OAuth CSRF → Account Takeover
Missing state on GET /connect/google allowed linking an attacker Google identity to the victim’s authenticated DomainScope session → full ATO via Sign in with Google and persistent password set via My Profile.
OPEN TO WORK · SECURITY ENGINEERING
Application Security & Offensive Security Engineer | B.Sc. Software Engineering
Living after 0x7c00
Recognition
Missing state on GET /connect/google allowed linking an attacker Google identity to the victim’s authenticated DomainScope session → full ATO via Sign in with Google and persistent password set via My Profile.
Validated critical vulnerability reported through DigitalOcean’s authorized bug bounty program and acknowledged in Bug Bounty Hall of Fame.
View Bugcrowd profile ↗Validated security finding responsibly disclosed via Pinterest’s bug bounty program and acknowledged in Bug Bounty Hall of Fame.
View Bugcrowd profile ↗Validated security finding submitted through Dell’s official bug bounty program and acknowledged in Bug Bounty Hall of Fame.
View Bugcrowd profile ↗20+ aggregate acknowledgments across Bugcrowd — View Bugcrowd profile ↗
References & Verifiable Assessment Logs Available Upon Request
HR & ATS · Verified
The SecOps Group — 2026
View CredentialSecurityBlue Team — 2023
View CredentialIBM — 2023
View badgeTryHackMe — 2024
VerifyResearch
Responsible disclosure of a $1,000 CSRF in Verisign DomainScope Google OAuth linking — missing state parameter allowed an attacker to link their Google account to a victim's DomainScope profile and take over the account. Includes redacted PoC and reward timeline.
An authorized blue-team assessment: exploit a trivial PHP RCE on Apache, contain it at runtime with an AppArmor profile, and then remediate the source. Includes profile snippets, audit logs, and validation output.
Built an ELK SOC home lab ingesting 50k+ Linux audit/syslog events — tuned noisy auditd rules into 5 Sigma detections (MITRE-mapped) and triaged alerts in Kibana with documented false-positive reduction.
Context: University research projects requiring software implementation and academic-grade documentation.
Responsibilities:
Outcomes:
Engineering work that builds system reasoning, architecture and tooling — not security assessment.
Completed Penetration Testing & Application Security internship track: company-led lectures, CTF challenges, vulnerability-exploitation lab work.
The path
Context
A practical security perspective shaped by both testing and operating real systems.

Driven by a deep fascination with low-level mechanics, I view cybersecurity not just as code, but as a craft. Software Engineer by degree, Offensive Security researcher by practice, I specialize in bridging application code quality with web/API penetration testing, threat modeling, and secure architecture.
My background in Software Engineering from Tomsk State University fuels my systematic approach to architecture, documentation, and automated tooling. On the offensive side, I conduct authorized security assessments and uncover critical vulnerabilities—with named disclosures for Verisign, DigitalOcean, Pinterest, and Dell, 20+ Bugcrowd acknowledgments, a Top 5 placement in Bastion’s CTF, and published research.
I test strictly within authorized scope, practice responsible disclosure, and align assessments with frameworks like OWASP ASVS, NIST CSF, ISO 27001, and GDPR guidelines to build fundamentally resilient systems.
16 notes in archive — Browse all →
Capabilities
Evidence-tiered and honestly scoped — Core · Applied · Familiar · Engineering — strongest to exposure, no percentage scores.
Hands-on in labs and authorized assessments — regularly practiced, including reporting
Applied in internships and labs — developing depth
Exposure / lab — currently developing, not a primary strength
Programming, systems and professional effectiveness — supports testing and tooling
Tiers reflect hands-on evidence: Core = regularly practiced with reporting · Applied = internship/lab depth · Familiar = lab exposure · Engineering = systems & professional effectiveness.
Next conversation