The record
85 vulnerabilities resolved in nine months, at a signal score in the top 12% of all HackerOne researchers.
Signal is HackerOne’s measure of report quality — reputation earned per report, capped at 7.00. It’s the number that separates researchers who submit noise from researchers who submit findings. Every figure here is public and checkable.
- Bounty Hunter
- Streaker
- TrailBlazer
- Diversity
- A5: Broken Access Control
- A7: Cross-Site Scripting
- Milestone Level 3
- Milestone Level 2
- Milestone Level 1
- Insecticide
- Good Samaritan
Selected writeups
- 01
The Fake .js File That Cached Everyone's Login
An API that handed out session tokens plus a CDN that thought it was serving JavaScript equals a one-click account takeover you could serve to anyone.
CriticalWeb Cache Deception - 02
The Boolean That Owned Every Account
A passwordless login trusted the browser to grade its own homework — so I flipped one false to true and walked into anyone's account with just their email.
CriticalAuth Bypass - 03
The Popup That Handed Me Everyone's Account
A single wildcard in one postMessage call quietly turned an OAuth popup into an account-takeover machine.
CriticalInsecure postMessage (OAuth Token Leak) → Account Takeover - 04
The First Name That Signed Me In as You
A profile field nobody guards became the loose thread that unraveled an entire OAuth login — one unescaped name away from full account takeover.
CriticalXSS to OAuth Account Takeover - 05
The Magic Link That Showed Itself to the Wrong Person
A feature meant to email a student's login link put it on the teacher's screen instead — turning convenience into one-click account takeover.
CriticalAuth Bypass - 06
One Vendor Number, the Whole Directory — Then the Keys
The app identified vendors by a number in the request. Read anyone's profile with it; then change their email and own the account.
CriticalIDOR → Account Takeover
Videos & tutorials
Open-source tooling
What I do
Engineering
Security and infrastructure tooling, shipped as real software — packaged, containerised, documented and licensed.
- TypeScript
- Rust
- Go
- Python
- Shell
- JavaScript
- PHP
Security
Web application vulnerability research against global bug-bounty programmes, with a signal score in the top 12% of all HackerOne researchers.
- IDOR
- XSS
- Account Takeover
- SSRF
- GraphQL
- Auth Bypass
- Business Logic
Access Control & Authorisation
IDOR · Account Takeover · Authentication Bypass · Business Logic
Client-Side
Cross-Site Scripting · Open Redirect
Server-Side
SSRF · Unrestricted File Upload · Denial of Service
API & Data Exposure
GraphQL · Information Disclosure · PII Exposure
Programmes reported to
Ford · Walmart · Disney · Nintendo · Experian · Yelp · Duolingo · HubSpot · Eurofins · Synthesia · Doximity · Henkel · SAS · Whatnot · Amplify
Community
I teach web security and tooling to a Persian-speaking developer community of around 33,000.
About
I'm a software engineer and security researcher. Most of what I build comes out of what I break: a recon pipeline that had to fit inside a free-tier CPU budget, a fuzzer that kept flagging WAF pages as XSS until I made it verify the DOM, a monitoring bot I wrote because I kept missing JavaScript changes on targets I was watching.
Since late 2025 I've submitted 85 reports across HackerOne and YesWeHack — mostly access-control and client-side issues — to programmes including Ford, Walmart, Nintendo and Disney. I care more about my signal score than my report count: 6.82 out of 7 means the things I send are real.
I also run a Persian-speaking developer community of around 33,000 people, where I teach web security and tooling. Explaining a bug to a few thousand people who have never seen one is a different skill from finding it, and it has made me better at writing reports.
I'm looking for a role where both halves are useful — application security, product security, or engineering on a team that takes security seriously.
Let’s talk.
Open to full-time application-security, product-security or engineering roles — remote, or on-site with visa sponsorship. Also open to private programme invites and contract testing.


