Cybersecurity Professional · Kerala, India
CEH-certified security consultant specializing in penetration testing, vulnerability assessment, and offensive security research. I help organizations identify and close critical security gaps — before adversaries find them first.
Skills & Certifications
Bug Bounty Findings
Network Solutions — Exposed API keys and production credentials in a publicly accessible AEM JavaScript file.
Todoist — Subdomain wildcard trust allowing credentialed cross-origin requests, enabling potential account takeover.
Todoist — Insecure Direct Object Reference allowing unauthorized modification of user profile data via token leakage.
Conductor — Misconfigured DNS record revealing internal AWS infrastructure details through subdomain takeover vector.
PayPal — Personally identifiable information accessible via skipAuth invoice links indexed by Google search.
Writing & Profiles
Contact
Available for security consulting engagements, penetration testing contracts, bug bounty collaborations, and advisory roles. Based in Kerala, India — working with clients globally, remotely.
✉ Get in touch