Break it.
Understand it.
Fix it.
Hi, my name is Gowriprasad. Security engineer at Zoho, working on penetration testing and vulnerability management. I write up what I learn, the bugs I find, and the CTF boxes I break, all here.
GET /whoami HTTP/1.1 Host: gowriprasad07.github.io Accept: application/json
HTTP/1.1 200 OK Content-Type: application/json { "whoami": "security engineer", "breaks": ["web apps", "APIs", "networks"], "reads": ["source code", "traffic"], "hunts_on": ["on-prem", "cloud", "linux", "windows"], "finds": ["vulnerabilities"], "certs": ["OSCP+"] }
Who I am
Most of my time goes into hunting for weaknesses in web apps, APIs, and networks, reading code to understand how they really work, and running bug bounty triage end to end. I care about why something breaks, not just that it breaks.
- Electronics, undergrad
- Security intern
- M.Tech, Cybersecurity
- Red team intern, Zoho
- Security Engineer, Zoho
Certification
Published work
- Securing Web Browsing: Detection of Browser-in-the-Browser Attack · Springer
- Investigating the Lack of Consensus Among Sentiment Analysis Tools · Springer
Outside work
Football, mostly. I play when I can, and I follow Bayern Munich.
Learn
Notes
Things I had to sit with for a while before they made sense. I write them down so I don't forget how they work.
Break
Findings
Bugs I found, explained simply. I keep the cause and the fix, and leave out anything related to internal or company data.
Attack
CTF
Boxes I found interesting. Written up as the path from foothold to full control, the way I'd explain it to someone stuck on the same machine.
Heist: a gMSA read all the way to SYSTEM
HeistFish: a GlassFish traversal that reads its way in, then a WAR to SYSTEM
FishNibbles: PostgreSQL default creds, then a SUID find to root
NibblesSnookums: a photo gallery LFI that became a shell, then PwnKit to root
SnookumsThe work, in numbers
What the years add up to.
Get in touch
If you've read something here and want to argue with it, or you're working on something interesting, I'd like to hear from you.