Dossier — 2026 Online

Security researcher & builder.

— 277levi

I break web applications to make them safer, and build them to be worth defending.

Based
Remote · UTC+7
Focus
Web App Security
Status
Open for work
Stack
Kali · Burp · Astro

I work at the seam where security and craft meet. On one side: web application testing — authentication flaws, broken access control, injection classes, and the business-logic bugs scanners will never find. On the other: designing and shipping static sites that load in under a second and refuse to leak anything they don't have to.

Most of my time is spent reading code, tracing trust boundaries, and asking the unglamorous questions — who can call this? what happens if I flip this flag? what does the error message reveal? The interesting bugs are almost always in the parts nobody thought to check.

The build side of my practice exists because of the security side. Once you've spent enough time breaking production systems, you develop strong opinions about how they should be built. That shows up in the work below: minimal surface area, honest types, no tracking, no third-party scripts, nothing running that doesn't need to be there.

  • Web App Security
  • Bug Bounty
  • Offensive Testing
  • Threat Modeling
  • Linux
  • Scripting
  • Astro
  • Static Sites
  • UI / UX
  • Typography

Six disciplines, grouped by intent — what I break, what I research, and what I build.

  1. 01 Offense

    Web Application Security

    OWASP Top 10, authentication and session flaws, IDOR, SSRF, injection, and access control. The bugs that let an attacker do something they shouldn't.

  2. 02 Offense

    Offensive Testing

    Reconnaissance, enumeration, exploitation, post-exploitation. Full kill-chain from information gathering to a report a developer can act on.

  3. 03 Research

    Vulnerability Research

    Finding, validating, and responsibly disclosing security issues in production systems. Coordinated disclosure and clear PoC documentation.

  4. 04 Tooling

    Linux & Automation

    Kali Linux as a daily driver. Burp Suite, nmap, ffuf, custom Python and shell for the repetitive work so focus stays on the interesting parts.

  5. 05 Build

    Web Development

    Static-first architecture with Astro, HTML, CSS, and vanilla JS where it counts. Fast, accessible, and cheap to run — a site that doesn't need a server.

  6. 06 Build

    Web Design

    Typography, layout, and hierarchy as functional tools, not decoration. Interfaces that make the reader's job easier and get out of the way.

Two halves of the same practice. Reports from the offensive side, sites from the build side.

aDisclosures

All reports resolved and disclosed privately. Targets withheld per coordinated disclosure. Full details available on request.

  • 2026 Critical Resolved Auth bypass Legacy endpoint accepted unsigned JWTs, allowing privilege escalation without credentials.
  • 2025 High Resolved Access control API allowed role escalation via mass assignment on the user update endpoint.
  • 2025 High Resolved SQL injection Blind boolean based injection in the search parameter. Filtered by upstream WAF.
  • 2024 Medium Resolved SSRF Internal metadata endpoint reachable through the image fetch URL parameter.
  • 2023 High Resolved IDOR Sequential customer IDs exposed full account records to any authenticated session.
  • 2022 Medium Resolved Authentication Password reset token was reusable within its validity window after first use.
  • 2021 Medium Resolved Access control User could retrieve another account order details by tampering with the order ID.
  • 2020 Low Resolved Info disclosure Debug stack traces leaked framework versions and internal file paths.
  • 2019 Low Resolved Misconfig Default admin panel exposed on a staging host without authentication.

bBuilds

Selected web development and design work.

  • Preview of Furniture marketplace
    2025 Marketplace · Web Dev & Design

    Furniture marketplace

    Two-sided marketplace for independent furniture makers. Listing flow, seller onboarding, category taxonomy, and a buyer-side browse and inquiry system.

    • Astro
    • CSS
    • Vanilla JS
    • Edge
    View ↗
  • Preview of Company profile
    2024 Corporate · Web Dev & Design

    Company profile

    Marketing and investor site for a mid-size firm. Multi-section narrative layout, restrained typography, print-inspired grid.

    • Astro
    • CSS
    • Design system
    View ↗
  • Preview of Studio landing page
    2024 Studio · Design

    Studio landing page

    Concept landing page for a small design studio. Editorial typography, asymmetric grid, single accent palette.

    • Figma
    • Type
    • Grid
  • Preview of This portfolio
    2025 Personal · Web Dev & Design

    This portfolio

    The site you are reading. Static Astro build, no JavaScript at runtime, hardened at the edge. A+ on securityheaders.com.

    • Astro
    • Cloudflare
    • CSP
    View ↗

A four-stage loop. Every engagement runs through it, every finding gets stress-tested against it.

  1. 01

    Recon

    Map the surface. Subdomains, endpoints, auth flows, stack fingerprints. Everything reachable is a candidate.

  2. 02

    Probe

    Send the weird requests. Flip flags, mutate roles, break types, watch what leaks in errors and timing.

  3. 03

    Exploit

    Turn a suspected bug into a demonstrable impact. If it can't be shown, it isn't a finding yet.

  4. 04

    Report

    Write it the way a developer needs it: steps, evidence, severity, and a fix. Then coordinate disclosure.

The working set. Chosen for reliability under pressure, not novelty.

Recon

  • nmap
  • subfinder
  • httpx
  • amass

Exploit

  • Burp Suite
  • ffuf
  • sqlmap
  • curl

Dev

  • Astro
  • HTML / CSS
  • JavaScript
  • Git
  • Node

Ops

  • Kali
  • Docker
  • Cloudflare
  • Python
  • Bash

Selected activity — disclosures, research, and builds. A full record lives on GitHub and HackerOne.

Date Type Subject Status
2026 · ongoing Disclosure HackerOne programs Active
2025 Research Web app access control Published
2025 Build Static portfolio systems Shipped
2024 Learning Offensive security tooling Ongoing

Open to collaboration, coordinated disclosure, and hard problems. Direct is best.

PGP — 27Rafa <27rafa@wearehackerone.com>

2B17C043 1956DD66 5A3C9E7B 31FB093D 3605D36E