burningresolve
I research how web applications break.
Independent security researcher focused on finding vulnerabilities in web applications and APIs through manual testing, application analysis, and bug bounty research.
I am an offensive security practitioner focused on web application and API security testing.
My approach prioritizes manual testing and understanding how an application actually works before attempting to exploit it. I focus on application behavior, business logic, trust boundaries, authentication, authorization, and access control to identify security issues that may not be obvious through automated scanning alone.
I continuously develop my skills through penetration testing, bug bounty research, and hands-on security testing.
Focus areas
Security focus
Reconnaissance & Attack Surface
Performing reconnaissance and endpoint discovery to understand the application's attack surface before moving into focused manual testing.
Manual Web Application Testing
Testing web applications manually by understanding their functionality, request flows, security boundaries, and server-side behavior.
API Security
Assessing APIs for authentication, authorization, access control, input handling, object-level permissions, and unintended data exposure.
Business Logic
Analyzing application workflows and business rules to identify ways functionality can be abused when security assumptions are incorrectly enforced.
Authentication & Authorization
Testing authentication mechanisms, authorization boundaries, role-based access control, and user privileges to identify unintended access.
Recent