> whoami

ROXOI_

//

Finding vulnerabilities before attackers do.
Breaking things (ethically) so they can't be broken maliciously.

roxoi@sec ~
scroll

about.md

The Mindset Behind
the Exploit

Hey, I'm roxoi — a bug hunter and cybersecurity researcher. I spend my time looking at systems the way an attacker would, then reporting what I find before someone with worse intentions gets there first.

My work spans web application security, vulnerability research, and bug bounty hunting — digging through auth flows, APIs, and business logic to find the edge cases that break things.

Security isn't a checklist for me, it's a mindset: assume everything is attackable until proven otherwise.

Bug Hunting

Bug bounty hunting across web and API targets — chasing auth bypasses, injection flaws, and logic errors.

Penetration Testing

Structured, methodology-driven testing of applications and infrastructure to surface real-world risk.

Vulnerability Research

Deep-dive analysis into how software fails — root-causing bugs and understanding their exploitability.

tech.json

Tools of the
Trade

[ Offensive Security ]

Penetration Testing Bug Bounty Hunting Red Teaming Social Engineering

[ Web & App Security ]

OWASP Top 10 Auth & JWT Attacks SQL Injection XSS / CSRF / SSRF API Security Business Logic Flaws

[ Tools & Frameworks ]

Burp Suite Nmap Metasploit sqlmap Wireshark Nuclei

[ Networks & Systems ]

Network Security Linux Active Directory Cloud Security (AWS) CTF / Reverse Engineering

findings/

Selected
Work

01
Bug Bounty Auth Bypass API

Auth Bypass in Public SaaS Platform

Reported & Triaged Vulnerability

Placeholder write-up: found a broken access control flaw in an API endpoint that allowed privilege escalation between user roles. Replace with your own disclosed report.

Read Write-up
02
Web App SQLi High Severity

SQL Injection in Search Parameter

Bug Bounty Report

Placeholder write-up: a blind SQL injection uncovered in a search feature, escalated to full database read access. Replace with a link to your disclosed report or CVE.

Read Write-up
03
Recon Automation Python

Automated Recon Toolkit

Custom Security Tooling

Placeholder project: a custom recon pipeline chaining subdomain enumeration, port scanning, and vulnerability scanning for faster bug bounty triage.

View on GitHub
04
CTF Reverse Engineering

CTF Write-ups

Capture The Flag Challenges

Placeholder: a collection of write-ups from CTF competitions covering web exploitation, reverse engineering, and crypto challenges.

Read Write-ups
05
Network Internal Pentest

Internal Network Penetration Test

Simulated Assessment

Placeholder: a simulated internal pentest engagement covering lateral movement, privilege escalation, and Active Directory misconfigurations.

Read Report

> more_findings.sh

Want to see more?

Check my GitHub and bug bounty platform profile for additional write-ups and disclosed reports.

Full Profile

contact.sh

Let's Talk
Security.

Found a bug in your product and need it reported responsibly? Need a security assessment? I'm one message away.

Available for bug bounty & security work