s
shifuke

Johnson M

@shifuke

Application Security Analyst

Kenia
Engels
Sommige informatie wordt in het Engels weergegeven.
Over mij
I am a web application security researcher with a proven bug bounty track record on HackerOne, where I am ranked #3 in Kenya for broken access control findings. I have deep working knowledge of the OWASP Top 10 and manual vulnerability discovery. I specialize in identifying API security flaws and business-logic gaps to help organizations secure their production environments.... Lees meer

Skills

s
shifuke
Johnson M
offline • 
Gemiddelde reactietijd: 1 uur

Bekijk mijn diensten

Programmering en technologie
I will perform an authorized web application security assessment

Portfolio

Werkervaring

Hackers_Academy

cyber sucurity

Hackers Academy

Dec 2024 - Present • 1 yr 10 mos

Independent Security Researcher – Bug Bounty Hunter HackerOne — Public and Private Bug Bounty Programs August 2025 – Present | Remote Conduct authorized security testing of production web applications and APIs to identify vulnerabilities and business-logic flaws. Achieved a HackerOne Signal score of 7.00, placing in the 99th percentile, and an Impact score of 15.00. Ranked #3 in Kenya on HackerOne’s national leaderboard for Web Application and Broken Access Control submissions in Q3 2026. Discovered and responsibly reported broken access control vulnerabilities, API information disclosures, and incomplete security fixes that exposed restricted user and event-related information. Performed reconnaissance, endpoint mapping, manual testing, exploitation proof-of-concept development, vulnerability reproduction, and responsible disclosure reporting. Applied the OWASP Top 10 methodology to identify access-control gaps, API weaknesses, sensitive-data exposure, and other web application security issues. Selected to test invite-only private bug bounty programs based on the quality and reliability of submitted vulnerability reports. Participated in cybersecurity CTF competitions involving web exploitation, network security, and password-cracking challenges.