Product Security · Bug Bounty · API Security
$ whoami // ferdus_alam · top_researcher · self_taught

I find what
scanners miss.

Product Security Engineer & Independent Researcher

500+ validated vulnerabilities. $72K+ from a single program. Ranked #1 in a leading private SaaS program. Entirely self-taught — I built this through manual testing, depth-first research, and obsessive focus on business logic that automated tools will never catch.

Manual-first testing SaaS authorization Critical impact Remote global
500+ Valid Vulns Reported
$72K+ Single Program Earned
#1 SaaS Program Rank
Top 7 HackerOne Country Rank
Why teams call me

I turn messy product behavior into clear, reproducible security impact that engineering teams can fix.

Where I am strongest

Authorization, multi-tenant SaaS boundaries, account recovery, API object access, and abuse of trusted workflows.

What you get

Concise reports, exploit paths, business impact, practical remediation guidance, and retest-ready validation.

How I Work
Depth-first security research.
Built for real products.
01 / Map

Model the product

I identify roles, object ownership, tenant boundaries, state changes, and trust assumptions before touching payloads.

02 / Break

Attack business logic

I chain normal product actions in abnormal orders to expose privilege, recovery, billing, and workflow failures.

03 / Prove

Show real impact

Every report is written with reproduction steps, affected scope, severity reasoning, and exploit constraints.

04 / Fix

Support remediation

I help teams close the root cause, retest patches, and avoid variant bugs across similar endpoints.

Selected Critical Findings
Business-critical bugs.
Zero noise.
Critical
Account Takeover via Password Reset Token Flaw

Weak token validation enabling full account compromise without user interaction — all account types in production.

Critical
Cross-Tenant Data Exposure (IDOR / BOLA)

Multi-tenant IDOR enabling unauthorized access to sensitive data across organizational boundaries in live SaaS.

High
Privilege Escalation via Access Control Bypass

Low-privilege users reaching admin-level permissions via authorization flaw impacting core data governance.

High
Broken Object-Level Auth in REST API

Systemic API parameter manipulation exposing confidential records across accounts — multiple endpoints affected.

Critical
Authentication Bypass via JWT Misconfiguration

Algorithm confusion attack allowing forged tokens to authenticate as any user without credentials.

High
Mass Assignment in User Profile API

Unprotected object properties allowing users to self-elevate roles and unlock restricted platform features.

What I Offer
What I can do
for your product.
🔐
Application Penetration Testing

Deep manual testing of web applications targeting authentication, authorization, and session logic. No automated scanner noise.

Auth · Session · Workflows
🔗
API Security Assessment

REST API audits covering BOLA, broken function-level auth, mass assignment, and token-based flaws across all endpoints.

REST · BOLA · JWT
🏢
Multi-Tenant Architecture Review

Specialized testing of SaaS platforms for cross-tenant data leaks, tenant isolation failures, and authorization boundary issues.

Tenant isolation
🧠
Business Logic Exploitation

Manual discovery of complex logic flaws — privilege chains, workflow bypasses — that DAST tools and automated scanners systematically miss.

Manual chains
🛡️
Access Control Audit

Comprehensive review of RBAC/ABAC implementations, permission models, and data scoping to eliminate privilege escalation paths.

RBAC · ABAC
📋
Security Consulting & Advisory

Collaborative remediation support, authorization design review, and Secure SDLC guidance for engineering teams building at scale.

Fix · Retest · Prevent
Technical Arsenal
The toolkit.
IDOR / BOLA
Account Takeover
Privilege Escalation
Broken Access Control
API Security (REST)
Business Logic Flaws
XSS
CSRF
SSRF
PII Leaks
Mass Assignment
JWT Attacks
Auth Bypass
Multi-Tenant Flaws
Threat Modeling
Secure SDLC
OWASP Top 10
Burp Suite
Manual Pentest
Responsible Disclosure
Vuln Management
Triage & Remediation
Proof of Work
Rankings & recognition.
#1
Program Rank
Leading Private SaaS Program — Highest impact, zero noise
#7
HackerOne India
Country rank achieved in 3 months (Oct–Dec 2024)
400
Bugcrowd Global
Top 400 worldwide across all active researchers
$72K
Single Program
Depth-first strategy on one complex SaaS product
Signature Case Study

$72K+ from one private program

The result came from going deeper into one complex SaaS platform instead of chasing volume. The strategy was simple: understand product roles, map object access, test tenant boundaries, then chain small authorization issues into high-impact reports.

  • Depth-first testing over broad scanner output
  • Business impact framed for engineering and leadership
  • Variant hunting across related endpoints and workflows
Engagement Fit

Best for teams with serious surface area.

SaaS, fintech, internal admin tooling, API-heavy platforms, multi-tenant products, identity systems, and any workflow where access control failure becomes business risk.

Publications
Medium writeups.
Real bugs, real lessons.
Medium · 655 followers
Case Study Mar 24, 2026

How I Made Over $72,000 From a Single Private Bug Bounty Program

A depth-first story about staying on one complex SaaS target and repeatedly finding IDOR, PII leaks, broken access control, and privilege escalation bugs.

IDORPII LeakAccess Control
Read on Medium →
Writeup Mar 23, 2026

How I Found a Critical Account Takeover Vulnerability in a Password Reset Flow

A critical password-reset flow failure where missing token validation allowed unintended password changes and sensitive account data exposure.

ATOPassword ResetToken Validation
Read on Medium →
Logic Bug Nov 10, 2025

How I Unlocked Enterprise Features with One Parameter and Earned $947

A business logic bypass where changing one server-trusted plan parameter unlocked premium and Enterprise trial features without approval.

Business LogicBillingPlan Bypass
Read on Medium →
IDOR Nov 4, 2025

Simple IDORs Lead To PII Leaks Got $1476 Bounty

Two same-root IDORs in workspace team actions leaked arbitrary user PII through audit logs after user ID tampering.

IDORAudit LogsPII
Read on Medium →
Journey Oct 22, 2025

How Bug Bounty Changed My Life

A personal story about learning from scratch, going manual-first, using PortSwigger and real writeups, and turning bug bounty into full-time work.

Bug BountyMindsetManual Testing
Read on Medium →
Case Study Oct 19, 2025

How I Made Over $10,000 Just by Chaining Multiple IDORs

A focused share-function hunting strategy that chained multiple IDOR variants across similar features in one SaaS application.

IDOR ChainSaaSVariants
Read on Medium →
Get in Touch
Open to remote.
Global roles only.

Available for full-time Product Security Engineer roles, consulting engagements, and private bug bounty programs. I work best on complex SaaS products where depth matters more than breadth.