Web Penetration Tester/Bug Bounty Hunter/HTB CWES

Web penetration tester.

Hands-on web application penetration testing across modern apps, APIs, auth flows, and business logic. Currently preparing for HTB Certified Web Exploitation Specialist (CWES).

Web penetration testing / bug bounty / client-ready reporting

I turn web failures into evidence clients can act on.

My focus is practical assessment work: finding exploitable weaknesses in web applications and APIs, then translating the technical path into clear business risk, remediation, and report-ready evidence.

Offensive focus

View all writeups
External surfaceWeb App

Web application pentesting

Testing modern web applications, auth flows, and business logic for exploitable weaknesses including XSS, IDOR, SQLi, SSRF, access-control flaws, token abuse, and chained impact.

Bug Bounty HunterImpact

Bug bounty hunting

Hunting real-world web targets for XSS, IDOR, auth bypass, business-logic flaws, and chained impact — with clear reproduction steps and report-ready evidence.

APIAuth

API and auth testing

Testing REST/GraphQL APIs, session handling, JWT and OAuth flows, access-control gaps, mass assignment, and other auth/session abuse paths.

InternalPrivEsc

Internal assessments

Mapping exposed services, misconfigurations, credential paths, weak permissions, and privilege escalation opportunities into clear attack chains and practical remediation.

Bio

From exploit path to report.

I work as a web penetration tester. The focus is understanding how applications fail in the real world: where authentication breaks, how trust gets abused, how small misconfigurations become attack paths, and how findings chain into real impact.

My work is centered on web application pentesting, bug bounty hunting, API security, internal assessments, automation, and professional reporting. I use Python to automate workflows, test attack ideas quickly, and turn repeatable findings into methodology.

Burp Suite Caido Nmap ffuf Python Docker XSS SQLi SSRF Bash

Projects

Operator stack

Web pentest craft.

A sharper view of the work: web application and API assessment skills, bug bounty methodology, internal paths, and client-ready reporting. HTB CWES track.

Focus

Web App Pentesting, Bug Bounty Hunter, API Security, Internal Assessments

Web

XSS, SQLi, SSRF, IDOR, Auth Bypass, File Inclusion, Command Injection, API & GraphQL Attacks

Workflow

Recon, Threat Modeling, Exploitation, Impact Proof, Remediation, Client-Ready Reporting

Tooling

Burp Suite, Caido, Nmap, ffuf, SQLMap, Metasploit, Wireshark, Python, Bash, Docker

Build

Python, Rust, JavaScript, Bash, Docker, Linux