Nidal Khan
Whoami
My name is Nidal Khan and most people in the security community know me as mrknightnidu. I am an independent security researcher and bug bounty hunter from Pakistan with 3+ years of experience. Bug hunting is a big part of my daily life. I mostly work on web apps, APIs, SDKs, mobile and open source projects. I spend around 30 to 40 hours every week reading code, testing targets, building PoCs and writing reports. Right now I am ranked #10 globally and #1 in Pakistan on Hackrate.
Profile on Hackrate
Profiles on Social Media
Interview
First Steps in Bug Hunting
I was curious about technology from a young age. I used to take toys apart, remove motors and try to build something different from them. By eighth grade I already wanted to become a hacker. Later I started learning HTML, CSS, Python and JavaScript by myself. While searching on YouTube and Google, I found bug bounty and penetration testing and that is where everything started for me. I learned mostly by doing practical work. I submitted many informative, out of scope and invalid reports before getting my first valid bug. It was a broken link hijacking on Tractive and I received £50 on 14 September 2024. For new hunters, my advice is simple: keep learning, practice on real authorized targets, read code and do not give up because of rejected reports.
When I approach a new target, I first try to understand how the application works. I check the users, roles, permissions and trust boundaries. I want to understand who is allowed to do what before I start sending payloads. Then I focus on places where authorization or authentication may be missing.
About the Testing Methodology
I do not follow one fixed checklist for every target. I prefer a whitebox and source code focused approach and change my testing depending on the application. I spend more time understanding the code and application logic than running large scanners. I keep patterns from my previous accepted reports and try them against new targets when they make sense. Before submitting a PoC, I usually test it multiple times to make sure it is reliable.
My main system is Parrot OS. I use different security tools depending on the target and I have my own Python recon tool called Living in the Shadows. I do not really depend on one favorite wordlist because I prefer understanding the application and building my testing around it.
Favorite Bug Classes
My favorite bugs are authorization vulnerabilities, especially missing authorization, broken access control and IDORs. I really like testing APIs and checking if low permission users, API keys or tokens can access something they should not be able to access.
I am interested in SSRF, OAuth, identity related bugs and authentication bypasses too.
Recently I have been spending more time on AI security and prompt injection. I enjoy testing LLM based applications, understanding their system prompts, tools and limitations and seeing if those boundaries can be broken.
Most of the bugs I enjoy finding are logic based bugs that normal scanners usually cannot find.
Certifications and Achievements
I currently hold:
- Certified Web Security Expert (CWSE)
- Certified Associate Penetration Tester (CAPT)
- TryHackMe Junior Penetration Tester
I think certifications are useful, especially when you are starting because they give you a learning path and help you understand the basics. But in bug bounty, practical experience matters more to me. Your reports, findings, bounties and the way you understand real applications show your skills better than certificates alone.
One of my biggest achievements was getting a Google Patch Rewards acceptance for a path traversal security fix that I contributed to protocolbuffers/protobuf. Having my security fix accepted in a project used by so many people was a big moment for me.
I am proud of my authorization findings in Daytona which resulted in GitHub Security Advisories including GHSA-ww63-pv5x-vfc8 and GHSA-qxvm-pcfm-qc39.
I received a $1,500 bounty from Descope and had findings accepted through Microsoft MSRC including work related to dotnet/runtime.
I was invited to the Microsoft MSRC researcher celebration at Black Hat USA 2026.
Right now I am ranked #10 on the Hackrate Global All-Time Reputation Leaderboard and #1 on the Hackrate Pakistan All-Time Leaderboard.
The Google Patch Rewards finding is probably the achievement I am most proud of because I was not only reporting a vulnerability, I contributed a security fix that was accepted into an important open source project.
Future of Bug Bounty
Can bug bounty hunting be a full-time job?
Yes, I believe bug bounty can be a full-time job, but it is not easy. You need consistency, patience and a good methodology. You cannot depend only on luck. You need to keep learning, build your own workflow and understand how to communicate properly with triagers and security teams.
What is the role of automation in security testing?
Automation is very useful for recon, collecting information and saving time on repetitive work. But I do not think automation can replace manual testing. Many high impact authorization and business logic bugs require someone to actually understand how the system works. I prefer using automation for boring and repetitive tasks and spending most of my time on manual testing, source code review and logic.
What are your expectations of bug bounty platforms?
I expect fair and technically strong triage, clear communication, proper severity decisions and timely payouts. One problem today is that security teams receive many low quality or AI generated reports. Good platforms should make sure serious researchers are not ignored because of that noise. I think communication between researchers and triagers is very important because both sides are trying to achieve the same thing, which is making the product more secure.
What is your impression of Hackrate? Will you be one of them?
I am already active on Hackrate and currently ranked #10 globally on the all-time reputation leaderboard and #1 in Pakistan. Because I have used the platform myself, I have experience with it as a researcher instead of only knowing about it from the outside. Being part of the Elite Hackers program would mean a lot to me. I want to continue improving, finding real vulnerabilities and contributing good quality research to the platform. So yes, I would be happy to be one of the Hackrate Elite Hackers.
Badges

Newcomer
11/20/2024
Bounty Hunter
11/21/2024
Hack Everything
7/2/2025
Supporter
7/2/2025