Security Researcher
& Bug Bounty Hunter

Finding critical vulnerabilities in enterprise systems. Specializing in web security, authentication bypasses, and business logic flaws across major platforms.

Account Takeover Business Logic XSS & CSRF API Security Burp Suite Linux Terminal
Download CV

Organizations I've Helped Secure

Featured Findings

CRITICAL • CVSS 9.8

Full Account Takeover Chain

Hilton Honors

Chained unverified email registration with OTP race condition to hijack any user account, completely bypassing 2FA verification through logical flaw exploitation.

Account Takeover Race Condition 2FA Bypass Authentication
HIGH • P2

Business Logic Bypass

OpenAI (Bugcrowd)

Discovered and exploited message editing functionality to bypass conversation limits for free accounts, demonstrating fundamental business logic flaw in AI platform.

Business Logic Limit Bypass API Security
MEDIUM - RESEARCH

API Cache / Limit Behavior

Meesho

Identified a reviews API accepting unusually large limit values. Further testing showed cache-bypass behavior when varying request parameters, potentially increasing backend processing load despite caching protections. The report appeared valid, though the program response did not reflect the impact reported by the community.

API Security Cache Behavior Input Validation Performance Testing
HIGH - IDOR

Multiple Cross-Tenant IDORs

UXCam

Found multiple cross-tenant IDOR issues where tenant-scoped resources could be accessed or modified across account boundaries through insufficient authorization checks.

IDOR Cross-Tenant Access Authorization API Security
HIGH - RESEARCH

OTP Flow Validation Weakness

OYO

Observed weaknesses in OTP flow validation where client-controlled request parameters influenced OTP handling behavior. Additional testing showed inconsistent attempt-limit enforcement when modifying request headers during authentication flows.

Authentication Business Logic OTP Flow Rate Limiting
CRITICAL - CVSS 9.1

Production Config Leak

Playtika (Slotomania)

Custom dork discovery leading to exposure of 25+ API keys, Facebook App IDs, and production credentials through misconfigured cloud storage.

Information Disclosure API Keys Reconnaissance Cloud

Technical Skills

Web Vulnerabilities

  • XSS (DOM/Stored/Reflected)
  • SQL Injection & XXE
  • CSRF & Clickjacking
  • SSRF & Web Cache Poisoning
  • OAuth & SSO Vulnerabilities

Tools & Environments

  • Burp Suite Professional
  • Linux & Terminal Mastery
  • Custom Scripting (Python/Bash)
  • Docker & Virtualization
  • Network Analysis (Wireshark)

Methodology

  • Reconnaissance & Enumeration
  • Authentication Testing
  • Business Logic Analysis
  • API Security Testing
  • Bug Chaining & Exploitation

Security Projects

SECURITY TOOL

Blind-XSSTrace

Self-hosted Blind XSS testing dashboard with unlimited payload markers, callback logging, page grouping, Discord alerts, import/export, and Render deployment support.

XSS Security Testing Research Open Source
View on GitHub
EDUCATION

Raina

Cybersecurity awareness web toolkit featuring email breach checks, hash generators, link analyzers, and phishing awareness tools for educational purposes.

JavaScript HTML/CSS Security Education Web
View on GitHub
SECURITY TOOL

Ghostmark

Command-line image forensics toolkit for metadata extraction, steganography detection, image hashing, and password protection detection.

Python Forensics Image Analysis CLI
View on GitHub
LEARNING

Exploit-Diary

Collection of notes and Python scripts for web vulnerabilities including SQLi, XSS, CSRF, and DOM-based attacks based on PortSwigger learning.

Python Security Notes Learning Automation
View on GitHub
SECURITY TOOL

API-Key-Validator

Open-source utility for validating exposed API keys during security research, helping triage leaked credentials and confirm whether reported keys are active.

API Security Credential Testing Automation Open Source
View on GitHub
SECURITY TOOL

source-map-reconstruct

Tooling for rebuilding readable frontend source from exposed source maps, helping researchers review client-side logic, routes, and bundled JavaScript during recon.

JavaScript Source Maps Reconnaissance Security Testing
View on GitHub
OPEN SOURCE

Dorking-Duck

Google Dorks generator with 150+ curated dorks for finding APIs, cloud exposures, directory listings, admin panels, and sensitive files for bug bounty research.

Python OSINT Reconnaissance CLI
View on GitHub
SECURITY TOOL

X-CVE-Alert

Automated pipeline that watches the NVD for newly published CVEs, summarises each one into a hunter-focused brief using Gemini, and posts it to X automatically.

Python Gemini AI Automation CVE Tracking
View on GitHub
SECURITY TOOL

Payload-Vault

Lightweight Chrome extension for storing, organising, searching, and copy-pasting payloads, URLs, and test strings during active bug bounty sessions.

Chrome Extension JavaScript Productivity Bug Bounty
View on GitHub
OPEN SOURCE

Bug-Bounty-Notes

Personal notes and methodologies for bug bounty and web security: recon workflows, techniques for hidden asset discovery, and vulnerability write-ups.

Methodology Recon Write-ups Reference
View on GitHub

Get In Touch

Socials