Finding the bugs
between the specs._
INFO Independent security research on APIs, authentication, OAuth, GraphQL, and the strange behavior nobody documented.
Case files
Hunting Account Takeovers in the Wild West of MCP OAuth Servers
How misconfigured Dynamic Client Registration in MCP OAuth servers enables one-click account takeover attacks against AI-integrated platforms
How I Scored $2K via an Easy IDOR
A predictable support-ticket reference exposed cross-account conversations, attachments, and replies.
Abusing URL Shorteners for Fun and Profit
Mining archived short links to recover private invitations, tokens, and forgotten application flows.
Account Takeover via an Unsanitized Facebook OAuth Redirect Scheme
How a one-character mutation in a mobile OAuth redirect scheme allowed authentication tokens to be intercepted by a malicious app.
How I RCE'd the Largest RU Company
How favicon reconnaissance and an exposed Java Debug Wire Protocol service led to remote code execution.
How I Scored 1K Bounty Using Waybackurls
How archived URLs exposed valid user tokens and turned one reconnaissance command into a $1K bounty.
Tale of XSS in Angular
Finding two reflected XSS vulnerabilities in an Angular application through automated subdomain monitoring and framework-aware testing.

SICKSEC
ROLE: Security Researcher & Bug Hunter
FOCUS: Web / API / GraphQL / OAuth
MODE: Stay curious
Finding bugs in production, breaking APIs for fun, and publishing the path that turns odd behavior into real impact.