Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
View Maniesh-Neupane's full-sized avatar
🎯
Focusing
🎯
Focusing

Organizations

@pwn4arn

Block or report Maniesh-Neupane

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Maniesh-Neupane/README.md

Maniesh Neupane (Pwn4arn)

Web App Pentester • Offensive Security Researcher • AWS Cloud Security

Finding real-world security flaws in web applications and cloud infrastructure


🧠 About Me

  • 🛡️ 90+ security vulnerabilities reported across 30+ enterprise bug bounty programs
  • 🏆 Hall of Fame: Apple Security · Google VRP · Microsoft MSRC
  • ☁️ AWS Cloud Security — IAM auditing, GuardDuty, CloudTrail, Security Hub
  • 🔴 Offensive Security — IDOR, SSRF, Auth Bypass, API Security, Mobile Pentesting
  • 🎓 Bachelor of Computer Applications (BCA) — Tribhuvan University · 2023–2027
  • 🌍 Identity: pwn4arn / manieshneupane · Based in Nepal

🌐 Digital Presence


🛠️ Skills & Tools

Offensive Security

AWS Cloud Security

Infrastructure & Platform


🔴 Security Focus Areas

Web & Mobile Pentesting

  • Web Application Penetration Testing (OWASP Top 10)
  • Broken Access Control · IDOR · Business Logic Flaws
  • SSRF · Authentication Bypass · Session Management
  • API & GraphQL Security Testing
  • Android APK Static & Runtime Analysis (JADX · Genymotion)

☁️ AWS Cloud Security

  • IAM Policy Auditing · Least Privilege Enforcement
  • Privilege Escalation Path Analysis (iam:PassRole · sts:AssumeRole)
  • CloudTrail Log Analysis · Root Account Monitoring
  • Amazon GuardDuty Threat Detection
  • AWS Security Hub · Foundational Security Best Practices
  • S3 Bucket Security Auditing · Encryption & Access Controls
  • MITRE ATT&CK Cloud Technique Mapping

"I find the vulnerabilities that automated scanners miss."

📩 manieshneupane@gmail.com

Popular repositories Loading

  1. BugBounty-Recon-Methodology BugBounty-Recon-Methodology Public

    BugBounty-Recon-Methodology

    322 77

  2. SQL.txt SQL.txt Public template

    The list of SQL injection payloads for fuzzing

    14 2

  3. Cyber-Security-Interview-Preparation- Cyber-Security-Interview-Preparation- Public

    Here are the list of cyber security interviews questions and answers

    14 1

  4. CarRental-Portal CarRental-Portal Public

    It is Created using CSS , HTML , JS on Frontend and on Backend PHP and MySQL are used.

    PHP 13

  5. ISS.txt ISS.txt Public

    12 1

  6. Blood-Bank-Management-Portal Blood-Bank-Management-Portal Public

    The Blood Bank Management Portal is a desktop-based application developed using Core Java. It is designed to bridge the gap between blood donors and recipients. This system automates the maintenanc…

    Java 12

Morty Proxy This is a proxified and sanitized view of the page, visit original site.