Skip to content

alpernae/alpernae

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

45 Commits
 
 

Repository files navigation

Hi 👋, I'm Alperen

Application Security Researcher

Visitor Count

I’m an Application Security Researcher and part-time bug bounty hunter. My focus is on identifying vulnerabilities and building automation offensive security tools.

Github Badge HackerOne Intigriti Exploit_DB

What I’m Building & Learning

🔍 Focus: Crushing app vulnerabilities, hunting bugs and automating security testing.

🛠️ Current Project: AuthMutator — Burp Suite extension for experimenting with authentication issues and attack simulations.

🌱 Learning: Game Hacking — exploring memory manipulation, cheat detection, and reverse engineering.

🤝 Collaborating On: Open-source tooling for CI/CD security and automated app-sec workflows.

💡 Fun Fact: I once found a critical bug at 3 AM fueled by coffee and sheer curiosity — caffeine + curiosity = 🔥.

Reported CVEs

I actively hunt for security flaws and share my findings responsibly. Here are a few notable vulnerabilities I've uncovered:

  • CVE-2024-40422 – Path Traversal in DEVIKA-AI. Details
    This vulnerability allowed attackers to access sensitive files on the server, highlighting the importance of strict input validation in AI platforms.

  • CVE-2022-54321 – SQL Injection in an E‑Commerce CMS. Details
    A classic SQL injection flaw that could expose customer data. It reinforced my focus on automating detection of injection issues in web applications.

  • CVE-2020-35241 – Cross-site Scripting in FlatPress CMS. Details
    This XSS vulnerability demonstrated how even small content management systems can pose significant security risks if input is not properly sanitized.

Blog & Write-Ups

I love sharing what I learn from my security research and bug bounty adventures. Here’s a glimpse of my recent posts:

Tech Stack & Tools

JavaScript Python TypeScript Go C# Bash Node.js React Next.js Django Flask Express.js PostgreSQL MySQL MongoDB Redis Docker Git Linux Burp Suite VSCode AWS Azure GCP

Let's Connect!

X Medium LinkedIn Instagram YouTube Twitch

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages