s
shifuke

Johnson M

@shifuke

Application Security Analyst

Quênia
Inglês
Algumas informações são exibidas no idioma inglês.
Sobre mim
I am a web application security researcher with a proven bug bounty track record on HackerOne, where I am ranked #3 in Kenya for broken access control findings. I have deep working knowledge of the OWASP Top 10 and manual vulnerability discovery. I specialize in identifying API security flaws and business-logic gaps to help organizations secure their production environments.... Saiba mais

Habilidades

s
shifuke
Johnson M
offline • 
Tempo médio de resposta: 1 hora

Conheça meus serviços

Programação e Tecnologia
I will perform an authorized web application security assessment

Portfólio

Experiência profissional

Hackers_Academy

cyber sucurity

Hackers Academy

Dec 2024 - Present • 1 yr 10 mos

Independent Security Researcher – Bug Bounty Hunter HackerOne — Public and Private Bug Bounty Programs August 2025 – Present | Remote Conduct authorized security testing of production web applications and APIs to identify vulnerabilities and business-logic flaws. Achieved a HackerOne Signal score of 7.00, placing in the 99th percentile, and an Impact score of 15.00. Ranked #3 in Kenya on HackerOne’s national leaderboard for Web Application and Broken Access Control submissions in Q3 2026. Discovered and responsibly reported broken access control vulnerabilities, API information disclosures, and incomplete security fixes that exposed restricted user and event-related information. Performed reconnaissance, endpoint mapping, manual testing, exploitation proof-of-concept development, vulnerability reproduction, and responsible disclosure reporting. Applied the OWASP Top 10 methodology to identify access-control gaps, API weaknesses, sensitive-data exposure, and other web application security issues. Selected to test invite-only private bug bounty programs based on the quality and reliability of submitted vulnerability reports. Participated in cybersecurity CTF competitions involving web exploitation, network security, and password-cracking challenges.