Verified Security Research
20 disclosed vulnerabilities across 3 engagements · 6 rated Critical · 1 Hall of Fame listing
EC-Council (CodeRed)
9 vulns · 3 Critical9 vulnerabilities found (3 Critical). Acknowledged same day. Hall of Fame 2026 + Certificate of Appreciation.
PriceOye
5 vulns · 3 Critical PII5 vulnerabilities found, including 3 Critical PII leaks. Remediation confirmed within 72 hours.
Waqar Electronics
6 vulns · XSS-to-ATO6 vulnerabilities found including one Stored-XSS-to-ATO chain via insecure session cookies.
Every finding reported through proper channels — technical details withheld by policy.
Contributions
Patching upstream — small changes, real impact. Statuses refresh from GitLab through a cached server lookup.
Merged (2)
gitlab-shell
GitLab
Fixed JWT refresh bug before rate-limit retries — preventing authentication failures under retry pressure.
Inkscape 1.5
Inkscape
Fixed the Wide Screen preference-state regression so the action restores correctly after interface-mode changes and restart.
In Review (2)
GitLab Docs
GitLab
Fixed test environment fallback mounts configuration — restored English-only doc resolution for localized sites (Japanese, French, Korean) by removing duplicate module.mounts override and adding --environment test to review-app CI. Closes #708.
OpenMW
OpenMW
Documented a launcher-first mod-installation path so users can manage data directories without manually editing openmw.cfg.
F-Droid App Security Audits
Verifying FOSS apps for tracker-free, privacy-respecting compliance
Audit History
| App | MR | Status |
|---|---|---|
| Resonance | !40311 | Merged |
| Snowflake | !35787 | Merged |
| YouPipe | !34597 | Merged |
| Acutis Firewall | !33629 | Merged |
| Fauxx | !36607 | Merged |
| Yelling | !35886 | Merged |
| ONVIF Camera | !32355 | Merged |
| Kochi Transit Go | !39731 | Merged |
| Conduit | !39885 | Merged |
| Redly | !36246 | Closed |
| Nightbell | !45381 | Merged |
| Lean | !46493 | Pending |
| TabGreater | !46639 | Merged |
Audit Activity
Certifications & Achievements
Hall of Fame, hackathon awards and instructor-led certifications — most recent first.
IBM Bob 2.0 Hackathon — Certificate of Completion
Awarded for outstanding performance and attendance — successfully completing and submitting a solution based on IBM in the IBM Bob 2.0 hackathon (Sep 25-27, 2026). Certificate ID CMULAQCLI00TVS6O1DEMZETUY.
CyberOps Associate — Networking Basics
Computer networking fundamentals and how networks operate.
EC-Council Hall of Fame 2026
Certificate of Appreciation — Responsible Disclosure
Recognized by EC-Council President Sanjay Bavisi for identifying vulnerabilities in EC-Council web assets (9 vulnerabilities, 3 Critical).
Introduction to Cybersecurity
Introduction to Dark Web, Anonymity, and Cryptocurrency
Network Technician Career Path
Digital Safety and Security Awareness
ChatGPT for Everyone
Foundational ChatGPT usage and prompting best practices.
CyberOps Associate — Networking Basics
CyberOps AssociateComputer networking fundamentals and how networks operate.
Network Technician Career Path
Network Technician Career PathCareer path badge covering networking fundamentals, security, and administration through Saylani Cisco Networking Academy.
Digital Safety and Security Awareness
Digital Safety and Security AwarenessDigital safety, online privacy, and cybersecurity hygiene awareness.
ALL VERIFIABLE ON SAYLANI CISCO NETWORKING ACADEMY & EC-COUNCIL
Activity
Terminal-style view of the latest commits, PRs, and events across repositories.
Snowflake Proxy
Help censored users browse the free internet — right from your browser
Proxy inactive — click Enable to start helping censored users access the free internet
WebRTC Relay
Your browser becomes a bridge. Censored users route traffic through your WebRTC connection to access the open internet.
Your Privacy First
Your IP is never exposed to the websites censored users visit. You're just a transport layer — no data stored, no logs kept.
By Tor Project
Snowflake is built by the Tor Project. It's used by thousands daily to bypass censorship in restricted regions worldwide.
Learn moreSnowflake Network
You're not alone — thousands of proxies are helping censored users worldwide
Passive Recon Scanner
Public-record reconnaissance. Reads DNS, TLS, WHOIS and HTTP headers for a host you nominate.
Where these requests go
- DNS, certificate-transparency and WHOIS data come from public services (Google DNS, crt.sh, whois).
- HTTP requests that browsers cannot make cross-origin are relayed through a third-party CORS proxy, so that domain and your IP reach that service as well as the target.
- Private, loopback and link-local addresses are rejected.
- Nothing is stored and no scan result is sent anywhere. Only use this on infrastructure you own or are authorised to assess.
Enter a domain you own or are authorised to assess to begin reconnaissance...
Requests go to public DNS, certificate-transparency and WHOIS services, plus a small number of direct HTTP requests to the host you enter. Only scan infrastructure you own or are authorised to assess.