I break things to understand how they work β then build them back stronger. Based in Kathmandu π³π΅, I focus on offensive security and web application pentesting, with hands-on experience in cloud infrastructure and IoT systems.
- Grinding through PortSwigger Web Security Academy labs (Access Control, Auth, SQLi)
- Building toward bug bounty on HackerOne & Bugcrowd
- Exploring real-world recon workflows and automation
Built a deliberately vulnerable e-commerce app, then pentested it end-to-end.
- Exploited IDOR, broken authentication, missing RBAC, and information disclosure
- Full grey-box pentest documented across all 7 phases of the Cyber Kill Chain
Node.jsSQLiteDockerBurp SuiteNmapGobuster
Cloud-connected IoT security system deployed on AWS EC2.
- ESP32 β MQTT β Python subscriber β InfluxDB β Grafana dashboard β SNS alerts
- Infrastructure provisioned with AWS CloudFormation
ESP32PythonDockerMQTTInfluxDBGrafanaAWS EC2SNS
Full desktop GUI in Java with OOP architecture and real-time duplicate detection.
JavaSwingOOPFile I/O
Security
Dev & Cloud
PortSwigger Web Security Academy β Access Control Β· Business Logic Β· SQLi
HackerOne β Recon Β· Subdomain enumeration Β· Real targets
Always down to collaborate on security research, CTFs, or open source β reach out anytime.
