MD MAINUL ISLAM (SIAM)
Hi, I'm

MD MAINUL ISLAM (SIAM)

I break web applications before attackers do — specialized in Access control vulnerabilities. I uncover security flaws and improve defenses through hands-on research.

whoami → security researcher

Who is Mainul Islam?

I'm MD MAINUL ISLAM (SIAM) — a security researcher & bug bounty hunter from Dhaka, Bangladesh. My core expertise is access control vulnerabilities — IDOR, RBAC bypass & privilege escalation.

Since 2022, I've reported 150+ valid vulnerabilities on HackerOne (1200+ reputation), with additional findings on YesWeHack — including a finalist spot in H1 Bug Hunt 2024 and #13 rank in Bug Hunt 2026 (BD).

Beyond hunting, I hold 8 industry certifications and work hands-on with real-world targets — HR systems, role-based workflows & complex business logic where automated tools fail.

siam@x0xhomelander — bash
siam@x0xhomelander:~$ whoami
security_researcher · bug_hunter · web_app_pentester
siam@x0xhomelander:~$ cat focus.txt
access_control — IDOR · RBAC Bypass · PrivEsc
platforms — HackerOne · YesWeHack
siam@x0xhomelander:~$ ./stats.sh
→ 150+ valid bugs · 1200+ rep · 8 certs · #13 BD 2026
siam@x0xhomelander:~$
ls ./services → 4 modules found

What I do best

Specialized offensive security expertise, validated on real-world targets.

🎯

Access Control Vulnerabilities

Core specialty — finding IDOR, broken access control, RBAC bypass and privilege escalation in real-world applications.

▸ HOVER / TAP

// focus areas

IDORRBAC BypassPrivEsc
🛡️

VAPT & Web App Pentesting

End-to-end vulnerability assessment & penetration testing of web applications and APIs — from recon to validated exploit.

▸ HOVER / TAP

// test coverage

XSSSQLiCSRFAPI Security
🧠

Business Logic Flaws

Identifying complex logic issues in HR systems and role-based workflows that automated scanners always miss.

▸ HOVER / TAP

// specialty

HR SystemsWorkflowsLogic Abuse
🔴

Red Team Fundamentals

Reconnaissance, enumeration and exploitation — plus computer networking and data structures foundations.

▸ HOVER / TAP

// toolkit

ReconEnumerationExploitation
cat certs.txt → 8 verified ✓

📜 Certifications

CNSP — The SecOps Group (Jun 2025) CSEDP — The SecOps Group (Jan 2025) kWAPTA — Knight Squad (Jan 2026) CASA — APISec University (Jan 2026) Google Cybersecurity Professional (Jul 2025) CRTOM — Red Team Leaders (Jan 2026) ACP — APISec University (May 2025) CCEP — Red Team Leaders (Jan 2026)
grep wins → 4 records found

Wins & Recognition

🏆

150+ Valid Vulnerabilities

Reported on HackerOne with 1200+ reputation points, plus multiple findings on YesWeHack.

🥇

Ranked #13 — H1 Bug Hunt 2026

Ranked #13 in Bangladesh on HackerOne Bug Hunt 2026.

🎖️

H1 Bug Hunt 2024 Finalist

Finalist in HackerOne Bug Hunt 2024 — all over Bangladesh.

💻

RDP-Based Environment Hunting

Active hunter on RDP-based environments — identified multiple security issues.

load capabilities → 6 modules ready

What I can do

From recon to report — full-cycle offensive security support for your product.

01

Web Application Penetration Testing

Full VAPT of web apps — OWASP Top 10, manual testing, real exploit proof-of-concepts, actionable reports.

▸ HOVER / TAP

// deliverables

OWASP Top 10Manual TestingPoC Reports
02

Bug Bounty Hunting

Continuous security testing on live targets — 150+ valid bugs reported on HackerOne, Bugcrowd, YesWeHack.

▸ HOVER / TAP

// track record

150+ Valid BugsHackerOneYesWeHack
03

Access Control & IDOR Assessment

Deep-dive into authorization logic — IDOR, RBAC bypass, privilege escalation across roles & workflows.

▸ HOVER / TAP

// depth areas

IDORRBAC BypassPrivEsc
04

API Security Testing

REST & GraphQL API assessment — broken object level authorization, mass assignment, injection, auth flaws.

▸ HOVER / TAP

// api coverage

RESTGraphQLBOLAMass Assignment
05

Business Logic Review

Manual review of critical flows — payment, HR systems, role-based workflows where scanners always fail.

▸ HOVER / TAP

// critical flows

PaymentHR SystemsRole Workflows
06

Security Reporting & Remediation Support

Clear, developer-friendly vulnerability reports with severity ratings, reproduction steps & fix suggestions.

▸ HOVER / TAP

// what you get

Severity RatingsRepro StepsFix Suggestions
ping me → response time: instant

Let's connect

Got a security project or a target to test?

Whether you need a web app penetration test, an access control assessment, or just want to talk bug bounty — my inbox is always open.