
bug-bounty-reports-desai-vinayak
Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

DNS Vulnerability - CVE-2020-1350

Shared technical notes and debugging documentation for CVE-2015-5477, a BIND DNS denial-of-service vulnerability. Focuses on reproduction, analysis,…

PoC attack server for CVE-2015-7547 buffer overflow vulnerability in glibc DNS stub resolver (public version)

A python tool to check subdomain takeover vulnerability

Security checks for your researches

oPanel DNS-Based Cross-Site Scripting (XSS) & Session Hijacking

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

DNS-based data exfiltration testing tool with bidirectional transfer, web UI, and client script for detecting blind RCE/XXE vulnerabilities in…

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

Automated SPF and DMARC configuration checker that identifies email spoofing vulnerabilities across single or bulk domains using DNS lookups.

A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.

Denial of Service PoC for CVE-2020-1350 (SIGRed)

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…