Areas of Expertise

These are the core technical areas where I bring deep knowledge and hands-on experience.

Web App PentestMobile App PentestInfrastructure PentestBinary ExploitationExploit DevelopmentRed Teaming

Recent Posts

My desire to practice my skills and share my acquired knowledge fuels my endeavors.

Cegah Website Tampilkan Konten Judi Online dengan Cloudflare Worker (Bahasa Indonesia)
Jan 15, 2025·4 min read

Dalam beberapa tahun terakhir, serangan perusakan situs web (`defacement`) telah meningkat, dengan banyak kasus melibatkan `threat actor` yang memasukkan konten Judi Online ke situs web yang disusupi.

Full Local File Read via Error Based XXE using XLIFF File
Jun 19, 2021·4 min read

A Few times ago, I had the opportunity to do Bug Hunting activities in one of the Private. In this program, there is a complex application with various features. One of the features in the application is Localization. We can change the Localization of the application by uploading an XLIFF file.

SSRF in PDF Renderer using SVG
May 19, 2021·2 min read

A few times ago, I had the opportunity to do Bug Hunting activities in one of the Private Programs a Bugcrowd. In this program, there is a complex application with various features. One of the highlights is converting objects to PDF, JPG, PNG files from SVG.

From Git Folder Disclosure to Remote Code Execution
Dec 4, 2020·4 min read

A few moments ago I did Bug Hunting activities in one of the Private Programs on Bugcrowd. As usual, the hunting process begins with Recon and Enumeration. The hunting process is carried out on this target in Blackbox.

From Unvalidated Redirect and Parameter Tampering to Account Takeover
Jun 14, 2020·3 min read

In this simple write-up, I would like to tell you how I found an **Account Takeover** vulnerability with a unique method. There's no special or unique bypass thing. Just try to find another exploitation way.

How I accidentally found Bug in Google Search Console
Jan 18, 2020·2 min read

In this simple write-up, I would like to tell how I found an Access Control bug in the Google Search Console application, where I can get information related to the domain that I added to the application, even though it was not successfully verified by me.