Open to work · Remote & relocation

Matin
Jafari.

I break web applications for a living — then build the tooling that finds the next one. Security researcher & software engineer.

85
reports resolved
6.82
signal · 88th %ile
16
programmes
33K
community
SCROLL ↓
01

The record

Verified via platform APIs · 2026-07-27

85 vulnerabilities resolved in nine months, at a signal score in the top 12% of all HackerOne researchers.

Signal is HackerOne’s measure of report quality — reputation earned per report, capped at 7.00. It’s the number that separates researchers who submit noise from researchers who submit findings. Every figure here is public and checkable.

1,655
Reputation
HackerOne
6.82
Signal
HackerOne
18.0
Impact
HackerOne
364
Reputation points
YesWeHack
#668
Hunter rank
YesWeHack
40
Reports submitted
YesWeHack
  • Bounty Hunter
  • Streaker
  • TrailBlazer
  • Diversity
  • A5: Broken Access Control
  • A7: Cross-Site Scripting
  • Milestone Level 3
  • Milestone Level 2
  • Milestone Level 1
  • Insecticide
  • Good Samaritan
02

Selected writeups

  1. 01

    The Fake .js File That Cached Everyone's Login

    An API that handed out session tokens plus a CDN that thought it was serving JavaScript equals a one-click account takeover you could serve to anyone.

    CriticalWeb Cache Deception
  2. 02

    The Boolean That Owned Every Account

    A passwordless login trusted the browser to grade its own homework — so I flipped one false to true and walked into anyone's account with just their email.

    CriticalAuth Bypass
  3. 03

    The Popup That Handed Me Everyone's Account

    A single wildcard in one postMessage call quietly turned an OAuth popup into an account-takeover machine.

    CriticalInsecure postMessage (OAuth Token Leak) → Account Takeover
  4. 04

    The First Name That Signed Me In as You

    A profile field nobody guards became the loose thread that unraveled an entire OAuth login — one unescaped name away from full account takeover.

    CriticalXSS to OAuth Account Takeover
  5. 05

    The Magic Link That Showed Itself to the Wrong Person

    A feature meant to email a student's login link put it on the teacher's screen instead — turning convenience into one-click account takeover.

    CriticalAuth Bypass
  6. 06

    One Vendor Number, the Whole Directory — Then the Keys

    The app identified vendors by a number in the request. Read anyone's profile with it; then change their email and own the account.

    CriticalIDOR → Account Takeover
03

Videos & tutorials

04

Open-source tooling

05

What I do

Engineering

Security and infrastructure tooling, shipped as real software — packaged, containerised, documented and licensed.

  • TypeScript
  • Rust
  • Go
  • Python
  • Shell
  • JavaScript
  • PHP

Security

Web application vulnerability research against global bug-bounty programmes, with a signal score in the top 12% of all HackerOne researchers.

  • IDOR
  • XSS
  • Account Takeover
  • SSRF
  • GraphQL
  • Auth Bypass
  • Business Logic

Access Control & Authorisation

IDOR · Account Takeover · Authentication Bypass · Business Logic

Client-Side

Cross-Site Scripting · Open Redirect

Server-Side

SSRF · Unrestricted File Upload · Denial of Service

API & Data Exposure

GraphQL · Information Disclosure · PII Exposure

Programmes reported to

Ford · Walmart · Disney · Nintendo · Experian · Yelp · Duolingo · HubSpot · Eurofins · Synthesia · Doximity · Henkel · SAS · Whatnot · Amplify

06

Community

33,749 combined

I teach web security and tooling to a Persian-speaking developer community of around 33,000.

07

About

I'm a software engineer and security researcher. Most of what I build comes out of what I break: a recon pipeline that had to fit inside a free-tier CPU budget, a fuzzer that kept flagging WAF pages as XSS until I made it verify the DOM, a monitoring bot I wrote because I kept missing JavaScript changes on targets I was watching.

Since late 2025 I've submitted 85 reports across HackerOne and YesWeHack — mostly access-control and client-side issues — to programmes including Ford, Walmart, Nintendo and Disney. I care more about my signal score than my report count: 6.82 out of 7 means the things I send are real.

I also run a Persian-speaking developer community of around 33,000 people, where I teach web security and tooling. Explaining a bug to a few thousand people who have never seen one is a different skill from finding it, and it has made me better at writing reports.

I'm looking for a role where both halves are useful — application security, product security, or engineering on a team that takes security seriously.

08 — Contact

Let’s talk.

Open to full-time application-security, product-security or engineering roles — remote, or on-site with visa sponsorship. Also open to private programme invites and contract testing.