I work in bug bounty — mostly API security and identity flows (IDOR and ATO chains). This site is where I keep the writeups, the research, and the occasional opinion that doesn't fit in a tweet.

Disclosure

All content is from authorized, in-scope testing. Details that could identify a live target or a real user are redacted.

Contact

Bug bounty or a pentest? Reach me at s4youud@gmail.com.