Penetration Tester · Application Security Researcher — Tashkent, Uzbekistan
I break web applications to help fix them. My focus is manual source-code review and responsible disclosure of real vulnerabilities in open-source software, alongside hands-on offensive security labs.
I actively review open-source projects and report vulnerabilities through coordinated disclosure (GitHub Security Advisories and vendor security channels). Reported findings to date span:
- Broken Access Control / IDOR — cross-tenant object access, missing authorization checks
- Server-Side Request Forgery (SSRF) — internal-network and cloud-metadata reach
- Injection — SQL injection, stored / reflected XSS
- Authentication & verification flaws — payment-callback forgery, weak token handling
Published advisories are linked here as they become public. All findings are disclosed privately and coordinated with maintainers before publication.
Web Application Security
OWASP Top 10 · IDOR / Broken Access Control · SSRF · SQL Injection · XSS · Authentication flaws
Methodology & Tooling
Manual source-code review (source→sink) · Burp Suite · SQLMap · Nmap · Gobuster / Dirsearch
Systems & Scripting
Linux & Windows enumeration · Python · Bash · PHP code review
Multi-VHost Security Lab — a custom enterprise-style penetration-testing environment with multiple virtual hosts and realistic, exploitable web vulnerabilities. → https://github.com/Doniyor2510/multi-vhost-security-lab
- LinkedIn: https://linkedin.com/in/doniyor-sotiboldiyev
- GitHub: https://github.com/Doniyor2510