Web Application Security • Penetration Testing
HI, I'M
Breaking apps, brewing coffee, and chasing vulnerabilities.
Want to know more about me?
// About
I'm a Computer Engineering graduate from Kantipur Engineering College building my path in cybersecurity and penetration testing. My current focus is practical web security: understanding requests, authentication flows, SQL injection, rate limits, and the logic behind vulnerabilities.
I learn by testing, documenting, and repeating — from PortSwigger labs and Burp Suite work to personal security writeups and projects.
// Security Work
Focused on practical web application security and the fundamentals that turn a vulnerability into an understandable attack path.
Exploring UNION-based, error-based, and blind SQL injection techniques through hands-on labs and writeups.
Username enumeration, brute-force controls, 2FA bypass scenarios, and weaknesses in authentication logic.
Building a repeatable workflow: understand the application, intercept traffic, test assumptions, document the finding.
// Projects
Software, AI, and security learning projects that show how I approach technical problems.
Completed practical labs covering SQL injection, authentication, and HTTP request manipulation; documented methodologies, observations, and recommended mitigations.
Built a web-based fundus-image analysis system using an Attention U-Net segmentation stage and a Vision Transformer classification head.
Built an AI-powered recommendation system using vector similarity search for personalized recommendations.
Published work on hybrid deep learning for glaucoma detection, achieving 89.77% classification accuracy on SMDG-19.
// Skills