LOADING VULNERABILITIES...
Responsible Disclosure

DISCOVERED VULNERABILITIES

Breaking Systems to Build Better Security

20+
Total Vulnerabilities
11
Critical Findings
10+
Companies Secured

.env file exposure

Critical
Educational platform

I discovered a vulnerability that leads to the leakage of the .env file, which contained database credentials and Office accounts.

2025/01
Patched
Database Authentication Bypass Payment System

SQL Injection

Critical
Educational platform

Critical SQL injection in teachers portal allowing complete database access personal data, and administrative functions.

2025/01
Recognition Award
Patched
SQLi Database Education

PII information disclosure

Critical
A major fashion platform

I discovered a misconfiguration in the company's Firebase setup that allowed me to access data of around 80,000 users.

2025/06
Recognition Award
Patched
PII Authentication Web App

Authentication bypass

Critical
A major hiring platform

An improper session expiration vulnerability that allowed bypassing 2FA and gaining full access to the account.

2025/04
Dublicate
Patched
Authentication bypass API Account Takeover

Authorization bypass

Critical
E-commerce CMS

Authorization bypass during the SSH server linking process, where the server allows a user with read-only permissions to access this function and obtain an admin role from the server's response.

2025/05
Dublicate
Patched
Authorization bypass Admin Role CMS

Information Disclosure

Critical
Cloud Storage Service

Leak of a Firebase key with admin privileges, which allowed me to create my own account and gain full access to everything in the Firebase project.

2025/05
Dublicate
Patched
Info Disclosure Privileges Escalation Cloud

IDOR

High
Cyber Security Company

A critical Broken Access Control vulnerability on an API allowed unauthenticated attackers to leak sensitive multi-tenant data and internal infrastructure details, and subsequently modify customer job settings.

2025/10
Under resolving
BAC IDOR Bounty

Authorization Bypass

High
NASA

An authorization bypass was achieved by using HTTP verb tampering (POST instead of GET) to gain unauthenticated access to restricted internal documents and team information on a NASA directory.

2025/05
Disclosed
BAC VDP

Information Disclosure

High
NASA

A publicly exposed .svn metadata file on a NASA server leaked internal repository details and a committer's username, enabling unauthenticated access to sensitive project files.

2025/06
Disclosed
Information Disclosure VDP

Hard-coded Credentials

Medium
Cyber Security Company

Exposed AWS access keys hard-coded in the client-side source code permitted valid AWS API authentication against the internal cloud environment but limited access.

2025/09
Under resolving
Hard-coded Credentials Bounty

Information Disclosure

Medium
Airport

A server misconfiguration permitted the unauthenticated public download of an internal SQLite database, exposing the mobile application's complete database schema and aiding attacker reconnaissance.

2025/09
Under resolving
Information Disclosure VDP

Blind SSRF

Low
A major social media platform

Interaction between the company's server and my server over HTTP and DNS.

2025/02
Recognition Award
Patched
SSRF Interaction Blind SSRF

Blind SSRF

Low
A major hiring platform

Interaction between the company's server and my server over HTTP and DNS.

2025/02
Recognition Award
Patched
SSRF Interaction Blind SSRF

Hall of Fame

Universities
5 Vulnerabilities
E-commerce
8 Vulnerabilities
Healthcare
4 Vulnerabilities
Cloud Services
7 Vulnerabilities