Security Researcher | Bug Bounty Hunter | Ethical Hacker
Hunting vulnerabilities and securing the digital frontier, one bug at a time.
Security researcher specializing in web application security, API testing, and CI/CD pipeline vulnerabilities. Certified penetration tester with active profiles on major bug bounty platforms.
Currently building advanced reconnaissance and security analysis tools, with a focus on automating vulnerability discovery and responsible disclosure.
Comprehensive MCP toolkit integrating 40+ security tools with AI-powered natural language interface for penetration testing workflows.
Smart contract security analysis tool for identifying vulnerabilities in blockchain applications and DeFi protocols.
Automated reconnaissance framework for bug bounty hunting, featuring subdomain enumeration and vulnerability scanning.
Expert-level proficiency with nuclei, subfinder, httpx, and the complete ProjectDiscovery security toolkit.
Full Active Directory domain compromise: anonymous LDAP enumeration into AS-REP Roasting, then nested-group and WriteDACL abuse to self-grant DCSync rights and Pass-the-Hash as Administrator.
Read Writeup →A Linux box built entirely around hand-rolled legacy printer protocols. Chains an LPD shell injection into a JetDirect path traversal for SSH key injection, then abuses a forensic honeypot's SCM_RIGHTS FD leak to reach root.
Read Writeup →A Next.js dashboard owned through a framework-level bug: unauthenticated RCE via CVE-2025-55182 ("React2Shell"), then SQLite credential theft and an MD5 crack, escalating to root by abusing a debug-mode Node.js process over the Chrome DevTools Protocol.
Read Writeup →A chain of corporate misconfigurations: an unauthenticated NFS share leaks onboarding creds, password reuse opens an OpenSTAManager CRM, and an authenticated file-upload RCE (CVE-2026-38751) lands a foothold — escalating to root via a shell-injectable OliveTin action running unauthenticated on localhost.
Read Writeup →A leaked DB password buried in Gitea commit history and a Krayin CRM file-upload RCE (CVE-2026-38526) chain into a foothold — then root falls to a hand-crafted git tree object smuggling a path-traversal filename past a root-run template sync script.
Read Writeup →An unauthenticated Craft CMS preauth RCE (CVE-2025-32432) via a Yii2 behavior gadget and access-log poisoning lands a foothold, then a cracked admin hash opens SSH — and root falls to a telnetd argument-injection auth bypass (CVE-2026-24061) where a crafted USER value becomes login -f root.
Read Writeup →A password-reset endpoint hands back the new password in its response, opening a log-viewer LFI that's poisoned via the User-Agent for RCE — then legacy rservices trust (hosts.equiv) and a sudo nano GTFOBins escape chain all the way to root.
Read Writeup →> More writeups coming soon. Check back regularly for new content.
root@security:~$ [email protected]
For security disclosures, please use encrypted communication.