$ whoami // rr-sec · karawang · +62

risky manuel tamba

bug bounty hunter / security researcher / linux practitioner

  • NODE:ACTIVE
  • ENC:AES-256
  • SIG:STRONG
  • VPN:ON
  • SECURE
#5rank · redlimit ctf
58solves
7620points
44repos · github
scroll ↓

§ 01about

Self-taught security researcher from Karawang, West Java. I started in computer networking — routers, MikroTik, hardware — and moved into offensive security through bug bounty programs. Today my focus is web application security: finding flaws that matter, then writing reports clear enough for anyone to reproduce.

I have reported IDOR, reflected XSS, SQL error disclosure, and QR-code injection issues to Indonesian institutions and received official acknowledgment — including recognition from CSIRT KAI (PT Kereta Api Indonesia). Everything I do runs on one principle: permission first, responsible disclosure always.

"I like to work alone, and I love technology. Solitude is true freedom."

location-6.3021°, 107.3050° — Karawang
focusweb security · red team
educationSMK Teknik Komputer & Jaringan
stacklinux · mikrotik · python
status● available for programs

§ 02findings

// curated from public acknowledgments — more in the log · ctf: rank #5 on RedLimit — 58 solves · 7,620 pts

2025-09-28 IDOR
CSIRT KAI — PT Kereta Api Indonesia (Persero) Insecure Direct Object Reference on the KAI Bandara web reservation system · officially recognized
ACKNOWLEDGED
2025-09-24 XSS
QR Code Injection — mobile browser Reflected XSS triggered by scanning a crafted QR code; payload executed in mobile browser
REPORTED
2025-09-02 XSS / SQLi
Depok city government website Reflected XSS & SQL error disclosure found Jul 07 · responsible disclosure followed
REPORTED
2025-08-28 XSS
tni.mil.id subdomain Submitted Aug 13 · triaged as duplicate — process and methodology still count
DUPLICATE
siloam IDOR / reward
Siloam Hospitals · siloamhospitals.com Confirmed issue on the program — reward acknowledged by the Siloam Hospitals bug bounty program
REWARDED
pixabay XSS
Pixabay · pixabay.com Submitted via their responsible disclosure — marked as duplicate, still validated
DUPLICATE
underarmour self-XSS
Under Armour · support.underarmour.com Self-XSS on the .help/customer-support subdomain — out of scope but documented for methodology
OUT OF SCOPE
next… ??

§ 03skills

$ man web-exploitation

  • XSS
  • SQL Injection
  • IDOR
  • SSRF
  • Open Redirect

$ man recon-osint

  • Subdomain Enum
  • Port Scanning
  • Google Dorking
  • Shodan

$ man tooling

  • Burp Suite
  • Nmap
  • ffuf
  • nuclei
  • sqlmap
  • Wireshark

$ man scripting

  • Python
  • Bash
  • JavaScript
  • PHP
  • SQL

$ man infra-network

  • Linux
  • MikroTik
  • Router & WiFi Mgmt
  • Docker

§ 04certifications

Bug Bounty Hunters · 2025

Bug Hunter

BanyuwangiKab · 2025

Bug Hunter

Microsoft · 2024

Azure AI Fundamentals

Microsoft · 2024

Azure Data Fundamentals

Microsoft · 2024

Security Fundamentals

Xcode · 2024

Ethical Web App Hacking & Security

Cursa

Cyber Security

ITHB

Data Privacy in the Digital Age

Cursa

Web Development

§ 05projects

python · tools

toolsRR / toolsR

Assorted Python helper scripts for bug bounty workflow — recon and automation experiments pushed as I learn. 44+ repos on GitHub, mostly me learning in public.

$ git clone →
docker · owasptop10

Web Vuln Lab

Intentionally vulnerable web environment built with Docker for safe, hands-on practice across the OWASP Top 10 — injection flaws to broken access control.

$ git clone →
research · writing

Findings Writeups

Public notes on vulnerabilities I find and report — root cause, impact, and mitigation — written so anyone starting out can follow the thought process.

$ git clone →
Red Team & Bug Bounty Assistant