Available for new opportunities

Aadilsha Shahmadar

[ madmax_4 ]

Security Researcher & Bug Bounty Hunter

Offensive security researcher focused on web application security, credential leak hunting, and secret scanning automation. I find, validate, and responsibly disclose vulnerabilities — with a focus on high-impact findings and clear, actionable reports.

Based in Rajkot, India Focus Web App Security · Secret Scanning Cert C|EH — EC-Council
  • 0+Password & key leaks found
  • 0+Website security issues found
  • 0Security tools built
  • 0Hall of Fame recognition
01.

About

AS MADMAX_4
handlemadmax_4
baseRajkot, Gujarat — IN
disciplineOffensive Security
certC|EH — EC-Council

I'm a security researcher who finds leaked passwords, tests websites for weak spots and writes simple, actionable reports.

Most of my work is building smart tools that automatically scan the internet for exposed secrets, then double-checking each issue with safe, harmless tests — so companies get real problems, not false alarms.

For websites, I think like an attacker but act like a partner: checking login security, permissions, and data safety. Every report starts with impact in plain words, shows how to reproduce safely, and ends with how to fix it.

  • 01
    Safe testing, always. I prove issues without damaging anything or accessing private data.
  • 02
    Less noise, more signal. Boring repetitive checks are automated, so human time goes to real judgment.
  • 03
    Responsible & confidential. No public leaks, no naming companies, everything shared privately first.
02.

Skills

Vulnerability Classes

SQL Injection
Cross-Site Scripting (XSS)
Server-Side Request Forgery (SSRF)
Cross-Site Request Forgery (CSRF)
IDOR / Broken Access Control
Business Logic Flaws
Authentication & Session Bypass
JWT / OAuth Misconfiguration
File Upload Exploitation
LFI / Path Traversal
SSTI Injection
XXE Injection
Remote Code Execution
Subdomain Takeover
CORS Misconfiguration
Open Redirect
WAF & Rate Limit Bypass
HTTP Request Smuggling

Tooling

Burp Suite
Nuclei
Nmap / Naabu
subfinder / amass
httpx / katana / gau
ffuf / gobuster
dalfox / xsser
sqlmap
arjun / ParamSpider
waybackurls / uro
Subzy
Metasploit
wafw00f
OpenRedirex
TruffleHog v3
Custom Python & Bash scripts

Cloud & OSINT

Cloud storage misconfiguration
GitHub dorking & leak discovery
Source code analysis
JS bundle route extraction
DNS enumeration
Passive asset discovery
Attack surface mapping
Report writing & disclosure
03.

Toolchain

  • TruffleHog v3verified secret scanning
  • Nucleitemplate vuln scanning
  • DalfoxXSS scanning · WAF evasion
  • Katanacrawling · param spidering
  • Subfindersubdomain enumeration
  • Httpxprobing · TLS · tech detect
  • DnsxDNS resolution & filtering
  • Gfpattern triage
  • Waybackurlshistorical URL harvesting
  • Gauknown URL collection
  • OpenRedireXopen redirect discovery
  • Burp Suite Prointercept · repeat · intrude
  • Nmapnetwork discovery
  • Metasploitexploit framework
  • Wiresharkpacket analysis
  • PostmanAPI experimentation
  • cURLraw HTTP craft
  • Githistory & diff review
  • Webhook ListenersOOB HTTP/DNS callbacks
  • Python · requestsread-only verification
  • OAuth 1.0arequests-oauthlib
  • Wayback CDX APIarchive queries
  • Kali Linuxprimary operating system
  • MCPsecurity orchestration
04.

Projects

01 Built by me

Secret Scanner for New Platforms

tool

An automatic scanner that finds leaked passwords on code platforms where no ready-made scanner exists. It lists projects, checks them safely, and reports only confirmed leaks.

why it matters

I figured out how an undocumented platform works and made it as easy to scan as GitHub — saving hours of manual work.

  • Bash
  • curl
  • jq
  • TruffleHog v3
  • REST API
  • Bearer Auth
  • Git
02 Built by me

Safe Leak Checker Toolkit

tool

A set of careful checks that prove a leaked password is real — without changing, deleting or harming any account.

why it matters

A clever safe test that proves access without posting or modifying anything — strong proof, zero damage.

  • Python
  • requests
  • requests-oauthlib
  • OAuth 1.0a
  • curl
  • Cloud read-only APIs
03 Designed by me

Smart Security Assistant Engine

engine

An AI-powered helper that runs website checks step-by-step, collects results in one clean report, and highlights what needs fixing first.

why it matters

Automatically catches tricky hidden issues and turns technical output into simple, structured findings anyone can understand.

  • Python
  • MCP
  • Burp Suite
  • OOB Webhooks
  • JSON Findings
05.

Research Findings

Company names and private details are hidden for privacy. All issues were reported privately to owners first.

critical Exposed Credential F-01

Origin CA Key Committed to an Official Package Registry Repository

Discovered an origin CA key sitting in an official package registry repository in a 2024 commit. Reported straight to the vendor — no self-verification on a key this hot.

impact A live CA key in an official repository could enable interception, decryption or manipulation of TLS traffic if abused.
critical Exposed Credential F-02

Complete OAuth 1.0a Credential Set in a Public Config File

Found a full OAuth 1.0a credential set in a public XML configuration. Confirmed with a read-only identity endpoint, then proved write authorization using an intentionally invalid payload — never writing real data.

impact Full account takeover of the associated account.
critical Exposed Credential F-03

Cloud Service Account Keys Leaked Across Public Repositories

Identified multiple administrative service account keys exposed in public repositories. Disclosed through the platform's own security advisory channel.

impact Full administrative control of associated cloud projects — database, storage, auth and messaging.
critical Broken Access Control F-04

Multi-Tenant IDOR Enabling Tenant-Wide Account Takeover

Uncovered a tenant isolation failure on an enterprise authentication platform's API-credentials endpoint — manipulating the auth token cookie exposed arbitrary tenant API secrets.

impact Cross-tenant secret exposure and tenant-wide account takeover.
high Exposed Credential F-05

Live Cloud Provider API Token in a Public Container Tooling Repo

Spotted a live personal access token for a cloud infrastructure provider in a public repository and validated it against a read-only account endpoint.

impact Full account access — resource abuse, financial cost and data loss.
high Web Vulnerability F-06

Reflected XSS Weaponised to Session Exfiltration

Traced unencoded reflection in an automation API's redirect query parameter and built a weaponized proof-of-concept that exfiltrates session cookies to an external listener — possible because the HttpOnly flag was missing.

impact Session hijacking, credential theft and one-click account takeover via cookie exfiltration.
high Web Vulnerability F-07

HTTP-Method WAF Evasion → Stored HTML Injection

Found that the edge WAF blocked POST but allowed identical malicious payloads over PATCH — letting stored HTML injection land in rich-text notes and expose session access tokens.

impact Persistent injection in a shared workspace plus exposure of session tokens.
medium Exposed Credential F-08

Live URL Shortener API Token in a Browser Extension Repo

Found a live API token for a URL shortening service in a public browser extension and verified it against a read-only user endpoint.

impact URL shortening abuse, spam distribution, quota theft.
medium Transport Security F-09

Missing HSTS on High-Value Authentication Endpoints

Audited perimeter edge routing and found authentication endpoints shipping without HSTS headers.

impact Users exposed to SSL-stripping and protocol downgrade vectors.
06.

Experience

Nov 2025 — Aug 2026

Web Pentester

RaqibSecOps

Hands-on Vulnerability Assessment and Penetration Testing on live security engagements, working directly with the founder on scoped client assessments.

  • VAPT
  • Web App Testing
  • Live Engagements
May 2025 — Nov 2025

Cybersecurity Intern

Cyber Security Protectors (CSP)
  • Black-box and grey-box VAPT across client web applications and internal network perimeters.
  • End-to-end vulnerability triage and manual verification of scanner output, producing formal remediation reports with defence-in-depth guidance.
  • Designed and ran controlled social-engineering and phishing simulations to measure employee security awareness.
  • Assisted with digital forensics, log analysis and preliminary incident response handling.
  • Focused training in manual bug hunting: IDOR, XSS, OS command injection, RFI and RCE.
Education & Certification

Bachelor of Commerce (B.Com)

—

Certified Ethical Hacker (C|EH) — EC-Council

// recognition

Hall of Fame

Bournemouth University — Hall of Fame

Acknowledged in the university's public Hall of Fame for security research reported through their disclosure program.

View listing
07.

Get in touch

Have a website to test
or a role for me?

I reply fast with a simple plan: what I'll check, how long it takes, and what you'll get. No confusing tech talk unless you want it.

Open mail client