SECURITY RESEARCH & EDUCATION Β· BENGALURU, INDIA

Breaking systems.
Built for the next researcher.

Independent security research and free education for the bug bounty and pentesting community. Real vulnerabilities. Real techniques. No paywalls.

anveshan@labs ~ security-research
$ ./recon.sh --target remitly.com
β†’ Mapping OAuth endpoints...
βœ“ CRITICAL: OAuth account takeover found

$ ./email-inject.py --bypass decimal-ip
β†’ Testing: http://1733060568 (no dots)
βœ“ BYPASS: Dot sanitization evaded

$ python3 jwt_tool.py --crack rockyou.txt
⚠ Key not in dictionary (strong secret)

$ cat achievements.log
β†’ Hall of Fame: Remitly βœ“
β†’ Critical Severity: 1 confirmed
β†’ 19 research articles published
$ _
19+
Articles
11+
Lab Videos
3yr
Research
CRIT
Top Severity
Free
Always
Security services,
built by a researcher.

Every service below comes from real hands-on experience finding vulnerabilities in production systems. Pick what you need or reach out to scope a custom engagement.

Services are offered on a project basis, short-term contract, or retainer. Each engagement is scoped on a discovery call and quoted per project. All work is backed by real bug bounty research experience across major platforms.

Book a call β†’
01
Web Application Penetration Testing
Manual security assessment of web applications and APIs using real attacker methodology β€” the same techniques used in active bug bounty research.
Project-based Short-term contract
  • Authentication and session management testing
  • IDOR and access control assessment
  • OAuth and JWT security review
  • Business logic vulnerability testing
  • Detailed report with reproduction steps
Quoted per scopeReach out
02
LLM & AI Agent Security Assessment
Security assessment of LLM-powered applications and autonomous AI agents β€” prompt injection, excessive agency, insecure output handling, and agent attack surfaces.
Project-based Freelance
  • Indirect prompt injection testing
  • Agent tool abuse assessment
  • Data exfiltration via agent workflows
  • OWASP LLM Top 10 coverage
  • Red team report with attack scenarios
Quoted per scopeReach out
03
Technical Security Content (YouTube & Blog)
Deep technical security content for your brand or channel. CVE breakdowns, vulnerability walkthroughs, tool reviews β€” produced end-to-end or ghost-published.
Freelance Long-term retainer Project-based
  • Researched script with real payloads and demos
  • Screen recording and technical walkthrough
  • Published on your channel or ours
  • Blog articles: 1,500–4,000 words, SEO-optimized
Quoted per scopeReach out
04
Bug Bounty Consultation & Mentorship
Hands-on guidance for security researchers looking to improve methodology, target selection, and report quality. From beginner to first bounty.
Short-term contract Freelance
  • 1-on-1 methodology sessions
  • Report review and quality improvement
  • Target selection and attack surface mapping
  • Real finding walkthroughs and analysis
Quoted per scopeReach out
05
Security Awareness Training
Practical security training for developer teams and non-technical staff. Real attack demonstrations, not slide decks. Built for people who need to understand threats, not pass a certification.
Project-based Short-term contract
  • Live attack demonstrations
  • Developer-focused secure coding sessions
  • Phishing and social engineering awareness
  • Custom curriculum for your team
Quoted per scopeReach out
06
Responsible Disclosure Support
Help organizations set up or improve their vulnerability disclosure program. Policy writing, triage process design, and researcher communication templates.
Project-based Freelance
  • VDP/BBP policy drafting
  • Scope definition and asset classification
  • Triage workflow design
  • Researcher communication templates
Quoted per scopeReach out
Retainer β€” The full lab, on retainer.
For security teams and content brands that want ongoing research, testing, and content without thinking about it. Pick any combination of services above, bundled into a monthly engagement with dedicated capacity.
Dedicated research roadmap Weekly working sessions Priority delivery Monthly review
Let's scope it β†’

Built for learners,
by a learner.

Patliputra Anveshan Labs is an independent security research initiative founded by Rishu Raj Singh β€” a bug bounty researcher and security educator based in Bengaluru, India.

The mission: make high-quality security education accessible to everyone regardless of background or budget. Every video, writeup, and resource here is free. Services exist to fund the research.

Research covers real-world web application security β€” the same techniques used to find vulnerabilities in production systems at companies like Remitly, BrowserStack, Zendesk, Flipkart, and others.

# HackerOne: rishusec Β· Bugcrowd: Rishuraj2666 Β· Intigriti: active

CRITICAL Β· HOF
Hall of Fame β€” Remitly
Critical severity OAuth authentication vulnerability on a regulated US fintech. Independently discovered and responsibly disclosed via HackerOne.
NOVEL TECHNIQUE
Decimal IP Encoding Bypass
Independently discovered decimal IP encoding (http://1733060568) bypasses dot-based URL sanitization β€” applicable across multiple major platforms.
EDUCATION
IIIT Bangalore Β· IIT Mandi Β· NPCI
Executive PG Diploma in Cybersecurity (IIIT-B). Minors in CSE (IIT Mandi). Application security internship at NPCI β€” National Payments Corporation of India.

Research &
writeups.

Technical security research articles covering real vulnerabilities, attack techniques, and security concepts. Published on Medium.

OAUTH
Breaking Google OAuth: How Account Merge Vulnerabilities Lead to Complete Account Takeover
How OAuth account merge vulnerabilities allow pre-authentication account takeover β€” including the 2FA permanent lockout chain.
Sep 2026Read β†’
WEB CACHE
How I Learned Web Cache Poisoning from James Kettle's Demo
A deep dive into web cache poisoning β€” one of the most overlooked and impactful vulnerability classes in modern web security.
Jul 2025Read β†’
ATO CHAIN
From OTP Bypass to Full Account Takeover: Chaining Three Overlooked Flaws
How three individually low-impact vulnerabilities chain together to create a Critical account takeover on a major platform.
May 2025Read β†’
OPEN REDIRECT
Redirect Gone Wrong: How I Chained Open Redirect to Steal Sessions
Open redirects are often dismissed as low-impact β€” this writeup shows how to chain them into real session theft.
Jun 2025Read β†’
AI SECURITY
I Found a Way to Control Google AI's Decoding Logic Using ASCII
How encoded ASCII characters can manipulate AI response behavior β€” an early exploration into LLM security research.
Apr 2025Read β†’
HTTP SMUGGLING
How HTTP Request Smuggling Gets You a $750 Bug Bounty
A practical guide to HTTP request smuggling β€” how CL.TE and TE.CL desync attacks work and how to find them in the wild.
Nov 2024Read β†’
RCE
RCE Through Monitoring Debug Mode
How a debug monitoring endpoint transformed black box testing into semi-white box β€” leading to remote code execution discovery.
Oct 2024Read β†’
XSS
Hidden Reflected XSS on 403 Page
Error pages are overlooked testing surfaces β€” this writeup covers finding reflected XSS on a 403 forbidden response.
Oct 2024Read β†’
AUTH BYPASS
Breaking the Lock: Real-World Authentication Bypass Techniques
A collection of authentication bypass techniques encountered across real bug bounty programs β€” with reproduction steps.
Apr 2025Read β†’
View all articles on Medium β†’

Free lab
walkthroughs.

Practical PortSwigger Web Security Academy solutions β€” access control, authentication, IDOR, OAuth, and LLM security. Free forever.

IDOR
User ID controlled by request parameter with password disclosure
PortSwigger Β· Access Control
AUTH
Password reset broken logic lab
PortSwigger Β· Authentication
OAUTH
Authentication bypass via OAuth implicit flow
PortSwigger Β· OAuth Security
IDOR
Insecure direct object references
PortSwigger Β· Access Control
2FA
2FA simple bypass lab
PortSwigger Β· Authentication
INFO LEAK
User ID with data leakage in redirect
PortSwigger Β· Access Control
View all videos β†’

Real findings.
Responsible disclosure.
πŸ”
OAuth Account Merge Vulnerability β€” Remitly
Critical severity pre-authentication ATO via OAuth account merge. Unverified email/password account gains access to KYC-verified account on a regulated US fintech serving millions.
CRITICALHALL OF FAME
πŸ“§
Decimal IP Encoding Bypass β€” Email Injection
Independently discovered decimal IP encoding (http://1733060568) bypasses dot-based URL sanitization across multiple major platforms including BrowserStack and Zomato.
NOVEL TECHNIQUEMULTI-PLATFORM
πŸ”‘
Session Tokens Not Invalidated β€” Crypto Exchange
JWT tokens remain valid after logout AND password reset on a crypto exchange. 7-day persistent access window β€” victim has no way to revoke attacker access by changing password.
SESSION MGMTFINTECH
πŸ€–
LLM Indirect Prompt Injection β€” Agent Security
Demonstrated indirect prompt injection where malicious content in product reviews causes AI agents to execute delete_account API calls against other authenticated users.
AI SECURITYAGENT ATTACKS

Your next security partner
probably shouldn't be a stranger.
// reach out

For security assessments or services β€” email with your project scope and timeline. Discovery calls are free.

For vulnerability disclosures β€” use HackerOne or Bugcrowd. Responsible disclosure only.

For content collaboration or mentorship β€” LinkedIn or email directly.

For speaking or training engagements β€” email with event details and audience profile.


rishuraj2666@gmail.com β†’