Skip to content
View itsmeashim's full-sized avatar

Highlights

  • Pro

Block or report itsmeashim

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
itsmeashim/README.md

Hi 👋, I'm Ashim Chapagain

Cyber Security Engineer · Penetration Tester · Bug Bounty Hunter

profile views trophies


🛡️ About Me

role:       Cyber Security Engineer @ BingoLabs
focus:      [ web app pentesting, api security, source code review ]
education:  B.Sc. CSIT — Tribhuvan University
building:   Plumbr 🔧
ask_me:     cybersecurity · bug bounty · pentesting
portfolio:  chapagaiashim.com.np
  • 🎯 Day job: breaking (and helping fix) web apps & APIs — OWASP Top 10, business logic, source code review
  • 🏆 Hall of fame: CVE-2023-28476 — Stored XSS in Concrete CMS, patched in 9.2.0
  • 🥇 Hackathon: Best Use of Web3 at Vertex Hacks for LeftOverLift
  • 🔭 Currently building Plumbr
  • 📄 Full experience & writeups → chapagaiashim.com.np

🎖️ Certifications

Cert Issuer
eJPT — Junior Penetration Tester INE
Junior Penetration Tester (PT1) TryHackMe
Programming with Google Go Specialization UC Irvine
OWASP Top 10 — 2021 Infosec
JavaScript Security Infosec
Introduction to Model Context Protocol Anthropic

🧰 Tooling & Languages

Offensive Security

Burp Suite OWASP ZAP Kali Linux Nmap

Languages

Python Go JavaScript TypeScript Bash SQL Assembly

Stack & Infra

Linux Docker Git PostgreSQL MySQL Next.js NestJS React


🚀 Featured Projects

  • Certchain — Tamper-proof certificate issuance & verification platform. Next.js (TS) + NestJS + Prisma + PostgreSQL. Designed, built, and security-hardened end-to-end (authn/authz, input validation, API & business logic).
  • LeftOverLift — Web3 food-waste redistribution platform on Polygon with ERC-20 / ERC-721 incentive layer, geo-matching, and SMS notifications. 🏆 Best Use of Web3 at Vertex Hacks.

📊 GitHub Stats

stats top langs

streak


🌐 Connect

LinkedIn Portfolio

"The quieter you become, the more you are able to hear."

Pinned Loading

  1. ghchk ghchk Public

    Go

  2. ProjectHunt-Flow ProjectHunt-Flow Public

    Python

  3. shochk shochk Public

    Validate Shodan API keys quickly and efficiently.

    Go

  4. SONIC-monitor SONIC-monitor Public

    Python

  5. TelegramSocialLinks TelegramSocialLinks Public

    Python