About

I’m Md Abdullahil Kafi — software engineer and security researcher.

I break things on purpose and write down how. Mostly:

  • CTF — web, crypto, reversing, pwn
  • Bug bounty — application logic, access control, injection
  • CVEs — coordinated disclosure, root-cause analysis
  • Research — whatever I’m currently nerd-sniped by

And, occasionally, things that aren’t code at all: politics and philosophy, under Thoughts.

Elsewhere

Disclosure

Everything here describes work done with authorization, on systems I own or was permitted to test. Writeups are published after a fix ships or the program clears them.