BUG BOUNTY HUNTER

Malik Hettige

Web application security researcher from Sri Lanka. Hunting IDOR, authentication flaws, and business logic bugs on HackerOne.

FOCUS AREAS

๐Ÿ”“ IDOR / Broken Access Control
Horizontal & vertical privilege escalation. Accessing other users' data by manipulating IDs and parameters.

๐Ÿ”‘ Authentication Flaws
Password reset bugs, session fixation, MFA bypass, and token predictability.

โš™๏ธ Business Logic
Workflow abuse, price manipulation, and trust boundary violations that scanners can't find.

๐Ÿ“Š By The Numbers27 Hacker101 CTF points
20+ disclosed reports analyzed
HackerOne โ€” actively hunting

๐Ÿ› ๏ธ TOOLS & STACK

Burp Suite ยท subfinder ยท httpx ยท gau ยท katana
LinkFinder ยท SecretFinder ยท ffuf ยท nuclei

๐ŸŽฏ CURRENTLY

Phase 1 โ€” Weapon Forging. Completing PortSwigger Access Control, Authentication, and Business Logic labs. First live VDP submission target: July 14, 2026.


ABOUT

Started teaching myself web application security at 17. No formal training โ€” just labs, disclosed reports, and live hunting. Focused on three vulnerability classes: IDOR, authentication flaws, and business logic bugs. This is the long game.

WRITE-UPS & RESEARCH

Coming July 2026 โ€” lab writeups and disclosed report breakdowns published on GitHub.

๐Ÿ”— FIND ME