$ cat about.txt

I'm Ahmed, also known asDestroyerX — a security researcher & bug bounty hunter.

I hunt bugs across web applications, APIs, and cloud infrastructure. My approach: deep recon, understanding business logic, and chaining low-severity findings into critical impact.

Notable programs: I've reported vulnerabilities to 13+ organizations including:

  • Autodesk(SaaS / CAD)
  • ABB(Industrial Automation)
  • IBM(Cloud / Enterprise)
  • Anthropic(AI Safety)
  • Whoer VPN(Privacy / Network)
  • FastRetailing(Retail / E-commerce)
  • Redis(Database / Infrastructure)
  • Hexagon(Manufacturing / Geospatial)
  • Western Union(Fintech)
  • Workato(Integration / Automation)
  • GetYourGuide(Travel / Marketplace)
  • Aboitiz(Conglomerate / Energy)
  • Smule(Social / Audio)

Focus areas: web application security, API testing, authentication and access-control flaws, cloud misconfigurations, and chaining low-severity issues into critical ones.

// stack

  • — recon & content discovery (custom wordlists, JS analysis)
  • — Burp Suite, custom tooling, a lot of curl
  • — bug bounty platforms: HackerOne, Bugcrowd
  • — Node.js / Next.js internals, prototype pollution, path normalization
  • — cloud infra: AWS, GCP, Azure, Kubernetes