whoami
I am a penetration tester, application security researcher and Computer Engineering student, working across application security, vulnerability research and bug bounty hunting. My focus is web and mobile application security on Android and iOS, API security and secure code review. I enjoy sharing what I learn with the security community, and this site is mainly where I do it.
specialities
- iOS
- Android
- Mobile
- Web
- API
- AppSec
- Pentest
recent writing
- Multiple Stored XSS Vulnerabilities in Codeastro Hospital Management System
- Authenticated File Upload to RCE in Codeastro Hospital Management System
- Authenticated SQL Injection in Codeastro Real Estate MS (CVE-2024-11058)
- Authenticated File Upload to RCE in Codeastro Real Estate MS
- Time-Based SQL Injection in Content Management System (CVE-2024-10758)
publications
- 9 official CVEs - CVE-2024-10758, CVE-2024-10999, CVE-2024-11000, CVE-2024-11058, CVE-2024-11674, CVE-2024-11675, CVE-2024-11676, CVE-2024-11677, CVE-2024-11678
- Account takeover on Mars (P1) - HackerOne Disclosed Report
portfolio
contact
Contact me via this email: