$ cat about_me.txt- 🔐 Finding vulnerabilities before attackers do — breaking things (ethically) so they can't be broken maliciously
- 🐛 Bug Bounty Hunting across web and API targets — chasing auth bypasses, injection flaws, and logic errors
- 🧠 Vulnerability Research — deep-diving into how software fails, root-causing bugs and their exploitability
- 🛠️ Penetration Testing — structured, methodology-driven testing of applications and infrastructure
- 📡 Focus areas: Auth & JWT Attacks · SQL Injection · XSS/CSRF/SSRF · API Security · Business Logic Flaws
- 🌐 Also into: Active Directory · Cloud Security (AWS) · CTF / Reverse Engineering
- 💬 Ask me about: OWASP Top 10, Burp Suite, recon automation, API exploitation
- 📫 Reach me: contact@roxoi.dev
Offensive Security: Penetration Testing · Bug Bounty Hunting · Red Teaming · Social Engineering
Web & App Security: OWASP Top 10 · Auth & JWT Attacks · SQL Injection · XSS/CSRF/SSRF · API Security · Business Logic Flaws
Networks & Systems: Network Security · Linux · Active Directory · Cloud Security (AWS) · CTF / Reverse Engineering
| Project | Description |
|---|---|
| raje-bug-toolkit | Browser-based bug bounty workflow — 19 hunting phases, 269 PortSwigger lab solutions, one-click script generator, zero dependencies |
| roxoi.github.io | Personal site / portfolio |
root@roxoi:~# echo "the quieter you become, the more you are able to hear"