About
Ahmed, also known as DestroyerX.
I'm a Security Researcher and Bug Bounty Hunter. I spend my time finding and reporting vulnerabilities, and turning small bugs into bigger, demonstrable impact.
This site is where I publish my writeups and the things I learn along the way.
My work
I've reported vulnerabilities to many companies, including:
AutodeskABBIBMAnthropicWhoX VPNGetYourGuideAboitizpowerand others…
What I focus on
Where I spend most of my research time.
01
Web & API security
Business logicInjectionAccess controlGraphQL
02
Authentication & authorization
Account takeoverIDOROAuthPrivilege escalation
How I work
A simple loop I keep coming back to on every target.
- 01
Map the attack surface
Deep recon — subdomains, endpoints, and JavaScript — to understand how an application is really put together.
- 02
Hunt with intent
Manual testing guided by how the app behaves, not a checklist. The interesting bugs live in the edge cases.
- 03
Prove real impact
Every finding ships with a working proof of concept and a clear write-up of what an attacker actually gains.