I break web applications before attackers do — specialized in Access control vulnerabilities. I uncover security flaws and improve defenses through hands-on research.
I'm MD MAINUL ISLAM (SIAM) — a security researcher & bug bounty hunter from Dhaka, Bangladesh. My core expertise is access control vulnerabilities — IDOR, RBAC bypass & privilege escalation.
Since 2022, I've reported 150+ valid vulnerabilities on HackerOne (1200+ reputation), with additional findings on YesWeHack — including a finalist spot in H1 Bug Hunt 2024 and #13 rank in Bug Hunt 2026 (BD).
Beyond hunting, I hold 8 industry certifications and work hands-on with real-world targets — HR systems, role-based workflows & complex business logic where automated tools fail.
Specialized offensive security expertise, validated on real-world targets.
Core specialty — finding IDOR, broken access control, RBAC bypass and privilege escalation in real-world applications.
▸ HOVER / TAPEnd-to-end vulnerability assessment & penetration testing of web applications and APIs — from recon to validated exploit.
▸ HOVER / TAPIdentifying complex logic issues in HR systems and role-based workflows that automated scanners always miss.
▸ HOVER / TAPReconnaissance, enumeration and exploitation — plus computer networking and data structures foundations.
▸ HOVER / TAPReported on HackerOne with 1200+ reputation points, plus multiple findings on YesWeHack.
Ranked #13 in Bangladesh on HackerOne Bug Hunt 2026.
Finalist in HackerOne Bug Hunt 2024 — all over Bangladesh.
Active hunter on RDP-based environments — identified multiple security issues.
From recon to report — full-cycle offensive security support for your product.
Full VAPT of web apps — OWASP Top 10, manual testing, real exploit proof-of-concepts, actionable reports.
▸ HOVER / TAPContinuous security testing on live targets — 150+ valid bugs reported on HackerOne, Bugcrowd, YesWeHack.
▸ HOVER / TAPDeep-dive into authorization logic — IDOR, RBAC bypass, privilege escalation across roles & workflows.
▸ HOVER / TAPREST & GraphQL API assessment — broken object level authorization, mass assignment, injection, auth flaws.
▸ HOVER / TAPManual review of critical flows — payment, HR systems, role-based workflows where scanners always fail.
▸ HOVER / TAPClear, developer-friendly vulnerability reports with severity ratings, reproduction steps & fix suggestions.
▸ HOVER / TAPWhether you need a web app penetration test, an access control assessment, or just want to talk bug bounty — my inbox is always open.