$ cat about.txt
I'm Ahmed, also known asDestroyerX — a security researcher & bug bounty hunter.
I hunt bugs across web applications, APIs, and cloud infrastructure. My approach: deep recon, understanding business logic, and chaining low-severity findings into critical impact.
Notable programs: I've reported vulnerabilities to 13+ organizations including:
- ▸Autodesk(SaaS / CAD)
- ▸ABB(Industrial Automation)
- ▸IBM(Cloud / Enterprise)
- ▸Anthropic(AI Safety)
- ▸Whoer VPN(Privacy / Network)
- ▸FastRetailing(Retail / E-commerce)
- ▸Redis(Database / Infrastructure)
- ▸Hexagon(Manufacturing / Geospatial)
- ▸Western Union(Fintech)
- ▸Workato(Integration / Automation)
- ▸GetYourGuide(Travel / Marketplace)
- ▸Aboitiz(Conglomerate / Energy)
- ▸Smule(Social / Audio)
Focus areas: web application security, API testing, authentication and access-control flaws, cloud misconfigurations, and chaining low-severity issues into critical ones.
// stack
- — recon & content discovery (custom wordlists, JS analysis)
- — Burp Suite, custom tooling, a lot of curl
- — bug bounty platforms: HackerOne, Bugcrowd
- — Node.js / Next.js internals, prototype pollution, path normalization
- — cloud infra: AWS, GCP, Azure, Kubernetes