PAYATU

Nikhil Mittal

Ex-Bandit
Former Security Consultant at Payatu, working on web and application security. Has authored 7 blogs, 9 published CVEs, 2 talks/webinars for Payatu.
PAYATU

Nikhil Mittal

Ex-Bandit
Former Security Consultant at Payatu, working on web and application security. Has authored 7 blogs, 9 published CVEs, 2 talks/webinars for Payatu.
Former Security Consultant at Payatu, working on web and application security. Has authored 7 blogs, 9 published CVEs, 2 talks/webinars for Payatu.
PAYATU

Nikhil Mittal

Ex-Bandit

CVEs published

Vulnerabilities discovered and responsibly disclosed. Each links to the Payatu advisory.

Safari Address Bar Spoof

Safari Address Bar Spoof This vulnerability allows an attacker to spoof safari address bar
Browser
Spoofing
Medium
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

massCode Code execution

massCode Code execution This vulnerability allows an attacker perfrom code execution on massCode editor
Developer Tools & Libraries
Cross-Site Scripting (XSS)
Medium
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Safari video permission spoof

Safari video permission spoof Using this vulnerability an attacker can trick the victim to grant website permissions to a website they didn’t intend to
Browser
Authentication & Access Bypass
Medium
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Articles by  

Nikhil Mittal

No items found.
My hacking adventures with Safari reader mode
August 27, 2020
No items found.
No items found.
No items found.
Web & API
Exploit dev & reverse engineering
Browser Security
Executing scripts in Safari Reader Mode to CSP Bypass
April 28, 2020
6 mins
Web & API
Exploit dev & reverse engineering
Browser Security
Engineers
Researchers
Research & disclosures
Guides & tutorials
Browser Security
Web & API
windows
That Evil Bookmark API in your Browser
February 26, 2020
6 mins
Browser Security
Web & API
windows
Engineers
Researchers
Research & disclosures
Application Security
Web & API
MassCode Code Execution (CVE-2020-8548)
February 4, 2020
2–3 mins
Application Security
Web & API
Engineers
Researchers
Research & disclosures
Browser Security
Mobile
Get Pwned By Scanning Firefox QR Code Reader
December 10, 2019
4–5 mins
Browser Security
Mobile
Engineers
Researchers
Research & disclosures
Web & API
windows
Browser Security
Microsoft Edge Extensions Host-Permission Bypass (Cve-2019-0678)
June 6, 2019
8–10 mins
Web & API
windows
Browser Security
Engineers
Researchers
Research & disclosures

The Bandits

Conferences, podcasts and workshops.
Bandits
All

Abizer Naseem

Security Consultant
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Abizer Naseem

Security Consultant
Dark gray arrow pointing to the right on a transparent background.White arrow pointing diagonally upward to the right on a black square background.
All
Bandits

Ajay S.K

IoT Firmware Security Researcher
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Ajay S.K

IoT Firmware Security Researcher
Dark gray arrow pointing to the right on a transparent background.White arrow pointing diagonally upward to the right on a black square background.
All
Bandits

Akanksha Prasad

Co-Lead - Web Application
Dark gray arrow pointing to the right on a transparent background.Dark gray arrow pointing to the right on a transparent background.

Akanksha Prasad

Co-Lead - Web Application
Dark gray arrow pointing to the right on a transparent background.White arrow pointing diagonally upward to the right on a black square background.