Ahmed.
Security researcher and bug bounty hunter, known online as DestroyerX. I find vulnerabilities that come from missing authentication, broken access control, and secrets left in production code.
When I find something worth writing about, it goes here.
100+
Reports
20+
Programs
I've reported vulnerabilities to over 20 companies, including:
AutodeskABBIBMAnthropicWhoX VPNGetYourGuideAboitizpowerCourseraEquifaxand others.
Focus
API & access control
- Missing authentication
- IDOR
- Broken access control
- GraphQL
Secrets & exposure
- JavaScript analysis
- Source maps
- Hardcoded credentials
- Cloud storage
Approach
01
Recon across subdomains, endpoints, and JavaScript bundles.
02
Test authorization: strip tokens, swap IDs, probe cross-tenant access.
03
Analyze production JS for hardcoded keys, cloud credentials, and internal endpoints.
04
Prove real impact with a working proof of concept before writing anything up.