Security researcher & builder.
— 277levi
I break web applications to make them safer, and build them to be worth defending.
I work at the seam where security and craft meet. On one side: web application testing — authentication flaws, broken access control, injection classes, and the business-logic bugs scanners will never find. On the other: designing and shipping static sites that load in under a second and refuse to leak anything they don't have to.
Most of my time is spent reading code, tracing trust boundaries, and asking the unglamorous questions — who can call this? what happens if I flip this flag? what does the error message reveal? The interesting bugs are almost always in the parts nobody thought to check.
The build side of my practice exists because of the security side. Once you've spent enough time breaking production systems, you develop strong opinions about how they should be built. That shows up in the work below: minimal surface area, honest types, no tracking, no third-party scripts, nothing running that doesn't need to be there.
- Web App Security
- Bug Bounty
- Offensive Testing
- Threat Modeling
- Linux
- Scripting
- Astro
- Static Sites
- UI / UX
- Typography
Six disciplines, grouped by intent — what I break, what I research, and what I build.
- 01 Offense
Web Application Security
OWASP Top 10, authentication and session flaws, IDOR, SSRF, injection, and access control. The bugs that let an attacker do something they shouldn't.
- 02 Offense
Offensive Testing
Reconnaissance, enumeration, exploitation, post-exploitation. Full kill-chain from information gathering to a report a developer can act on.
- 03 Research
Vulnerability Research
Finding, validating, and responsibly disclosing security issues in production systems. Coordinated disclosure and clear PoC documentation.
- 04 Tooling
Linux & Automation
Kali Linux as a daily driver. Burp Suite, nmap, ffuf, custom Python and shell for the repetitive work so focus stays on the interesting parts.
- 05 Build
Web Development
Static-first architecture with Astro, HTML, CSS, and vanilla JS where it counts. Fast, accessible, and cheap to run — a site that doesn't need a server.
- 06 Build
Web Design
Typography, layout, and hierarchy as functional tools, not decoration. Interfaces that make the reader's job easier and get out of the way.
Two halves of the same practice. Reports from the offensive side, sites from the build side.
aDisclosures
All reports resolved and disclosed privately. Targets withheld per coordinated disclosure. Full details available on request.
- 2026 Critical Resolved Auth bypass Legacy endpoint accepted unsigned JWTs, allowing privilege escalation without credentials.
- 2025 High Resolved Access control API allowed role escalation via mass assignment on the user update endpoint.
- 2025 High Resolved SQL injection Blind boolean based injection in the search parameter. Filtered by upstream WAF.
- 2024 Medium Resolved SSRF Internal metadata endpoint reachable through the image fetch URL parameter.
- 2023 High Resolved IDOR Sequential customer IDs exposed full account records to any authenticated session.
- 2022 Medium Resolved Authentication Password reset token was reusable within its validity window after first use.
- 2021 Medium Resolved Access control User could retrieve another account order details by tampering with the order ID.
- 2020 Low Resolved Info disclosure Debug stack traces leaked framework versions and internal file paths.
- 2019 Low Resolved Misconfig Default admin panel exposed on a staging host without authentication.
bBuilds
Selected web development and design work.
- 2025 Marketplace · Web Dev & Design
Furniture marketplace
Two-sided marketplace for independent furniture makers. Listing flow, seller onboarding, category taxonomy, and a buyer-side browse and inquiry system.
- Astro
- CSS
- Vanilla JS
- Edge
- 2024 Corporate · Web Dev & Design
Company profile
Marketing and investor site for a mid-size firm. Multi-section narrative layout, restrained typography, print-inspired grid.
- Astro
- CSS
- Design system
- 2024 Studio · Design
Studio landing page
Concept landing page for a small design studio. Editorial typography, asymmetric grid, single accent palette.
- Figma
- Type
- Grid
- 2025 Personal · Web Dev & Design
This portfolio
The site you are reading. Static Astro build, no JavaScript at runtime, hardened at the edge. A+ on securityheaders.com.
- Astro
- Cloudflare
- CSP
A four-stage loop. Every engagement runs through it, every finding gets stress-tested against it.
- 01
Recon
Map the surface. Subdomains, endpoints, auth flows, stack fingerprints. Everything reachable is a candidate.
- 02
Probe
Send the weird requests. Flip flags, mutate roles, break types, watch what leaks in errors and timing.
- 03
Exploit
Turn a suspected bug into a demonstrable impact. If it can't be shown, it isn't a finding yet.
- 04
Report
Write it the way a developer needs it: steps, evidence, severity, and a fix. Then coordinate disclosure.
The working set. Chosen for reliability under pressure, not novelty.
Recon
- nmap
- subfinder
- httpx
- amass
Exploit
- Burp Suite
- ffuf
- sqlmap
- curl
Dev
- Astro
- HTML / CSS
- JavaScript
- Git
- Node
Ops
- Kali
- Docker
- Cloudflare
- Python
- Bash
Selected activity — disclosures, research, and builds. A full record lives on GitHub and HackerOne.
| Date | Type | Subject | Status |
|---|---|---|---|
| 2026 · ongoing | Disclosure | HackerOne programs | Active |
| 2025 | Research | Web app access control | Published |
| 2025 | Build | Static portfolio systems | Shipped |
| 2024 | Learning | Offensive security tooling | Ongoing |
Open to collaboration, coordinated disclosure, and hard problems. Direct is best.