Filter:
2 writeups found
More writeups being drafted — SSRF, auth bypass, and subdomain takeover findings coming soon.
Latest NASA · nasa.gov P1 · Critical LOR Awarded Featured

P1 Critical · NASA · 2025

Full Admin Takeover on

NASA's nasa.gov

Directory listing exposed admin usernames on a live NASA subdomain. A simple credential guess unlocked full CMS access — enabling content creation, deletion, file upload, and potential site defacement. Initially dismissed as Informational, resubmitted with PoC and accepted as P1 Critical. NASA issued a Letter of Appreciation.

AD
Aashutosh Devkota
2025 ~10 min read
Read Writeup
admin:admin123
✓ Access Granted
P1 · Critical
Severity
Critical
Let's Connect

Open to Opportunities

Cybersecurity researcher & developer based in Nepal. Available for bug bounty collaboration, penetration testing engagements, and developer roles.

</> {} 0x