GET /febin-benny HTTP/1.1 
200 OK · Kerala, India
Hostfebin.dev
Acceptsecurity/*, systems/*
HTTP/1.1 200 OK

Junior Security
Analyst

Bug Bounty · Web App Pentesting · Active Directory · Bash · Linux · Windows · OWASP Top 10

Passionate about hands-on cyber defense, vulnerability assessments, bug bounty hunting, Active Directory security, and building tools and training platforms.

/projects2 endpoints
GET /breachlabs 200 OK

A hands-on cybersecurity training platform covering all 10 OWASP Top 10 (2021) vulnerability categories — Broken Access Control, Injection, Cryptographic Failures, and more. Self-contained step-by-step labs in a HackTheBox-style interface with authentication, a leaderboard, and server-side flag verification via Postgres functions on Supabase.

GET /cyber-quiz-bot 200 OK

A Python-based Telegram bot built to test and sharpen cybersecurity awareness through interactive quizzes. Uses the Telegram Bot API — Python automation, API integration, and user engagement in one small tool.

/writeups2 records
GET /privilege-escalation-wildcard CRITICAL

Vertical privilege escalation via permission wildcard injection — a low-privileged account's authentication response was modified so its permissions[] array became a wildcard, unlocking administrative functionality client never should have trusted.

Broken Access ControlPrivilege EscalationVDP
GET /lfi-cloudflare-bypass HIGH

Local file inclusion via origin IP disclosure and Cloudflare WAF bypass — passive recon exposed the origin server behind Cloudflare, leading to a media endpoint that leaked /etc/passwd once requests bypassed the WAF entirely.

LFIWAF BypassBug Bounty
/certificates3 issued
BearerCEH · EC-Councilissued Nov 2022 · expired Nov 2025 · ECC3957846102 EXPIRED
BearerGoogle Cybersecurity ProfessionalCoursera 200 OK
BearerGoogle IT Support ProfessionalCoursera 200 OK
/education1 record
GET Bachelor of Computer Applications 200 OK
University of Calicut — graduated Nov 2022
POST /contact
// EOF — thanks for stopping by