Sign In

Mayank Kapoor

Red Teamer ► Penetration Tester - Web/Network/Mobile/Cloud ► Security Researcher ► OSCP ► OSWP

Professional Background

Mayank Kapoor is a highly experienced professional in the field of Information Security, known for his extensive skill set that encompasses infrastructure and application penetration testing. His work involves comprehensive security reviews of web services, web applications, thick client systems, and mobile applications for clients spanning diverse industry verticals. With a deep understanding of the intricacies of security processes and technologies, Mayank has successfully conducted informative training sessions aimed at improving security practices across various organizations.

In addition to his role as a Principal Security Consultant at NotSoSecure, where he leads security assessments and solutions, Mayank has held significant positions in several other reputable organizations. His career includes stints as a Security Consultant for Lateral Security (IT) Services Limited, IBM's prestigious X-Force Red Team, SecurView, Inc., and Network Intelligence (I) Pvt. Ltd. He also brings foundational experience as a Web Developer at Infowaves Systems Pvt Ltd, which has further informed his comprehensive approach to security.

Education and Achievements

Mayank Kapoor’s academic background is rooted in a strong technological foundation. He earned a Diploma in Software Engineering from NIIT, complementing it with a Bachelor's degree in Information Technology from Kuvempu University, Shankaraghatta, Shimoga. His education has equipped him with both the theoretical knowledge and practical skills necessary for excelling in the fast-paced realm of Information Security.

Mayank has been recognized for his exceptional contributions to Information Security, notably discovering an XSS vulnerability on Microsoft Dynamics NAV, which was identified as CVE-2018-8651. This significant discovery highlights his prowess in vulnerability assessment and showcases his ability to identify critical security weaknesses that could affect organizations. His accomplishments extend beyond this notable finding; he has published multiple vulnerabilities related to XAMPP 3.2.1 and phpMyAdmin 4.1.6 on esteemed exploit resources, including SecurityFocus, Packetstorm, Exploit-DB, and OSVDB.

Additionally, he has reported Remote Code Execution vulnerabilities to high-profile companies such as Vodafone and Qatar Airways, for which he received commendations from their respective CERT teams. These accolades underscore his reputation in the security community and his commitment to improving the industry’s standards through responsible disclosure practices.

Vulnerability Reporting and Recognition

Mayank Kapoor has been featured in various bug bounty programs, amassing accolades that include recognition in several Hall of Fame listings. His contributions to major tech companies showcase his broad expertise and willingness to collaborate with industry leaders to enhance security measures. Some of the notable companies where he has received such acknowledgments include:

  • Google - Acknowledged for his contributions to their Bug Hunter program.
  • Microsoft - Recognized for his findings contributing to their security enhancements.
  • Yahoo, Adobe, Facebook, Twitter, and Nokia - He has reported multiple security vulnerabilities, earning accolades that reflect his dedication to security excellence.
  • Additionally, he was acknowledged by Deutsche Telekom, eBay, and BlackBerry, fortifying his status as a significant contributor within various security communities.

Mayank's process-oriented attitude towards security sets him apart in the industry. He advocates that effective security is not merely about the tools employed, but heavily relies on a thorough understanding of the underlying processes and technologies involved. This philosophy informs his consulting practices and training methodologies, ensuring that his clients receive a holistic view of security that empowers them to tackle vulnerabilities proactively.

Conclusion

With a stellar track record in the Information Security domain, Mayank Kapoor exemplifies what it means to be a dedicated and knowledgeable security consultant. His blend of hands-on experience, formal education, and genuine passion for protecting digital assets makes him a valuable resource for organizations striving to strengthen their cybersecurity posture. Whether it's through direct consulting engagements, conducting training workshops, or contributing to the broader security community through vulnerability disclosures, Mayank's contributions continue to make a lasting impact in the field of Information Security.

Related Questions

How did Mayank Kapoor develop his profound knowledge in Information Security?
What are some key methodologies employed by Mayank Kapoor when conducting security reviews?
Can you detail some of Mayank Kapoor's most significant findings in his security career?
What impact has Mayank Kapoor's work had on the organizations he has consulted for in terms of enhancing their security posture?
How has Mayank Kapoor's educational background influenced his approach to cybersecurity?
Mayank Kapoor
Add to my network

Location

Amritsar, Punjab, India