About Me
I am a dedicated Cybersecurity Researcher and Penetration Tester based in Dhaka, specializing in finding and exploiting critical vulnerabilities.
With over 6 years of experience in bug bounty hunting and nearly 2 years in formal penetration testing, I have successfully identified and reported approximately 500 vulnerabilities across more than 50 diverse companies, organizations, and governmental entities.
My expertise covers full-stack vulnerability research (IDOR, XSS, RCE, LFI, etc.), and I am proficient with key industry tools like Burp Suite Pro, Metasploit, Nmap, and more.
- emptymahbob@gmail.com
- +8801813880373
- Dhamrai, Dhaka, Bangladesh
Education:
- B.Sc. in Software Engineering (Cybersecurity Major) - Daffodil International University (2022-2026)
- Diploma in Computer Science & Engineering - Faridpur Polytechnic Institute (2017-2021)
Compliance & Frameworks:
HIPAA GDPR NIST OWASP Top 10Core Capabilities
Areas of Expertise
- Penetration Testing & Vulnerability Research
- Exploitation (IDOR, XSS, CSRF, RCE, LFI)
- SIEM & Incident Response
- Security Frameworks & Risk Management
- Automation and Scripting
Security Tools
Languages
- Python: Automation & Exploit Development
- PHP: Web Application Security Context
- Bash Scripting: CLI & Workflow Automation
- SQL: Database Interaction & Injection Testing
- CVSS, Git: Other Technologies
Professional Experience
Private Penetration Testing
Jan 2024 - Present (Contractual)
PentesterSpace
- Conducted project-based penetration tests for local & international companies.
- Delivered detailed vulnerability reports with impact analysis & remediation steps.
- Collaborated with development teams to ensure perfect implementation of patches.
Security Researcher (Bug Bounty Hunter)
Jan 2020 - Present
Hackerone
- Conducted security testing for 50+ international companies, reporting critical vulnerabilities.
- Specialized in identifying complex flaws including IDOR, CSRF, XSS, RCE, and Business logic issues.
- Collaborated with other researchers to maximize the security impact of findings.
Bug Bounty Hall of Fame
Acknowledged and rewarded by global organizations for finding and reporting security flaws.
Community & Participation
CTF and Hacking Contest Participation:
- Finalist DIU CYBERCON CTF 2025 | On-site National Cybersecurity Conference and CTF Competition.
- Finalist HackerOne Bug Hunt 2023 | On-site Hacking Contest & Security Conference.
- Finalist BUET CSE Fest 2023 | On-site CTF Contest & Conference.
- Finalist Take-Off programming contest | On-site Programming Contest & Conference.
- Participant in Bugcrowd Hacker Cup 2023.
- Participant in BDSec CTF 2025.
- Participant in HackerOne Ambassador World Cup 2023.
Blog / Writeups
Documenting my journeys in CTFs, Penetration Testing, and Bug Bounty hunting.