

80%

Network Penetration Testing

80%

Android Penetration Testing

70%

API Penetration Testing

75%

IOS Penetration Testing

50%

Experience

Cyber Security Analyst (Intern)

October 2023 - Present

Performing Regular Pentest over a Variety of Technology Stack.

The Red team at Pentabug

September 2022 - Present

Bug Hunter

September 2022 - Present

Certifications

eJPT - eLearnSecurity Junior Penetration Tester

eLearnSecurity

Credential ID: 83928229

Blogs

...

Zero Click Account Takeover

This Web application is a type of Bus Ticket booking platform. Where I was able to book tickets by creating an account and also, I was able to book tickets as a guest user providing the email.

READ MORE
...

My P1 — Account Takeover

While I am hunting on one target named example.com (all will name redacted.com). There is an invite Functionality on their website. By using that functionality, I can take over the victim's account.

READ MORE
...

Disclosed API key to list user information and complete Exploitation !!

Accidental public exposure of credentials such as API keys, OAuth tokens, and app secrets is a mistake that can be made by both inexperienced and seasoned developers, particularly when it comes to source control.

READ MORE