§ 01about
Self-taught security researcher from Karawang, West Java. I started in computer networking — routers, MikroTik, hardware — and moved into offensive security through bug bounty programs. Today my focus is web application security: finding flaws that matter, then writing reports clear enough for anyone to reproduce.
I have reported IDOR, reflected XSS, SQL error disclosure, and QR-code injection issues to Indonesian institutions and received official acknowledgment — including recognition from CSIRT KAI (PT Kereta Api Indonesia). Everything I do runs on one principle: permission first, responsible disclosure always.
"I like to work alone, and I love technology. Solitude is true freedom."
§ 02findings
// curated from public acknowledgments — more in the log · ctf: rank #5 on RedLimit — 58 solves · 7,620 pts
§ 03skills
$ man recon-osint
$ man tooling
$ man scripting
$ man infra-network
§ 04certifications
Bug Hunter
Bug Hunter
Azure AI Fundamentals
Azure Data Fundamentals
Security Fundamentals
Ethical Web App Hacking & Security
Cyber Security
Data Privacy in the Digital Age
Web Development
§ 05projects
toolsRR / toolsR
Assorted Python helper scripts for bug bounty workflow — recon and automation experiments pushed as I learn. 44+ repos on GitHub, mostly me learning in public.
$ git clone →Web Vuln Lab
Intentionally vulnerable web environment built with Docker for safe, hands-on practice across the OWASP Top 10 — injection flaws to broken access control.
$ git clone →Findings Writeups
Public notes on vulnerabilities I find and report — root cause, impact, and mitigation — written so anyone starting out can follow the thought process.
$ git clone →§ 06contact
// open for bounty programs, collabs & security work