Cybersecurity · Web Application Security · Bug Bounty · CTF
I focus on web application security — finding and responsibly disclosing real vulnerabilities on HackerOne and Bugcrowd. My work centers on understanding how systems break: authentication flaws, access control issues, client and server-side injection, and API abuse.
I play CTFs and machines on HackTheBox and TryHackMe, focusing on web challenges and OSINT. Currently ranked top 3 on TryHackMe.
Web Application Security Sql injection · IDOR · SSRF · SSTI · LFI · RFI · Command Injection · Authentication & Access Control Testing · API Testing · Recon & Enumeration · LLM hacking · Source code review · Oauth hacking · OWASP top 10
Languages
Infrastructure
- Bug bounty hunter on HackerOne and Bugcrowd
- CTF player on HackTheBox and TryHackMe — top 3 on THM
- Hands-on testing of real-world web applications