Skip to content

bug bounty hunting

Members Public

Open Bug Bounty: 3048 Patched Vulnerabilities

Over a 36 month period, I helped remediate 3048 vulnerabilities through Open Bug Bounty.

Open Bug Bounty: 3048 Patched Vulnerabilities
Members Public

BBC Security Hall of Fame: Reflective XSS Vulnerability

In 2018, I discovered a GET-based reflective cross-site-scripting (XSS) vulnerability on the homepage of the BBC.

BBC Security Hall of Fame: Reflective XSS Vulnerability
Members Public

University of Twente Security Hall of Fame: Remote Command Execution (RCE)

In 2018, I discovered a remote command execution (RCE) vulnerability on University of Twente's website.

University of Twente Security Hall of Fame: Remote Command Execution (RCE)
Members Public

United Nations Security Hall of Fame: Path Disclosure Vulnerability

In 2017, I discovered a path disclosure vulnerability on a subdomain belonging to United Nations.

United Nations Security Hall of Fame: Path Disclosure Vulnerability
Members Public

Deutsche Telekom Security Hall of Fame: Information Disclosure

In 2017, I discovered an information disclosure vulnerability on a subdomain belonging to Deutsche Telekom.

Deutsche Telekom Security Hall of Fame: Information Disclosure
Members Public

Esri Security Hall of Fame: Cookie Based SQL Injection

In 2017, I discovered a cookie based SQL injection (SQLI) vulnerability on a subdomain belonging to Esri.

Esri Security Hall of Fame: Cookie Based SQL Injection
Members Public

Duke Security Hall of Fame: Reflective XSS Vulnerability

In 2017, I discovered multiple cross-site-scripting (XSS) vulnerabilities on Duke's website.

Duke Security Hall of Fame: Reflective XSS Vulnerability
Members Public

Houzz Security Hall of Fame: Blind Based SQL Injection (SQLI)

In 2016, I discovered a blind based SQL injection (SQLI) vulnerability on the Houzz website.

Houzz Security Hall of Fame: Blind Based SQL Injection (SQLI)
Members Public

AOL Security Hall of Fame: Local File Inclusion (LFI) Vulnerability

In 2016, I discovered a local file inclusion (LFI) vulnerability on a subdomain belonging to AOL.

AOL Security Hall of Fame: Local File Inclusion (LFI) Vulnerability
Members Public

AT&T Security Hall of Fame: Reflective XSS Vulnerability

In 2016, I discovered a GET-based reflective cross-site-scripting (XSS) vulnerability on a subdomain belonging to AT&T.

AT&T Security Hall of Fame: Reflective XSS Vulnerability