Finding critical vulnerabilities in enterprise systems. Specializing in web security, authentication bypasses, and business logic flaws across major platforms.
Download CV






Chained unverified email registration with OTP race condition to hijack any user account, completely bypassing 2FA verification through logical flaw exploitation.
Discovered and exploited message editing functionality to bypass conversation limits for free accounts, demonstrating fundamental business logic flaw in AI platform.
Identified a reviews API accepting unusually large limit values. Further testing showed cache-bypass behavior when varying request parameters, potentially increasing backend processing load despite caching protections. The report appeared valid, though the program response did not reflect the impact reported by the community.
Found multiple cross-tenant IDOR issues where tenant-scoped resources could be accessed or modified across account boundaries through insufficient authorization checks.
Observed weaknesses in OTP flow validation where client-controlled request parameters influenced OTP handling behavior. Additional testing showed inconsistent attempt-limit enforcement when modifying request headers during authentication flows.
Custom dork discovery leading to exposure of 25+ API keys, Facebook App IDs, and production credentials through misconfigured cloud storage.
Self-hosted Blind XSS testing dashboard with unlimited payload markers, callback logging, page grouping, Discord alerts, import/export, and Render deployment support.
Cybersecurity awareness web toolkit featuring email breach checks, hash generators, link analyzers, and phishing awareness tools for educational purposes.
Command-line image forensics toolkit for metadata extraction, steganography detection, image hashing, and password protection detection.
Collection of notes and Python scripts for web vulnerabilities including SQLi, XSS, CSRF, and DOM-based attacks based on PortSwigger learning.
Open-source utility for validating exposed API keys during security research, helping triage leaked credentials and confirm whether reported keys are active.
Tooling for rebuilding readable frontend source from exposed source maps, helping researchers review client-side logic, routes, and bundled JavaScript during recon.
Google Dorks generator with 150+ curated dorks for finding APIs, cloud exposures, directory listings, admin panels, and sensitive files for bug bounty research.
Automated pipeline that watches the NVD for newly published CVEs, summarises each one into a hunter-focused brief using Gemini, and posts it to X automatically.
Lightweight Chrome extension for storing, organising, searching, and copy-pasting payloads, URLs, and test strings during active bug bounty sessions.
Personal notes and methodologies for bug bounty and web security: recon workflows, techniques for hidden asset discovery, and vulnerability write-ups.
Socials
GitHub
@Bugatsec
Medium
@Bugatsec
Instagram
@Bugatsec
X (Twitter)
@Bugatsec