Web application pentester who finds what scanners miss. I dig into authentication flows, business logic, and API trust boundaries โ the places where real vulnerabilities hide.
I don't stop at the CVE. I trace the full impact, build the PoCs, and document what it takes to fix it right.
๐ Top 1% Rank
๐๏ธ 180+ Days Streak
๐๏ธ 230+ Rooms Completedweb_app_pentesting:
- Recon, subdomain enumeration & attack surface mapping
- Authentication & authorization bypass (OAuth, JWT)
- Injection attacks: SQLi, XXE, SSTI, Command injection
- Business logic & access control vulnerabilities
- Client-side attacks: XSS, CSRF, Clickjacking, CORS abuse
- API security testing: REST, GraphQL, WebSockets
- Source-assisted code review & vulnerability chaining
- Tools Used: FFuF,Burp Suite,Gobuster,John-The-Ripper// The best defense is built on a complete understanding of the offense.