About

Ahmed, also known as DestroyerX.

I'm a Security Researcher and Bug Bounty Hunter. I spend my time finding and reporting vulnerabilities, and turning small bugs into bigger, demonstrable impact.

This site is where I publish my writeups and the things I learn along the way.

My work

I've reported vulnerabilities to many companies, including:

AutodeskABBIBMAnthropicWhoX VPNGetYourGuideAboitizpowerand others…

What I focus on

Where I spend most of my research time.

01

Web & API security

Business logicInjectionAccess controlGraphQL
02

Authentication & authorization

Account takeoverIDOROAuthPrivilege escalation

How I work

A simple loop I keep coming back to on every target.

  1. 01

    Map the attack surface

    Deep recon — subdomains, endpoints, and JavaScript — to understand how an application is really put together.

  2. 02

    Hunt with intent

    Manual testing guided by how the app behaves, not a checklist. The interesting bugs live in the edge cases.

  3. 03

    Prove real impact

    Every finding ships with a working proof of concept and a clear write-up of what an attacker actually gains.