Skip to content
bughunter.pro
EN/FRRequest an audit
Independent bug bounty hunter - Web & API security

Vulnerabilities found before hackers do.

Your vulnerabilities already exist. The only question is who finds them first.

Active researcher onYesWeHackIntigriti
01 Approach

Who better than an ethical hacker to find your vulnerabilities?

An attacker only needs one flaw. My job is to find it before they do. I think like them: patient, methodical, quiet. Where automated tools stop, I keep going, uncovering the weaknesses in your system until I reach the one that truly threatens your business. Then, instead of walking away with what I found, I hand you everything you need to fix the vulnerabilities for good.

Adversarial mindset

Real attacker logic. I hunt the path no scanner will ever find.

Real-world rigor

Hands-on experience built on high-traffic platforms and sensitive environments.

Absolute discretion

Strict confidentiality, NDA as standard, encrypted reports if needed.

02 Engagements

An audit shaped around your situation.

Whether you're launching a site or looking to secure a service already live, these are the engagements I run most often.

01

Pre-launch audit

Catch flaws while they still cost a fix, not an incident, before your site or feature ever goes live.

02

Live production testing

Already online? I test it the way a real attacker would, quietly, and without breaking anything.

03

API audit

REST, JSON, GraphQL: I make sure every endpoint exposes only what it should, and only to whoever should reach it.

04

Auth & access review

Who can reach what? I hunt the access that crosses the lines you set: IDOR, privilege escalation, broken permissions.

05

Continuous testing

Coverage over time instead of a one-off snapshot: I keep testing as your perimeter evolves.

06

Second opinion & post-incident

A doubt after an alert or a major change? I confirm what's real, qualify the impact, and document it.

03 What I test

Anything that takes a request, I'll test.

From a brochure site to a complex business platform: any surface reachable from a browser or an API is a potential target, and therefore a candidate for penetration testing.

Websites & web appsCustomer portals & client areasBack-offices & admin panelsBusiness platformsWordPress & other CMSAuthentication & SSORoles & permissionsPayments & checkoutREST / JSON APIsThird-party integrations
04 What I hunt

The vulnerabilities I go after.

In practice, here are the doors an attacker tries to open. The gist fits in one line for newcomers; the technical detail is there for experts.

Injections & input

Making the app run what it shouldn't.

01XSS
02SQL injection
03File upload abuse
04Path traversal

Access & identity

Seeing or doing what isn't yours.

01IDOR / BOLA
02Broken access control
03Privilege escalation
04Broken authentication

API & logic

Bending business rules and authorizations.

01API authorization flaws
02BFLA
03Mass assignment
04Business logic flaws

Server & config

Exploiting a setting left open.

01SSRF
02CSRF
03CORS misconfiguration
04Information disclosure
05 Method

A repeatable path from recon to retest.

01

Recon & mapping

I map everything you have exposed, including the subdomains, endpoints and forgotten flows you didn't know were still online.

02

Surface analysis

I learn your roles, trust boundaries and business logic before attacking, to aim precisely rather than broadly.

03

Manual exploitation

Where scanners are blind, I hand-craft attacks and chain weaknesses into real, demonstrable impact.

04

Impact & proof

A reproducible proof of concept: you see exactly what an attacker could reach.

05

Clear reporting

Priorities both leadership and engineers can read, with what to fix and in what order.

06

Retest & close

I re-check every fix myself: a flaw is only closed once I've confirmed it.

06 Deliverables

What you receive after my engagement.

Work your teams, or your providers, can act on immediately, with every finding proven and explained.

Prioritized report

Every flaw ranked by real severity and urgency, so the most dangerous gets fixed first, not the loudest.

Reproducible proof of concept

The exact steps to replay each flaw. No "maybe", no theory, proof you can hand straight to your developers.

Business impact

In plain language: what it exposes, what it could cost, and who is affected. Readable without a security background.

Concrete remediation

Not just "it's broken": how to fix it, step by step, in a way your team can actually apply.

Retest included

Once you've patched, I re-check your fixes. The door is shut, and verified, not assumed.

Debrief & handover

A walkthrough of the report with your team, so the findings are understood and owned, not just delivered.

07 Scope

Focused where it counts: web and APIs.

I focus on two surfaces: the web and the APIs, exactly where your customer data, your payments and your access controls live. Depth over breadth: I'd rather know these environments inside out than scan everything at the surface, where the costly vulnerabilities never show.

The web layer

Websites, web apps, customer portals, client areas, back-offices and CMS: the full interface your users and staff touch.

WebsitesWeb appsPortalsClient areasBack-officesSPACMS

The API layer

REST and JSON APIs, authentication, authorization, and the third-party integrations that hold everything together.

RESTJSONGraphQLAuth & tokensWebhooksIntegrationsWebSocketsOAuth & OIDCAPI versioning

Native mobile is outside my scope. For that, I'll happily point you to a trusted specialist.

08 Track record

Proven where the stakes are highest.

Vulnerabilities found, reported and fixed across French public-sector services, CAC 40 groups, luxury-industry leaders and more. A practice kept sharp as an active researcher on public bug bounty platforms.

French public-sector services (.gouv.fr)

CAC 40 groups

Luxury-industry leaders

YesWeHack & Intigriti researcher

A few real findings, anonymized and fixed

SQL injectionRead access to an entire company's database.
Critical
IDORAccess to other users' complete records on a public-sector service (.gouv.fr).
Critical
XSSZero-click takeover of a user account, no action required from the victim.
High
CSRFAn account's email silently swapped for the attacker's, with no confirmation, opening a clear path to account takeover.
High
Business logicPurchase-limit bypass: ordering several units of an item capped at one per customer.
Medium
Active onYesWeHackIntigriti

I never disclose a client's name or the vulnerabilities found.

09 FAQ

Questions, answered.

Do you sign NDAs?

Yes. Confidentiality is the default, not an upsell. An NDA is signed before any scope is shared, and reporting can be fully encrypted on request.

Will you ever name my organization?

Never. Your identity, your scope and every finding stay strictly between us. Discretion is part of the service.

Do you test mobile applications?

My focus is the web and APIs. That is where I go deepest and find the highest-impact vulnerabilities. For native mobile, I will gladly refer you to a specialist I trust.

How does an engagement start?

A short scoping conversation, a signed agreement, then a defined testing window ending in a clear, prioritized report.

Fixed-scope audit or continuous testing?

Both. A time-boxed audit with a full report, or ongoing results-based testing across your perimeter, whether production, staging or development. Either way, everything runs under a signed testing agreement.

How long does an engagement take?

It depends on the scope. A focused audit can wrap in a few days; a complex application will take one to two weeks. We align on that during scoping.

How much does an audit cost?

Scoped to what you actually need: pricing depends on the size and complexity of your perimeter. We define it together in a first, no-commitment conversation.

10 Contact

Start with a conversation.

Tell me what you'd like tested. Everything you send is treated as strictly confidential.

The right time to reach out

  • You're about to put a new site or feature live.
  • You handle sensitive data and have never had your application audited.
  • You expose an API and aren't sure the authorizations hold.
  • A client, an insurer or a compliance rule requires a penetration test.
  • A scanner flagged something and you want human validation.
Encrypted exchange available on request (Session ID or PGP key).