I'm Asim Alharbi — I hunt broken access control, authorization flaws and server-side bugs across public bug bounty programs, then disclose them responsibly.
Who's behind the handle, and what I'm actually after.
I'm a web and API penetration tester based in Saudi Arabia. I hunt on public bug bounty programs — mostly broken access control, authorization flaws and server-side bugs — and I write them up so they actually get fixed.
I came up through web and rev CTF and still play with my team, C00kie_Byte (0xCB). I'd rather go deep on one bug class than find one of everything, so most of my time goes into object-level authorization — finding where an app forgets to check who you are.
The vulnerability classes I go looking for first — where business logic and identity meet.
IDOR & BOLA where an object ID is all that stands between you and someone else's data. The most common critical, and the most overlooked.
SSRF pivots into internal networks and cloud metadata. Chaining a fetch primitive into full internal reach where filters are too trusting.
Privilege escalation and tenant isolation gaps — the flaws a scanner never sees because they live entirely in how the app decides who you are.
Auditing plugin source for auth bypass, injection and unrestricted actions, then coordinating disclosure with vendors and the wider ecosystem.
Undocumented endpoints, mass-assignment and rate-limit gaps. Where the docs end is usually where the interesting behaviour begins.
Rev challenges in CTF and binary logic bugs in the wild — reading what a program actually does, not what its docs claim.
Each one written as a case study — problem, action, outcome. Click to open. Swap for your real findings.
Offensive web security credentials — both verifiable by ID.
When I'm not hunting live targets, I play — mostly web and reverse engineering.
The CTF & bug bounty crew I run. We chase web exploitation and rev challenges, and carry the same instinct into real programs: read the logic, find where trust breaks, prove it cleanly.
Open to bug bounty collaboration, security research and CTF. If your program needs a sharp pair of eyes on access control — let's talk.