Available for Bug Bounty Collaborations

0xResearcher
Osman Hamdy

Security Researcher | Bug Bounty Hunter

Hunting web vulnerabilities across HackerOne & Bugcrowd programs. Specializing in XSS, SQL Injection, IDOR, and SSRF chains. Turning attack surfaces into detailed, reproducible reports.

Who I Am

I'm a self-taught security researcher obsessed with breaking web applications before the bad guys do. With over 3 years of active bug bounty hunting, I've reported 100+ valid vulnerabilities to programs ranging from FinTech startups to Fortune 500 companies.

My approach is methodology-driven: I map every attack surface, enumerate endpoints, and chain low-severity findings into high-impact exploits. When I find something, I write reports that developers can actually act on.

Languages & Tools
Python Bash JavaScript HTML/CSS MySQL SQLMap Burp Suite Nuclei ffuf Linux Networking Git
Vulnerability Classes
XSS SQL Injection IDOR SSRF RCE Auth Bypass CSRF XXE Open Redirect
0
Reports Submitted
0
Valid Bugs
0
Programs Tested
0
Write-ups Published

Vulnerability Write-ups

XSS High

Stored XSS via SVG Upload in Profile Editor

Mar 2024 HackerOne

Bypassed MIME-type validation to upload a crafted SVG with embedded <script> tags. The payload executed in the context of every visitor viewing the profile page.

SQLi Critical

Blind Time-Based SQLi in REST Search Endpoint

Jan 2024 Bugcrowd

Discovered unsanitized sort parameter in a paginated API. Time-based extraction confirmed full DB read access, exposing 2M+ user records.

IDOR High

IDOR Leaking Full PII via Invoice API

Dec 2023 HackerOne

Sequential integer IDs on /api/invoices/{id} with no authorization check. Iterated 50k records to retrieve name, email, address, and last-4 card digits.

SSRF Critical

SSRF to AWS Metadata Service via Webhook URL

Nov 2023 Bugcrowd

Webhook URL field fetched arbitrary hosts without SSRF mitigations. Pointed to 169.254.169.254 to retrieve IAM credentials with full EC2 role permissions.

RCE Critical

Pre-Auth RCE via Insecure Deserialization in Admin Panel

Sep 2023 HackerOne

Serialized Java object in a cookie was passed to ObjectInputStream without validation. Crafted a ysoserial payload achieving unauthenticated RCE as www-data.

Auth Medium

Password Reset Token Not Invalidated After Use

Aug 2023 Bugcrowd

Reset tokens remained valid after password change and lacked expiry. An attacker intercepting a single token could perform account takeover indefinitely.

XSS Medium

DOM XSS via Unvalidated URL Fragment in SPA Router

Jul 2023 HackerOne

React SPA passed window.location.hash directly to dangerouslySetInnerHTML. Crafted URL with encoded payload bypassed WAF and triggered cookie theft.

IDOR Medium

Mass Assignment IDOR Elevating User to Admin Role

Jun 2023 Bugcrowd

Profile update endpoint accepted role parameter and assigned it without privilege checks. Sent "role":"admin" to self-escalate to full admin access.

Acknowledged Programs

🏦
FinVault Technologies
Bug Bounty Program · Hall of Fame #3
$1,200 — Critical SSRF
☁️
CloudEdge Systems
Security Acknowledgment Page
$750 — Blind SQLi
🛒
ShopNova Inc.
Public Hall of Fame · Rank 12
$500 — Stored XSS
🔐
AuthGuard Platform
Researcher Recognition Program
$350 — Auth Bypass
📡
NetStream Media
Vulnerability Disclosure Policy
CVE-2023-39512 · RCE
🏥
MedConnect Health
Responsible Disclosure — Thank You
$600 — IDOR PII Leak

Get In Touch

Found a collaboration opportunity? Running a private program? Want to discuss a finding or commission a security review? Drop a message — I respond within 24 hours.

0xresearcher@protonmail.com

PGP-encrypted comms available on request.