Bug bounty hunter targeting web applications, APIs, cloud infrastructure, and wireless systems.
I find vulnerabilities, write exploit tools, and share them with the community.
- 🔴 HackerOne:
realridhinofficia - 🐍 Stack: Python, Bash, JavaScript, TypeScript, C, SQL, Go, Rust
- 🛠️ Tools: Burp Suite, Nmap, Metasploit, Ghidra, Frida, 100+ security skills
- 🎯 Platforms: Immunefi, HackenProof, HackerOne, Bugcrowd
| Repo | CVE | Type | Status |
|---|---|---|---|
panos-captive-portal-rce | CVE-2026-0300 | PAN-OS BOF RCE (root) | 🔴 CRITICAL · CISA KEV |
cisa-kev-exploit-scanners | 11+ CVEs | Master scanner + PoCs | 🔴 CRITICAL · CISA KEV |
drupal-jsonapi-sqli-scanner | CVE-2026-9082 | Drupal PostgreSQL SQLi → RCE | 🔴 CRITICAL · CISA KEV |
beyondtrust-rce-scanner | CVE-2026-1731 | BeyondTrust Pre-auth RCE | 🔴 CRITICAL · CISA KEV |
ghe-push-option-rce-scanner | CVE-2026-3854 | GitHub Enterprise RCE | 🔴 CRITICAL · CISA KEV |
defender-privilege-escalation-scanner | CVE-2026-41091/45498 | MS Defender LPE/DoS | 🟠 HIGH · CISA KEV |
litellm-sqli-scanner | CVE-2026-42208 | LiteLLM SQLi | 🟠 HIGH · CISA KEV |
android-adb-bypass-scanner | CVE-2026-0073 | Android ADB Auth Bypass | 🔴 CRITICAL · CISA KEV |
| Repo | Category | Description |
|---|---|---|
VulnHunterAI | AI Pentest | Autonomous AI-powered pentest framework with swarm intelligence, 47+ tools |
API-Security-Toolkit | API Sec | REST, GraphQL, WebSocket, gRPC scanners + 72-pattern secret scanner |
Cloud-Security-Toolkit | Cloud Sec | AWS, Azure, GCP, IaC misconfig, IAM, storage, network scanners |
Web-Security-Toolkit | Web App | SQLi, XSS, SSRF, SSTI, CMDi, IDOR, CSRF, JWT attacks |
Mobile-Security-Toolkit | Mobile | Android/iOS static & dynamic analysis, cert pinning bypass, IPC |
Infra-Security-Toolkit | Infra | Linux, Windows, AD, K8s, Docker, Cloud hardening & vuln scans |
Wireless-Security-Toolkit | Wireless | WiFi, Bluetooth/BLE, RFID/NFC auditing framework |
Crypto-Attack-Toolkit | Crypto | RSA, hash attacks, lattice cryptanalysis, symmetric cipher attacks |
Exploit-Dev-Toolkit | Exploit Dev | Protocol fuzzer, payload generator, ROP builder, shellcode encoder |
Reversing-Toolkit | Reverse Eng | Binary exploitation, heap/stack overflow, VM reverse engineering |
| Repo | Category | Description |
|---|---|---|
OSINT-Toolkit | OSINT | Domain recon, email OSINT, social search, breach monitoring |
github-secret-scanner | Secrets | 72-pattern exposed-secrets scanner for bug bounty targets |
netrecon | Network | Network reconnaissance & service enumeration |
subdomain-finder | Recon | Subdomain enumeration & takeover detection |
| Repo | Platform | Description |
|---|---|---|
flipperwire | Flipper One | WiFi 6E & BT 5.2 exploitation for MT7921AUN |
ghostwire | Flipper One/RK3576 | Modular wireless exploitation framework |
pocket-s | ESP32-S3 | Open-source Flipper Zero alternative (Sub-1GHz, NFC, RFID, IR, BLE, WiFi) |
usbrubberducky-payloads | Hak5 USB | Official USB Rubber Ducky payload repository |
Penetration Testing ████████████████████░ 95%
Web Application Sec ████████████████████░ 95%
API Security ███████████████████░░ 85%
Network Security ███████████████████░░ 85%
Exploit Development ██████████████████░░░ 80%
CTF / Reverse Eng █████████████████░░░░ 75%
Cloud Security ██████████████████░░░ 80%
Mobile Security █████████████████░░░░ 75%
Wireless Security █████████████████░░░░ 75%
Smart Contract Audit ████████████████░░░░░ 70%
- Web: SQLi, XSS, SSRF, SSTI, CMDi, IDOR, CSRF, JWT attacks, auth bypass
- API: GraphQL introspection, BOLA/IDOR, mass assignment, rate limit bypass
- Infra: Linux/Windows hardening, AD attacks, K8s/Docker escape, cloud misconfig
- Mobile: Android pentesting, iOS app security, Frida/Objection, cert pinning bypass
- Crypto: RSA attacks, hash length extension, lattice crypto, symmetric cipher breaks
- Reversing: Binary exploitation, heap/stack overflow, custom VM reverse engineering
- Wireless: WiFi 6E, Bluetooth 5.2, RFID/NFC, SDR, protocol fuzzing
- Smart Contracts: Solidity (Flying Tulip ftPUT), Clarity/Stacks (Zest v2), DeFi attack patterns
- 🔬 Researching: AI-driven autonomous pentesting, LLM prompt injection, supply chain attacks
- 🎮 Building: VulnHunterAI — fully autonomous pentest agent with swarm intelligence
- 📝 Writing: Pine Script v5 trading strategies (SMC futures: structure, FVG, liquidity sweeps)
- 🔍 Hunting: Immunefi/HackenProof — web3, cloud, API, wireless targets
| Platform | Handle |
|---|---|
| HackerOne | realridhinofficia |
| X/Twitter | @c_y_p_h3r |
| ridhinofficial@gmail.com | |
| GitHub | ridhinva |
| ridhinva |
- 💼 Contract security research (web3, cloud, API, mobile, wireless)
- 🐛 Bug bounty triage/consulting (methodology, tooling, reporting)
- 🛠️ Tool development (scanners, exploits, automation, AI agents)
- 🎓 Mentoring (pentesting, bug bounty, exploit dev, reverse engineering)
⭐ Star the repos you find useful • 🍴 Fork to customize • 📬 Open issues for bugs/features