
Subdomain Enumeration Done Right: Passive and Active Techniques
A practical, ordered approach to subdomain discovery — from passive OSINT to active resolution, wildcard handling, and cleanup of false positives.
~/ introduction
I'm Wahyudi — I build reliable software, then attack it before the adversaries do. SDET automation, application security, and offensive research with responsible disclosure at the core.
live research doc
A living playbook I run against real targets — scoped engagements, bug bounty programs and labs. Organized across web, API, phishing and general hacking.
Web application attack surface — enumeration, injection, file handling and client-side flaws.
REST, GraphQL and auth flows — broken object/function access, mass assignment and token abuse.
Social-engineering delivery — pretexting, payload hosting and credential-harvesting flows.
Cross-cutting tradecraft that applies to every target and engagement.
~/blog

A practical, ordered approach to subdomain discovery — from passive OSINT to active resolution, wildcard handling, and cleanup of false positives.

How quality engineers can shift left on API security — threat-focused test cases, auth bypass checks, and automation patterns that don't burn the team's time.

What happens between 'you found something' and 'the fix shipped' — triage, evidence, CVEs, timelines, and how to behave like a professional when vendors get busy.
~/projects
A privacy-first Android app that locks sensitive applications behind the device's own biometric gate.
A lightweight Spotify metadata scraper used to power music discovery experiments without heavy SDK overhead.
A multi-tenant web platform that gives small businesses a virtual office — digital storefront, document storage, and customer status tracking.
An offline-first Android app that saves view-once and regular WhatsApp statuses to local storage.
~/disclosures
Findings reported through coordinated disclosure to major platforms — root cause and impact, redacted until remediation.
Kaltura's self-serve signup issued live, authenticated partner accounts without ever verifying the email — an unvalidated CAPTCHA, a verification secret returned in the API response, and a login path that never checked verification status at all.
Vercel's OAuth 2.0 introspection endpoint returned full token claims to any caller, with no client authentication and no rate limiting. The sibling revocation endpoint enforced credentials — which is what turned this from a design choice into a wiring gap.
connect
Research, triage, mitigation, or a challenging target — I'm open for collaboration and security consulting.