Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile
Nirmal Dahal - #Nittam 

@thenittam

Building Secure Digital Futures with @CryptoGenNepal | Leader at @pentesternepal | Former Leader at @owaspnepal

ID: 734489900

linkhttps://nirmaldahal.com.np calendar_today03-08-2012 08:45:12

259 Tweet

1,1K Followers

87 Following

PenTester Nepal🇳🇵 (@pentesternepal) 's Twitter Profile Photo

"XSS To Account Takeover [Q2A Themes]" writeup is added in 'Pentester Nepal' Medium Publication by Nirmal Dahal - #Nittam : medium.com/pentesternepal… #infosec #PenTest #XSS #PTN

Simran Karki (@51mr4n_) 's Twitter Profile Photo

Here comes my first blog on medium about OODA loop, which is a four-step process for making effective decisions in high-stakes situations. For more info please follow the link below. CryptoGen Nepal link.medium.com/4NSiCKer2ib

PenTester Nepal🇳🇵 (@pentesternepal) 's Twitter Profile Photo

"ByPassing eBay XSS Protection" writeup is added in 'Pentester Nepal' Medium Publication by Nirmal Dahal(Nirmal Dahal - #Nittam ): link.medium.com/N7u3OwvHfjb #infosec #bugbounty #Ebay #XSS #PentetserNepal #medium

"ByPassing eBay XSS Protection" writeup is added in 'Pentester Nepal' <a href="/Medium/">Medium</a> Publication by Nirmal Dahal(<a href="/TheNittam/">Nirmal Dahal - #Nittam </a>):

 link.medium.com/N7u3OwvHfjb

#infosec #bugbounty #Ebay #XSS #PentetserNepal #medium
Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

"leveraging the SQL injection to execute the XSS by evading CSP (Content Security Policy)." Although it sounds silly, I am dumb enough to do this 🥶 Link: link.medium.com/hL0B5II0itb

"leveraging the SQL injection to execute the XSS by evading CSP (Content Security Policy)."

Although it sounds silly, I am dumb enough to do this 🥶

Link: link.medium.com/hL0B5II0itb
Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

Back in June 2022, I found a flaw in the MEGA cloud storage system that let me store more data than they permit for free accounts. I was able to store roughly 1300GB data in MEGA, despite the fact that the free account storage restriction for MEGA is 20GB. nirmaldahal.com.np/posts/2022/11/…

Back in June 2022, I found a flaw in the MEGA cloud storage system that let me store more data than they permit for free accounts. I was able to store roughly 1300GB data in MEGA, despite the fact that the free account storage restriction for MEGA is 20GB.
nirmaldahal.com.np/posts/2022/11/…
PenTester Nepal🇳🇵 (@pentesternepal) 's Twitter Profile Photo

Simran Karki started her YT channel You can follow her channel for infosec and internet safety tips. Congrats 🎉and good wishes to her for creating useful contents! youtube.com/@hercyberworld

CryptoGen Nepal (@cryptogennepal) 's Twitter Profile Photo

CryptoGen Nepal is among #Top250MSSP by MSSP Alert We are thrilled to share this with all of you and we have a continuous drive to focus on Cyber Security and be the Cyber Security Partner by Choice. Full story: cryptogennepal.com/blog/msspalert… #Made4Security #CyberSecurity #MSSP

<a href="/cryptogennepal/">CryptoGen Nepal</a> is among #Top250MSSP by <a href="/msspalert/">MSSP Alert</a> 

We are thrilled to share this with all of you and we have a continuous drive to focus on Cyber Security and be the Cyber Security Partner by Choice.

Full story: cryptogennepal.com/blog/msspalert…

#Made4Security #CyberSecurity #MSSP
Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

We at CryptoGen Nepal dug deep into the #trojan app named #NepaliGirl causing fear in Nepal cyberspace & found some concerning findings. Big shoutout to niraj with whom I have always had a great collaboration experience. Full Report: cryptogennepal.com/case-studies/n…

We at <a href="/CryptoGenNepal/">CryptoGen Nepal</a> dug deep into the #trojan app named #NepaliGirl causing fear in Nepal cyberspace &amp; found some concerning findings.

Big shoutout to <a href="/nirajkharel7/">niraj</a> with whom I have always had a great collaboration experience.

Full Report: cryptogennepal.com/case-studies/n…
Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

Regex mastery is key for Forensics, Red/Blue Teams, Dev roles. Try ReGen - inspired by Burp Suite's Grep and Extract feature, it simplifies Regex crafting. Create the desired Regex with ease. Join to shape Regex simplicity in cybersecurity github.com/TheNittam/ReGen

Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

🚨 CVE-2025-29927 (9.1/10) 🚨 If your app uses Next.js Middleware for authentication, attackers can bypass it. Check if your Next.js version is affected: 1️⃣ Right-click → Inspect 2️⃣ Open Console 3️⃣ Enter next.version Affected Versions & Full Details: github.com/vercel/next.js…

🚨 CVE-2025-29927 (9.1/10) 🚨
If your app uses Next.js Middleware for authentication, attackers can bypass it.

Check if your Next.js version is affected:
1️⃣ Right-click → Inspect
2️⃣ Open Console
3️⃣ Enter next.version

Affected Versions &amp; Full Details:
github.com/vercel/next.js…
Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

Used Gemini Flash (free tier) + Python + AI browser agent to run a basic vuln assessment on DVWA locally. No paid tools. No human clicks. Just AI following prompts. It worked and this is just the beginning. If we can do this now with limitations, imagine what’s future holding.

PenTester Nepal🇳🇵 (@pentesternepal) 's Twitter Profile Photo

We are excited to announce that HackerOne will be our Community Partner for the 12th Anniversary Celebration Program! 🎉 Get ready for an exciting lineup of cybersecurity talks, CTF challenges, and networking sessions. Thank you for your support! #PTN #community #HackerOne

We are excited to announce that <a href="/Hacker0x01/">HackerOne</a> will be our Community Partner for the 12th Anniversary Celebration Program! 🎉
Get ready for an exciting lineup of cybersecurity talks, CTF challenges, and networking sessions.
Thank you for your support! 
#PTN #community #HackerOne
PenTester Nepal🇳🇵 (@pentesternepal) 's Twitter Profile Photo

We’re excited to announce that bugcrowd will be the Supporting Partner for Pentester Nepal’s event! 🎉 Get ready for a thrilling lineup of cybersecurity talks, CTF (Capture The Flag) challenges, and networking sessions. Thank you for your support! #PTN #ItTakesACrowd

We’re excited to announce that <a href="/Bugcrowd/">bugcrowd</a> will be the Supporting Partner for Pentester Nepal’s event! 🎉

Get ready for a thrilling lineup of cybersecurity talks, CTF (Capture The Flag) challenges, and networking sessions.

Thank you for your support! #PTN #ItTakesACrowd
PenTester Nepal🇳🇵 (@pentesternepal) 's Twitter Profile Photo

Thank you Ullens College bugcrowd Altered Security HackerOne APIsec University NCA Nepal Rovix Cloud stickermandu🙏🇳🇵 A huge appreciation to all the amazing speakers, volunteers, & participants who made this event possible! 🎉 We look forward to organizing another event together soon!

Thank you Ullens College <a href="/Bugcrowd/">bugcrowd</a> <a href="/AlteredSecurity/">Altered Security</a> <a href="/Hacker0x01/">HackerOne</a> <a href="/apisecu/">APIsec University</a> NCA Nepal Rovix Cloud stickermandu🙏🇳🇵

A huge appreciation to all the amazing speakers, volunteers, &amp; participants who made this event possible! 🎉
We look forward to organizing another event together soon!
Nirmal Dahal - #Nittam  (@thenittam) 's Twitter Profile Photo

You can use the same testing approach to verify exposure to CVE-2025-55182 (CVSS 10.0 - Critical) Ref: vercel.com/changelog/cve-… Fixed in: React: 19.0.1, 19.1.2, 19.2.1 Next.js: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 15.6.0-canary.58, 16.0.7