About Me
Hello, I'm Saurav Kumar — an active Bug Bounty Hunter and Penetration Tester based in Delhi, India. I proactively identify and responsibly disclose security vulnerabilities, and contributing to a safer internet by reporting security flaws to organizations worldwide.
My core expertise lies in IDOR (Insecure Direct Object Reference), API Security, and AI Security, where I've developed strong skills in identifying broken authorization flows and hidden API risks that attackers could exploit.
Beyond IDOR, I explore web application vulnerabilities, authentication bypasses, and modern recon techniques. I enjoy combining automation tools with manual testing to uncover bugs that slip past surface-level scans.
Skills
Specialization
- IDOR & Broken Object Level Auth
- API Security Testing
- AI / LLM Security (Prompt Injection, Jailbreak)
- Authentication & Session Bypass
- Business Logic Vulnerabilities
Web Pentesting
- XSS (Reflected, Stored, DOM)
- SQL Injection & NoSQL Injection
- SSRF & Path Traversal
- CSRF & Clickjacking
- JWT & OAuth Abuse
Programming
- Python — automation & PoC scripting
- Bash / Shell — recon pipelines
- Go — basics, tool usage
Platforms
- TryHackMe (Jr Pentester ✓, AI Security ✓)
- PortSwigger Web Security Academy
- BugCrowd — active programs
- HackerOne — active programs
Tools
Projects & Writeups
Completed TryHackMe Jr Penetration Tester path — covering network pentesting, web exploitation, and post-exploitation.
Completed TryHackMe AI Security path — covering LLM vulnerabilities, prompt injection, and adversarial AI testing.
Reported valid bugs in live programs on BugCrowd and HackerOne — including IDOR, API auth issues, and logic flaws.
Exploring automation pipelines for recon, JWT testing, and AI-assisted vulnerability triage using Nuclei, DalFox, and local LLMs.