I hunt for security flaws in web applications and APIs — access control, auth flows, business logic, XSS and other vulnerabilities that automated scanners tend to miss. Every finding is reported responsibly to the vendor before being written up here.

Hello, my name is Moh Faiz Hidayatulloh, i am an Independent security researcher based in Kebumen, Indonesia. I started to dive in Bug Hunting since September 2025. My main focus is web application and API security — digging into authentication flows, access control, XSS, business logic and other vulnerabilities that automated scanners usually overlook.
Actively reporting findings through public bug bounty programs and private VDPs. Every writeup published here goes live only after the bug has been fixed or disclosure has been authorized by the affected party.