PinnedMonish·Jan 5Open Source Hacking — Breaking AstroJsHow a convenience feature turned into SSRF and local file reads
PinnedMonish·Sep 10, 2025Hacking Into India’s Largest Payment Network Through a Single API Call“What if I told you that with just one POST request, you could go from being a cashier to controlling thousands of retail stores across…A response icon1A response icon1
PinnedMonish·Jun 1, 2025Unlimited free burgers — Hacking McDonald’s IndiaWhat if I told you it was possible to order free burgers from McDelivery India — in a single order — without spending an extra rupee?A response icon1A response icon1
PinnedMonish·Dec 31, 2022Hacking Bigbasket Ethically For Free GroceriesWho doesn’t love free groceries? In this write-up, I will be discussing a cart tampering vulnerability that I discovered in the popular…A response icon1A response icon1
PinnedMonish·Nov 13, 2023Hacking cult.fit for unlimited free Gym sessionsNavigating the Race Conditions and Payload Manipulation Exploits in Cult.fit’s Gym Trial SystemA response icon1A response icon1
Monish·Nov 29, 2023Cancelling everyone’s CultSport orders with IDORWhat if someone was able to cancel all the orders you placed? This write-up lists the details of an IDOR vulnerability within Cult Fit’s…
Monish·Aug 25, 2023Hacking India’s Biggest Fintech Provider With a Simple IDORUnveiling the Threat of IDOR Vulnerabilities By Hacking a Fintech Provider Ethically
Monish·Aug 27, 2022The Million Dollar Hack 💰Hacking a leading gift card company with a simple IDOR + Race conditionA response icon2A response icon2
Monish·Nov 21, 2021Open Redirect Vulnerability On Zapier: An Accidental FindOpen Redirect Vulnerabilities have been around for a long time now, finding one can either be extremely easy, or at the same time can be…
Monish·Aug 22, 2021Trusting Pre-domain Wildcard as Origin CSRF Attack — DevfolioCross Site Request Forgery (CSRF) attacks are the most common vulnerabilities on the web today, naturally they make their way into the…