BUG BOUNTY HUNTER
Malik Hettige
Web application security researcher from Sri Lanka. Hunting IDOR, authentication flaws, and business logic bugs on HackerOne.
FOCUS AREAS
๐ IDOR / Broken Access Control
Horizontal & vertical privilege escalation. Accessing other users' data by manipulating IDs and parameters.
๐ Authentication Flaws
Password reset bugs, session fixation, MFA bypass, and token predictability.
โ๏ธ Business Logic
Workflow abuse, price manipulation, and trust boundary violations that scanners can't find.
๐ By The Numbers27 Hacker101 CTF points
20+ disclosed reports analyzed
HackerOne โ actively hunting
๐ ๏ธ TOOLS & STACK
Burp Suite ยท subfinder ยท httpx ยท gau ยท katana
LinkFinder ยท SecretFinder ยท ffuf ยท nuclei
๐ฏ CURRENTLY
Phase 1 โ Weapon Forging. Completing PortSwigger Access Control, Authentication, and Business Logic labs. First live VDP submission target: July 14, 2026.
ABOUT
Started teaching myself web application security at 17. No formal training โ just labs, disclosed reports, and live hunting. Focused on three vulnerability classes: IDOR, authentication flaws, and business logic bugs. This is the long game.
WRITE-UPS & RESEARCH
Coming July 2026 โ lab writeups and disclosed report breakdowns published on GitHub.
๐ FIND ME