Available for private programs & engagements
Yousef Muhammedelkhir

Security Researcher uncovering critical vulnerabilities in web apps, APIs & cloud infrastructure. Specializing in multi-bug exploitation chains that turn overlooked issues into account takeovers.

Web App Security API Exploitation Cloud Security Bug Chaining Account Takeover HackerOne Vuln Research
forcedrofes ~ research
โฏ cat profile.json
{
  "researcher": "Yousef Muhammedelkhir",
  "handle": "forcedrofes",
  "specialty": "API Security & Bug Chaining",
  "max_severity": "Critical"
}

โฏ cat latest_writeup.txt
ยป "When One Bug Isn't Enough"
   Finding a Full House of Vulnerabilities
   medium.com/@rofes1337 ยท Jun 2025
Critical
Severity Findings
Bounty Rewarded
ATO
Account Takeover Chains
Disclosed
Multi
Bug Chain Reports
Published
H1
HackerOne Active
Verified
about me

Who I Am

Security researcher turning complex attack surfaces into actionable critical findings.

I'm Yousef Muhammedelkhir, a security researcher and bug bounty hunter based in . I focus on uncovering high-impact vulnerabilities in web applications, APIs, and cloud infrastructure with real business impact.

My approach goes beyond surface-level testing โ€” I look for vulnerability chains that escalate into critical outcomes like full account takeover, unauthorized data access, and privilege escalation. This methodology has led to critical-severity findings across public and private programs on HackerOne.

I actively share knowledge through detailed writeups on Medium and engage with the security community on X, contributing techniques and methodologies back to the space that helped me grow.

๐ŸŽฏ Core Specialty

API security, broken access control, and chaining bugs into account takeover

โ˜๏ธ Cloud Research

Firebase misconfigurations, GCP API exposure, cloud storage security research

โœ๏ธ Knowledge Sharing

Publishing technical writeups on Medium (@rofes1337) from real findings

๐Ÿ”ง Tool Building

Developing custom security automation and recon tooling to scale discovery

high-impact findings

Notable Vulnerabilities

Selected findings demonstrating real-world security impact across programs.

๐Ÿ”ด Critical Severity

Critical Finding โ€” Private Program

Identified and responsibly disclosed a critical-severity vulnerability on a private HackerOne program with significant impact on core business functionality, resulting in a bounty award.

HackerOnePrivate ProgramBounty Awarded
๐ŸŸ  High ยท Account Takeover

Full ATO via Multi-Bug Chain

Chained multiple individually low-impact vulnerabilities to achieve complete account takeover. Documented in a published writeup โ€” demonstrating the power of creative bug chaining.

Bug ChainingATOWritten Up
๐ŸŸ  High ยท Access Control

Broken Access Control + IDOR

Discovered broken access control and IDOR vulnerabilities enabling unauthorized access to sensitive user data and privileged application functionality across multiple user accounts.

IDORBACData Exposure
๐ŸŸ  High ยท API Security

API Authentication Bypass

Identified missing authorization checks in API endpoints allowing unauthenticated or low-privilege users to access privileged functionality and sensitive cross-account data.

REST APIAuth BypassOAuth
๐Ÿ”ด Critical ยท Cloud

Cloud Infrastructure Misconfiguration

Uncovered critical cloud misconfigurations exposing sensitive backend data and internal resources โ€” including exposed Firebase databases and publicly readable storage buckets.

FirebaseGCPMisconfiguration
expertise

Core Skills

Areas of deep focus developed through real-world research and bug bounty hunting.

๐ŸŒ Web App Security

Broken Access ControlIDORAuth BypassXSSSQLiSSRFMass AssignmentBusiness Logic

๐Ÿ”Œ API Security

REST API TestingGraphQLOAuth 2.0JWT AttacksAccount TakeoverEndpoint DiscoverySwagger/OpenAPI

โ˜๏ธ Cloud Security

Firebase MisconfigGCP APIsCloud StorageAPI Key ExposureIAM MisconfigBucket Exposure

๐Ÿ” Vuln Research

JS Source AnalysisEndpoint DiscoveryOSINTAPK AnalysisSource Map AnalysisParameter Hunting

๐Ÿ› ๏ธ Development

PythonJavaScriptGoBashCustom Tool DevSecurity Automation

๐Ÿ“ Research & Reporting

Technical WriteupsBug ChainingPoC DevelopmentResponsible DisclosureImpact Assessment
research & writing

Security Writeups

Sharing knowledge from real findings to help the security community grow.

Featured Article ยท Medium ยท @rofes1337 ยท June 2025

"When One Bug Isn't Enough: Finding a Full House of Vulnerabilities"

A deep-dive into how a single target can yield a full suite of chained vulnerabilities. Walks through recon, initial discovery, and how multiple individually minor bugs were chained to achieve significant real-world impact โ€” showing why bug chaining is the most underrated skill in bug bounty.

Bug Chaining Account Takeover Web App Security Methodology Real-World Finding
โ†’
// Medium ยท @rofes1337

All Security Writeups

Full collection of vulnerability research, exploitation techniques, and bug bounty methodologies.

โ†’ Read on Medium
// HackerOne ยท forcedrofes

Disclosed Reports

Publicly disclosed vulnerability reports with technical details and proof-of-concept exploits.

โ†’ View on HackerOne
// X (Twitter) ยท @r0_fes

Security Tips & Research

Regular security insights, hunting tips, and research notes shared with the bug bounty community.

โ†’ Follow on X
credentials

Certifications

Industry-recognized certifications across red teaming, penetration testing, and application security.

Certified Red Team Analyst

CyberWarFare Labs

Issued Nov 2025 ยท ID: 69123b2d

Red TeamPenetration TestingActive Directory
โ†—

eCPPTv2 Certified Professional Penetration Tester

INE Security (eLearnSecurity)

Issued Aug 2023 ยท ID: 6315014

Penetration TestingNetwork SecurityWeb App
โ†—

Certified AppSec Practitioner

The SecOps Group (PentestingExams.com)

Issued Dec 2022 ยท ID: 6878766

Application SecurityOWASPSecure Code Review
โ†—

API Penetration Testing

APIsec University

Issued Aug 2023 ยท ID: eaf2a510

API SecurityREST TestingOWASP API Top 10
โ†—

Introduction to OWASP Top 10 Vulnerabilities

EC-Council

Issued Mar 2022

OWASP Top 10Web SecurityVulnerability Basics
connect

Get In Touch

Let's Work Together

Open to private program invitations, penetration testing engagements, security consulting, and research collaborations.