Alva Radian
Bug Hunter | Security Engineer
Passionate about cybersecurity, with a focus on web application security, penetration testing, and vulnerability research. Experienced in identifying security weaknesses, conducting security assessments, and building practical security solutions. Currently working as a Security Engineer, building hands-on security labs as a challenge author and problem setter for Red Team and Blue Team exercises. Always exploring new techniques and improving my skills in offensive and defensive security.
whoami
Alva Radian
cat about.txt
Bug Hunter & Security Engineer
Currently building hands-on security labs as a challenge author
and problem setter for Red Team and Blue Team exercises.
Focused on application security, vulnerability research,
penetration testing, and security operations.
cat ./experience/index.txt — section: Experience and Hall of Fame
[01] Experience
- Security Engineer — Challenge Author / Problem Setter
Builds hands-on security labs and challenges for Red Team and Blue Team exercises on a private platform (name withheld).
- Penetration Testing Projects — Web, Android and API
Delivered several penetration testing engagements for private companies (names withheld), covering web applications, Android applications, and APIs.
[02] Hall of Fame
- Deepnote — Security Acknowledgments
Credited in Deepnote's public researcher acknowledgments.
https://deepnote.com/.well-known/acknowledgments.txt
- UXCam — Bug Bounty Hall of Fame
Listed in the UXCam bug bounty Hall of Fame.
https://uxcam.com/bug-bounty-hall-of-fame/
- Google VRP — Bug Hunters Profile
Public Google Vulnerability Reward Program profile.
https://bughunters.google.com/profile/7606ba31-24c6-4a2e-a111-a9358d90e74a
[03] Security Research
- Statamic CMS — Blind XSS and Business Logic Flaw [open-source software]
Blind XSS and business logic findings reported against the Statamic platform itself.
https://github.com/statamic/cms
- Suteki — Critical Access to SMTP and Database Servers [web platform]
Critical issue that could be leveraged to reach the SMTP and database servers. Reported to the security team, fixed, and rewarded with a bounty.
https://suteki.co.id
- Tripay — Account Takeover and Full Inbox Access [web platform]
Multiple security issues that could be chained into account takeover and unauthorized access to all inboxes. Fixed and rewarded with a bounty.
https://tripay.co.id
- Blibli — Redirect to Attacker-Controlled Page (Credential Phishing) [web platform]
Users could be redirected to an attacker-controlled page for credential theft and phishing. Fixed and rewarded with a bounty.
https://www.blibli.com
- Halodoc — Client-Side Code Execution (Account Takeover) [web platform]
Client-side vulnerability that could execute code on the client, leading to account takeover. Fixed and rewarded with a bounty.
https://www.halodoc.com
and many more.
cat ./skills.txt — section: Skills
[SECURITY]
- Vulnerability Assessment
- Penetration Testing
- Bug Hunting
- Log Management
- Log Correlation
[PROGRAMMING]
- PHP
- JavaScript
- Python
- Bash
cat ./infrastructure.txt — section: Infrastructure and software
- CONTAINERS
- Docker
- VIRTUALIZATION
- Proxmox
- SIEM
- Wazuh
- SOAR
- Shuffle
$ ls ./socials — section: Socials