Lokanath Pradhan

Cybersecurity Researcher · Bug Bounty Hunter · Developer

Cybersecurity professional with hands-on experience in web application & network vulnerability assessment, bug bounty research, and security tool development. 50+ vulnerability reports submitted across HackerProof, HackerOne, Bugcrowd, immunefi (Web3), and direct disclosures — with bounty-paid and resolved findings at Max Healthcare, Perfios, TATA Motors, HDFC Life, Synology, Adidas, and Hero MotoCorp. Critical-severity Web3 finding on Berachain. Proficient in Python, Go, JavaScript, and Shell scripting.

Languages

JavaScript Python Golang Bash PowerShell HTML5/CSS3

Frameworks

React.js Flask Django

Security Tools

Burp Suite Nuclei Metasploit Nmap Wireshark

Cybersecurity

Web App Pentesting Bug Bounty OSINT Red Teaming SOC L1 Network Recon

Dev & Cloud

Git / GitHub AWS Docker Telegram API

Vuln Classes

SSRF XSS CORS Cache Poisoning PII Exposure Host Header Injection Web3 / Mempool
Independent Security Researcher
Bug Bounty — HackerProof, HackerOne, Bugcrowd, immunefi, Direct Disclosure
2024 – Present
  • 50+ vulnerability reports across 6+ platforms; findings include Bounty-Paid, Resolved, and In-Review statuses across public and private programs.
  • HackerProof (Com Olho) — 38 reports at Max Healthcare, Perfios, Allcargo, TATA Motors, HDFC Life, Zerodha, Orient Electric and more. Bounty-paid: Unauthenticated PII Exposure (Perfios P4), Session Cookie Server-Side Exceptions (Max Healthcare P2).
  • HackerOne — Reports at LinkedIn (Business Logic / Rate Limit Bypass, High), 8x8 (Host Header Injection / Cache Poisoning, Medium), Remitly, Deribit, Status (CVE-2025-59474).
  • immunefi (Web3) — Critical finding on Berachain: Public RPC leaks live Mempool data via txpool_content, enabling frontrunning attacks (#50274).
  • Direct Disclosure — SSRF + OAuth PII leakage (Adidas); Nginx Config Disclosure (Hero MotoCorp, acknowledged); CORS Misconfiguration CDN credential leakage, High (Synology).
  • Bugcrowd — Directory Listing (Monash University), Prometheus Node Exporter on 26 production hosts (Opera), AWS Access Key Exposure, DNS Rebinding (Ibotta).
Proof of findings (Gist)

Python Intern
Twintechn Engineering & Design Technology Pvt. Ltd.
2023 · 1 Month
  • Contributed to Python automation scripts during a 1-month internship.
  • Gained practical exposure to real-world software engineering and development workflows.
CredStore
Cross-platform credential management / password manager app.
PythonFlask
EvilEye
IoT offensive security tool based on ESP32 Node MCU.
C/C++ESP32
TLDX
Top-level domain expansion tool using the IANA domain list.
Python
403
HTTP 403 bypass tool for penetration testers.
PythonBash
CryptoCut
Web3 fuzzing tool for smart contract security testing.
JavaScriptWeb3
turtle
CLI file sharing tool via Telegram Bot API with config automation.
GolangTelegram API
netcon
Network misconfiguration discovery tool.
PythonBash
More tools and research available on my GitHub profile.
github.com/locamartin
7+
HTB Badges
10
THM Paths
50+
Vuln Reports
6+
Platforms

Completed TryHackMe paths:

Web App Red Teaming Red Teaming Web App Pentesting Jr. Penetration Tester SOC Level 1 Security Engineer Cyber Security 101 Pre-Security DevSecOps Web Fundamentals
Web Application Red Teaming
TryHackMe · THM-QTORDPWTLH
Feb 2026
Red Teaming Certificate
TryHackMe · THM-MX2CT1OWUV
Feb 2026
Web Application Pentesting
TryHackMe · THM-VFQY7ULUSF
Feb 2026
Jr Penetration Tester
TryHackMe · THM-RZ5TO4GFL3
Feb 2026
SOC Level 1
TryHackMe · THM-BWZLC7GWR8
Feb 2026
Security Engineer
TryHackMe · THM-52XT7PRMM7
Feb 2026
DevSecOps
TryHackMe · THM-6O8OSRSEXB
Jan 2026
AWS Introduction to Containers
Amazon Web Services · a263bbef-b739-4f49-ad5a-073faa97ad71
Jan 2026
Tech Mahindra Cybersecurity (MSDE Skill India)
NSDC · 9390e20a-9cac-48f7-9fb4-35eddca4aeae
Jul 2025
ISC2 Candidate
ISC2 · 2a33246e-6a45-4269-a9dd-220cc3e1daa4
Jun 2025
Cybersecurity Fundamentals
IBM · 31252357-04ef-4b8d-a97e-09334cc7d933
Jun 2025
CS & Engineering (Diploma)
KIIT Polytechnic, Bhubaneswar
2023
PGDCA
UCC Utkal Computer Center
2019
+2 / 12th
C.H.S.E Board, Odisha
2020