agrresore@node:~$ whoami
Independent security researcher & bug bounty hunter.
I break things on purpose — then write the report that gets them fixed. Web2 & Web3. Disclosures, CVEs, and field notes from Central Asia.
- Platforms
HackerOne · HackenProof · Immunefi · Cantina
- Focus
Web · Web3 · Active Directory
- Published CVEs
$ cat ~/about.md
Who’s behind the handle
An hacker.
I’m Muhammad — handle agrresore. An independent security researcher and bug bounty hunter based in Central Asia, working across both Web2 and Web3 targets. My day is mostly reading other people’s code and traffic until something doesn’t add up, then proving it cleanly and writing the report that gets it fixed.
I hunt on HackerOne, HackenProof, Immunefi, Cantina — programs and protocols alike. Everything here is disclosed responsibly, or published only after a fix has shipped.
// what I test
- Web (Web2) IDOR, auth bypass, SSRF, injection, business logic, GraphQL
- Web3 Smart-contract review, accounting/oracle bugs, access control
- Active Directory Enumeration, lateral movement, misconfig abuse
- Recon & tooling Asset discovery, automation, small purpose-built scripts
// languages
- C
- Python
- Bash
- PowerShell
- JavaScript
Currently going deeper on AI/ML and its security surface.
Field notes
Selected writeups
No writeups published yet.
Longer form
From the blog
No posts published yet.