[ system boot — infosec portfolio v2.0 ]

root@saurav:~# ./portfolio.sh

Penetration Tester // Bug Bounty Hunter // Security Researcher

About Me

Hello, I'm Saurav Kumar — an active Bug Bounty Hunter and Penetration Tester based in Delhi, India. I proactively identify and responsibly disclose security vulnerabilities, and contributing to a safer internet by reporting security flaws to organizations worldwide.

My core expertise lies in IDOR (Insecure Direct Object Reference), API Security, and AI Security, where I've developed strong skills in identifying broken authorization flows and hidden API risks that attackers could exploit.

Beyond IDOR, I explore web application vulnerabilities, authentication bypasses, and modern recon techniques. I enjoy combining automation tools with manual testing to uncover bugs that slip past surface-level scans.

Active BugCrowd HackerOne AI Security Web AppSec

Skills

Specialization

  • IDOR & Broken Object Level Auth
  • API Security Testing
  • AI / LLM Security (Prompt Injection, Jailbreak)
  • Authentication & Session Bypass
  • Business Logic Vulnerabilities

Web Pentesting

  • XSS (Reflected, Stored, DOM)
  • SQL Injection & NoSQL Injection
  • SSRF & Path Traversal
  • CSRF & Clickjacking
  • JWT & OAuth Abuse

Programming

  • Python — automation & PoC scripting
  • Bash / Shell — recon pipelines
  • Go — basics, tool usage

Platforms

  • TryHackMe (Jr Pentester ✓, AI Security ✓)
  • PortSwigger Web Security Academy
  • BugCrowd — active programs
  • HackerOne — active programs

Tools

ReconSubfinder
ReconAssetfinder
ReconAmass
CrawlKatana
FuzzFFUF
ScanNuclei
ScanOWASP ZAP
XSSDalFox
XSSXSStrike
ManualBurp Suite
SQLiSQLmap
FingerprintWappalyzer

Projects & Writeups

Completed TryHackMe Jr Penetration Tester path — covering network pentesting, web exploitation, and post-exploitation.

Completed TryHackMe AI Security path — covering LLM vulnerabilities, prompt injection, and adversarial AI testing.

Reported valid bugs in live programs on BugCrowd and HackerOne — including IDOR, API auth issues, and logic flaws.

Exploring automation pipelines for recon, JWT testing, and AI-assisted vulnerability triage using Nuclei, DalFox, and local LLMs.

Published Writeup
How I Found an Arbitrary Read/Write Vulnerability in Grok — a Popular xAI Tool

medium.com/@esaurav  ·  xAI / Grok  ·  Arbitrary Read/Write

Contact