ZeroDay Test

ZeroDay Test Don’t Wait for a Breach || Let's Secure your Digital Assets. Bangladesh's First Bug Bounty Platform 🇧🇩

19/09/2026

বরং প্রশ্ন হওয়া উচিৎ ছিল - Breach যেন না হয়, তার জন্য আমরা কী করেছি? 🚨

Don’t Wait for a Breach, Secure your Digital Assets with ZeroDay Test 🇧🇩

🎉 1,000 HUNTERS. ONE BIG MILESTONE. 🎉What started as an idea to build a stronger cybersecurity ecosystem is now a commun...
14/09/2026

🎉 1,000 HUNTERS. ONE BIG MILESTONE. 🎉

What started as an idea to build a stronger cybersecurity ecosystem is now a community of 1,000+ Hunters on ZeroDay Test. 🌍

Every registration represents a security researcher ready to find vulnerabilities, every report helps organizations become more secure, and every client who trusts the platform helps us move this ecosystem forward.

A heartfelt THANK YOU to all our Hunters, Clients, Partners & Supporters. ❤️
This milestone belongs to all of you.

🚀 1,000 Hunters today. A safer digital ecosystem tomorrow.
And this is only the beginning.

🛡️ ZeroDay Test — by Byte Capsule

Can a Bangladesh-born cybersecurity platform compete with global giants like Bugcrowd? We believe the question isn’t sim...
12/09/2026

Can a Bangladesh-born cybersecurity platform compete with global giants like Bugcrowd?

We believe the question isn’t simply “Who is bigger?”
It’s “Which platform fits your organization better?”

With ZeroDay Test, we’re building a security ecosystem designed with Bangladesh and South Asia in mind—combining:

🔐 Bug Bounty & VDP
🎯 Private & Targeted Testing
🛡️ Expert Triage & Validation
🌐 A growing ethical hacker community
🤝 Direct local communication & support
🔎 VAPT, Pentesting & Security Consulting through our broader ecosystem

Our goal isn’t to copy global platforms.

Our goal is to build something that understands our market, our organizations and our security challenges—while growing globally. 🚀

This is an illustrative positioning comparison, not a claim that one platform is universally better than the other.

ZeroDay Test — Built in Bangladesh. Thinking Global.

🚀 ZeroDay Test  vs. HackerOne - Built for a Different Reality.HackerOne has built a strong global presence in bug bounty...
11/09/2026

🚀 ZeroDay Test vs. HackerOne
- Built for a Different Reality.

HackerOne has built a strong global presence in bug bounty. But does every organization need a one-size-fits-all global platform?

ZeroDay Test takes a different approach.

🇧🇩 Bangladesh-first. Global-ready.

Why organizations may choose ZeroDay Test:

🔹 Localized support & communication
🔹 Flexible VDP, Bug Bounty & Private Bug Bounty programs
🔹 Cost-effective security testing options
🔹 Managed vulnerability triage
🔹 Access to a growing ethical hacker community
🔹 VAPT, ISMS Audit, Training & Consulting under one security ecosystem
🔹 Programs tailored to organizational needs
🔹 A long-term security partnership—not just a platform

The goal isn't simply to find vulnerabilities.

The goal is to help organizations understand, manage and reduce their real-world security risk.

🌐 ZeroDay Test — by Byte Capsule

More Hunters. More Coverage. More Value.

🔐 SQL Injection: The Vulnerability That Turns Data Queries into Attack Pathsএকটা সাধারণ database query—আর সেখান থেকেই শু...
09/09/2026

🔐 SQL Injection: The Vulnerability That Turns Data Queries into Attack Paths

একটা সাধারণ database query—আর সেখান থেকেই শুরু হতে পারে পুরো application compromise.

SQL Injection (SQLi) এমন একটি vulnerability যেখানে attacker application-এর input manipulation করে database query-এর logic পরিবর্তন করতে পারে। এর মাধ্যমে sensitive data exposure, authentication bypass, unauthorized data modification—এমনকি কিছু পরিস্থিতিতে deeper system compromise-এর পথও তৈরি হতে পারে।

কিন্তু SQL Injection শুধু `' OR 1=1 --` টাইপের payload-এর মধ্যে সীমাবদ্ধ নয়।

একজন security tester-এর জন্য গুরুত্বপূর্ণ হলো বোঝা:

🔹 কোথায় untrusted input SQL query-তে পৌঁছাচ্ছে
🔹 Error-based, Union-based, Blind & Time-based SQLi কীভাবে কাজ করে
🔹 Authentication ও authorization-এর উপর SQLi-এর প্রভাব
🔹 Modern frameworks ও ORMs কীভাবে SQLi risk কমায়—এবং কোথায় ভুল implementation আবার vulnerability তৈরি করে
🔹 কীভাবে secure parameterized queries, prepared statements ও proper input handling দিয়ে SQLi প্রতিরোধ করা যায়

The real skill isn't just finding SQL Injection—it's understanding why it exists, how far the attack can go, and how to eliminate the root cause.

💬 আপনার মতে, modern web applications-এ SQL Injection এখনও কতটা critical threat?

*******onTesting

🔐 DON’T WAIT FOR A BREACH. TEST BEFORE ATTACKERS DO.Every digital product has weaknesses. The real question is—will you ...
05/09/2026

🔐 DON’T WAIT FOR A BREACH. TEST BEFORE ATTACKERS DO.

Every digital product has weaknesses. The real question is—will you discover them first?

With ZeroDay Test, organizations can leverage ethical hackers to continuously identify and responsibly report vulnerabilities within an authorized scope.

🛡️ Continuous Security Testing
🔎 Real-world Vulnerability Discovery
👨‍💻 Ethical Hacker Community
📋 Responsible Disclosure
🚀 Stronger Digital Security

Know your weaknesses before attackers do.

🌐 ZeroDay Test — A Saas platform of Byte Capsule

*******onTesting

🔐 Attackers Test Your Security. Why Shouldn’t You?Cybersecurity isn’t about waiting for a breach  - it’s about finding w...
05/09/2026

🔐 Attackers Test Your Security. Why Shouldn’t You?

Cybersecurity isn’t about waiting for a breach - it’s about finding weaknesses before attackers do.

With ZeroDay Test, organizations can leverage a community of ethical hackers to continuously identify and responsibly report vulnerabilities within an authorized scope.

🛡️ Continuous Security Testing
🔎 Vulnerability Discovery
👨‍💻 Ethical Hacker Community
📋 Responsible Vulnerability Disclosure
🔐 Stronger Digital Security

Know your weaknesses before attackers do.

🌐 www.zerodaytest.com

*******onTesting

একটি CV শুধু চাকরির Piece of Paper নয়, এটা আপনার Digital Identity-এর Blueprint.সম্প্রতি প্রায় ৬০ লাখ বাংলাদেশির CV ডার...
25/08/2026

একটি CV শুধু চাকরির Piece of Paper নয়, এটা আপনার Digital Identity-এর Blueprint.

সম্প্রতি প্রায় ৬০ লাখ বাংলাদেশির CV ডার্ক ওয়েবে বিক্রির দাবি নিয়ে আলোচনা শুরু হয়েছে। বিষয়টি সত্যিই Bdjobs.com Ltd. -এর database থেকে এসেছে কি না, সেটা সরকারের Liability থেকে যাচাই করা জরুরি। কারণ শুধু Dark Web-এ কোনো database বিক্রির বিজ্ঞাপন দেখলেই breach প্রমাণিত হয় না।

কিন্তু প্রশ্নটা অন্য জায়গায় -

একটা CV Leak হলে আসলে কী হতে পারে?

একটি CV-তে থাকতে পারে -

🔹 Full Name
🔹 Phone Number
🔹 Email Address
🔹 বর্তমান/স্থায়ী ঠিকানা
🔹 Date of Birth
🔹 Education & University
🔹 Previous Employer
🔹 Job Position
🔹 Work History
🔹 Skills & Professional Information
🔹 ছবি এবং অন্যান্য ব্যক্তিগত তথ্য

এই তথ্যগুলো আলাদা আলাদা অবস্থায় হয়তো খুব একটা বিপজ্জনক মনে হবে না।

কিন্তু একজন Attacker's কাছে এগুলো একসাথে গেলে তৈরি হয় আপনার একটি Digital Profile।

আর সেখান থেকেই শুরু হতে পারে -

CV Leak → Profiling → Social Engineering → Targeted Phishing → Account Takeover → Financial Fraud

ধরুন, কেউ আপনাকে ফোন করে বলল -

“আপনি কিছুদিন আগে অমুক কোম্পানিতে চাকরির জন্য আবেদন করেছিলেন, আপনার CV আমাদের কাছে আছে…”

এরপর সে আপনার University, Previous Job, Position কিংবা Skills-এর সঠিক তথ্য বলে দিল।

আপনি তাকে বিশ্বাস করার সম্ভাবনা অনেক বেড়ে গেল।

তারপর সে পাঠাতে পারে একটি Fake Interview Link,
Fake HR Portal,
Malicious Document,
অথবা আপনার Login Credential চাওয়ার কোনো Phishing Page।

অর্থাৎ CV leak-এর সবচেয়ে বড় বিপদ শুধু Privacy Loss নয়।

এটা ব্যবহার করে আপনার বিরুদ্ধে আরও বিশ্বাসযোগ্য Social Engineering Attack তৈরি করা সম্ভব।

আরও একটি বিষয় গুরুত্বপূর্ণ -

Bdjobs-এর নিজস্ব Privacy Policy অনুযায়ী CV-তে নাম, ফোন, email, education, work experience, skills, photo, location ইত্যাদি তথ্য থাকতে পারে এবং ব্যবহারকারীর CV searchable করার নিয়ন্ত্রণও রয়েছে।

তাই আমাদের CV-কে “শুধু চাকরির ডকুমেন্ট” হিসেবে দেখলে ভুল হবে।

CV হচ্ছে আপনার Digital Identity-এর একটি গুরুত্বপূর্ণ অংশ।

এবং আজকের দিনে প্রশ্ন হওয়া উচিত শুধু -

“আমার Password Leak হয়েছে কি না?”

বরং “আমার সম্পর্কে একজন Attacker কতটা তথ্য সংগ্রহ করতে পারছে?”

⚠️ তাই অপ্রয়োজনীয় Personal Information CV-তে না দেওয়া, একই Password একাধিক জায়গায় ব্যবহার না করা, MFA/2FA চালু রাখা এবং সন্দেহজনক Job/Interview Link যাচাই করা এখন আগের চেয়ে অনেক বেশি গুরুত্বপূর্ণ।

আর এই ঘটনায় সবচেয়ে গুরুত্বপূর্ণ বিষয় হলো -
দাবি, প্রমাণ এবং উৎস - এই তিনটাকে আলাদা করে দেখা।

কারণ Cybersecurity-তে আতঙ্ক নয়, evidence-based analysis-ই সবচেয়ে গুরুত্বপূর্ণ। এ বিষয়টাকে হাসিতামাশা করে উড়ানোরও কিছু নেই।

🔐 REST API Security বুঝুন: কেন আধুনিক হ্যাকাররা এখন ওয়েবসাইটের চেয়ে API-কে বেশি টার্গেট করে?একসময় সাইবার আক্রমণের প্র...
07/07/2026

🔐 REST API Security বুঝুন: কেন আধুনিক হ্যাকাররা এখন ওয়েবসাইটের চেয়ে API-কে বেশি টার্গেট করে?

একসময় সাইবার আক্রমণের প্রধান লক্ষ্য ছিল ওয়েবসাইট। কিন্তু এখন পরিস্থিতি বদলে গেছে। আধুনিক হ্যাকাররা ধীরে ধীরে তাদের ফোকাস সরিয়ে নিচ্ছে REST API-এর দিকে।

কেন?

কারণ আজকের প্রায় প্রতিটি ডিজিটাল সেবা—মোবাইল অ্যাপ, ওয়েব অ্যাপ, ই-কমার্স, ব্যাংকিং, ফিনটেক, SaaS, এমনকি IoT ডিভাইস—সবকিছুই API-এর মাধ্যমে একে অপরের সাথে যোগাযোগ করে। অর্থাৎ, API-ই এখন অ্যাপ্লিকেশনের মূল দরজা।

ZeroDay Test এর ভালনারেবিলিটি ব্লগ সিরিজ এ এবার Topic - Understanding REST API Security: Why Modern Applications Depend on APIs

💢 Explore - https://zerodaytest.com/blog/understanding-rest-api-security-why-modern-hackers-target-apis-instead-of-websites

যদি একটি API নিরাপদ না হয়, তাহলে একজন আক্রমণকারী অনেক সময় ওয়েবসাইটে না গিয়েই সংবেদনশীল তথ্য, ব্যবহারকারীর অ্যাকাউন্ট বা গুরুত্বপূর্ণ ফাংশনে প্রবেশ করতে পারে।

API Security-তে সবচেয়ে বেশি দেখা যায় এমন কিছু দুর্বলতা হলো:

🔹 Broken Object Level Authorization (BOLA / IDOR)
🔹 Broken Authentication
🔹 Excessive Data Exposure
🔹 Lack of Rate Limiting
🔹 Mass Assignment
🔹 Broken Function Level Authorization
🔹 Business Logic Vulnerabilities

অনেক প্রতিষ্ঠান এখনও শুধুমাত্র তাদের ওয়েবসাইটের নিরাপত্তা নিয়ে কাজ করে, অথচ একই অ্যাপ্লিকেশনের API সম্পূর্ণভাবে উপেক্ষিত থেকে যায়। বাস্তবে, এই API-ই অনেক বড় ডেটা লিক ও নিরাপত্তা ঝুঁকির কারণ হয়ে দাঁড়ায়।

একজন Web Application Pentester বা Bug Hunter হিসেবে শুধু UI টেস্ট করলেই হবে না। এখন প্রয়োজন—

✅ API Endpoint Enumeration
✅ Authentication ও Authorization Testing
✅ JWT/OAuth Security Testing
✅ Business Logic Testing
✅ Rate Limit Validation
✅ API Fuzzing

ভবিষ্যতের Application Security মানেই API Security।

আপনি যদি Web Security বা Bug Bounty শিখতে চান, তাহলে REST API Security শেখা আর অপশন নয়—এটি এখন একটি অপরিহার্য দক্ষতা।

Mission 2026-এর মাধ্যমে আমরা বাংলা ভাষায় REST API Security ও Web Application Security Testing নিয়ে সম্পূর্ণ প্র্যাকটিক্যাল কনটেন্ট তৈরি করছি, যাতে নতুনরাও ইন্ডাস্ট্রি-রেডি স্কিল অর্জন করতে পারে।

আপনার প্রতিষ্ঠানের API কি সত্যিই নিরাপদ?

*******onTesting #বাংলায়_সাইবার_সিকিউরিটি

🔐 OAuth নিরাপদ—তবে ভুলভাবে Implement করলে এটি বড় ধরনের Security Risk-এ পরিণত হতে পারে।বর্তমান সময়ে OAuth ব্যবহার করা হ...
05/07/2026

🔐 OAuth নিরাপদ—তবে ভুলভাবে Implement করলে এটি বড় ধরনের Security Risk-এ পরিণত হতে পারে।

বর্তমান সময়ে OAuth ব্যবহার করা হচ্ছে অসংখ্য Web Application ও API-তে। কিন্তু Redirect URI Validation, State Parameter Handling, Scope Misconfiguration, Access Token Leakage কিংবা Authorization Flow-এর দুর্বলতা কাজে লাগিয়ে একজন আক্রমণকারী Unauthorized Access অর্জন করতে পারে।

Security Testing-এর সময় OAuth শুধুমাত্র Login Feature হিসেবে দেখলেই হবে না; পুরো Authorization Flow, Token Handling এবং Trust Relationship গভীরভাবে যাচাই করা জরুরি।

ZeroDay Test এর ভালনারেবিলিটি ব্লগ সিরিজ এ এবার ৪ টি পর্বে আমরা OAuth Vulnerability Testing-এর বাস্তবধর্মী Methodology, Common Misconfigurations এবং Exploitation Techniques নিয়ে আলোচনা করেছি, যাতে আপনি বাস্তব Bug Hunting ও Pe*******on Testing-এ এগুলো শনাক্ত করতে পারেন।

🐞 পর্ব ০১ - https://www.zerodaytest.com/blog/part-01-oauth-security-vulnerability
🐞 পব ০২ - https://www.zerodaytest.com/blog/oauth-security-vulnerability-testing-part-02
🐞 পর্ব ০৩ - https://www.zerodaytest.com/blog/oauth-security-vulnerability-testing-part-03
🐞 পর্ব ০৪ - https://www.zerodaytest.com/blog/oauth-security-vulnerability-testing-part-04

💬 আপনার অভিজ্ঞতায় সবচেয়ে ইন্টারেস্টিং OAuth Vulnerability কোনটি? কমেন্টে জানাতে পারেন।

*******onTesting

Address

Level 04, 15 Indira Road, Farmgate
Dhaka
1215

Alerts

Be the first to know and let us send you an email when ZeroDay Test posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share