Offensive Security Researcher • Product Security Specialist • Bug Bounty Hunter
Security professional focused on offensive security, product security assessments, vulnerability research, and enterprise application testing with experience securing modern applications, APIs, infrastructure, and customer-facing systems.
Security services tailored for organizations that need real validation, not just checklist-based testing.
A portfolio of real-world vulnerability discovery, responsible disclosure, product security research, and public recognition across global technology and enterprise platforms.
Recognized by leading organizations and multiple private programs for impactful security findings.
Publicly recognized vulnerability research across enterprise products, security platforms, CMS ecosystems, payment systems, and operational technology-related environments.
Identified an HTTP request smuggling vulnerability that could allow a remote attacker to disrupt application behavior and potentially trigger denial-of-service conditions.
HTTP Request SmugglingStored XSS vulnerability that could be leveraged for full account takeover through malicious script execution inside a trusted application context.
Stored XSSGET-based redirection issue that could send users to attacker-controlled destinations, increasing phishing and credential theft risk.
Open RedirectMulti-step privilege escalation chain involving IDOR, rate-limit weakness, and OTP bypass, enabling unauthorized access expansion.
Privilege EscalationStored XSS vulnerability that could execute malicious scripts in victim sessions and potentially lead to account compromise.
Stored XSSFailure to restrict URL access allowed unauthorized access to uploaded sensitive files without authentication.
Access ControlSQL injection vulnerability that could allow remote database extraction and compromise of application data confidentiality and integrity.
SQL InjectionArbitrary file upload vulnerability through crafted SVG-based payloads that could lead to XSS and eventual account compromise.
File Upload / XSSStored XSS vulnerability that could be exploited to achieve full account takeover in trusted administrative contexts.
Stored XSSImproper authorization flaw enabling privilege escalation and unauthorized access to administrative functionality.
Authorization BypassCross-site scripting issue in the BIC Search component caused by unsafe handling of attacker-controlled input.
Cross-Site ScriptingURL restriction bypass leading to unauthorized download of executable files and an increased risk of malicious file delivery.
Restriction BypassUnauthenticated username enumeration issue allowing attackers to discover valid accounts and improve brute-force or social-engineering efforts.
Username EnumerationAccount lockout bypass vulnerability enabling attackers to circumvent protection controls designed to slow repeated authentication attempts.
Lockout BypassA blend of certifications, tooling, frameworks, and hands-on experience across offensive security, application security, and enterprise testing.
Open to security consulting, penetration testing, product security engagements, and professional collaborations.
Whether you need penetration testing for a product, a web application review, mobile app assessment, API testing, or practical remediation guidance, this portfolio reflects the kind of offensive security work built to protect modern systems.
Discuss Your Security Needs