~/ introduction

Security-minded
engineer & researcher.

I'm Wahyudi — I build reliable software, then attack it before the adversaries do. SDET automation, application security, and offensive research with responsible disclosure at the core.

  • Web App Pentesting
  • API Security
  • Mobile Security
  • SDET / Test Automation
  • Secure Software
  • Bug Bounty & Disclosure

live research doc

Pentesting Methodology

A living playbook I run against real targets — scoped engagements, bug bounty programs and labs. Organized across web, API, phishing and general hacking.

full methodology →
  1. → Web

    Web application attack surface — enumeration, injection, file handling and client-side flaws.

  2. → API

    REST, GraphQL and auth flows — broken object/function access, mass assignment and token abuse.

  3. → Phishing

    Social-engineering delivery — pretexting, payload hosting and credential-harvesting flows.

  4. → Generic Hacking

    Cross-cutting tradecraft that applies to every target and engagement.

~/blog

Latest from the blog

all posts →
3 min read

Subdomain Enumeration Done Right: Passive and Active Techniques

A practical, ordered approach to subdomain discovery — from passive OSINT to active resolution, wildcard handling, and cleanup of false positives.

3 min read

API Security Testing for SDETs: A Practical Checklist

How quality engineers can shift left on API security — threat-focused test cases, auth bypass checks, and automation patterns that don't burn the team's time.

3 min read

Responsible Disclosure: From Finding to Fix, the Full Playbook

What happens between 'you found something' and 'the fix shipped' — triage, evidence, CVEs, timelines, and how to behave like a professional when vendors get busy.

~/projects

Featured projects

all projects →
maintained

Gembok

A privacy-first Android app that locks sensitive applications behind the device's own biometric gate.

androidkotlinprivacybiometric
link ↗details →
maintained

Spotify API Scraper

A lightweight Spotify metadata scraper used to power music discovery experiments without heavy SDK overhead.

spotifyscrapingapidata
repo ↗details →
active

Virtual Office UMKM

A multi-tenant web platform that gives small businesses a virtual office — digital storefront, document storage, and customer status tracking.

web-appumkmmulti-tenanttypescript
details →
archived

WhatsApp Status Downloader

An offline-first Android app that saves view-once and regular WhatsApp statuses to local storage.

androidwhatsappjavascriptwebview
repo ↗details →

~/disclosures

Security disclosures

Findings reported through coordinated disclosure to major platforms — root cause and impact, redacted until remediation.

all disclosures →
HighCWE-287Improper Authentication

Kaltura — Email Verification Bypass in Self-Serve Signup

Kaltura's self-serve signup issued live, authenticated partner accounts without ever verifying the email — an unvalidated CAPTCHA, a verification secret returned in the API response, and a login path that never checked verification status at all.

redacted
read →
MediumCWE-306Broken Authentication

Vercel — OAuth Token Introspection Without Caller Authentication

Vercel's OAuth 2.0 introspection endpoint returned full token claims to any caller, with no client authentication and no rate limiting. The sibling revocation endpoint enforced credentials — which is what turned this from a design choice into a wiring gap.

redacted
read →

connect

Let's talk security.

Research, triage, mitigation, or a challenging target — I'm open for collaboration and security consulting.