// Security Researcher

Prayers Khristi

Hey, I'm Prayers. I'm a 21-year-old security researcher. I've been awarded multiple rewards and appreciation letters in bug bounties for securing critical infrastructure and the open web.

Security Research

Dec 2025

Doverunner — Account Takeover

0-Click Account Takeover via Punycode Email Manipulation in Password Reset Function

Resolved
Mar 2026

Microsoft — Infinite 'reaction' bug in comments

An infinite reaction bug was identified on MSN (Microsoft News), where users can repeatedly trigger the “reaction” functionality on comments without proper server-side validation or rate limiting. This flaw could allow manipulation of engagement metrics and potential abuse of the platform’s interaction system.

Resolved
April 2025

Sony — Reflected Cross-Site Scripting (CVE-2025-0133)

A Reflected Cross-Site Scripting (XSS) vulnerability (CVE-2025-0133) was identified on a Sony web application, where unsanitized user input is reflected in the server’s response without proper encoding. This flaw allows an attacker to inject malicious scripts that execute in a victim’s browser, potentially leading to session hijacking or data theft.

Resolved
May 2025

ASN Bank — Sensitive Financial Transaction Data Exposure

Found leaked cached API responses contain confidential financial information including transaction details, customer payment data, merchant banking details, and authorization credentials.

Resolved
May 2025

AMD — Access to backend infrastructure functionality to unauthenticated users

An improper access control vulnerability was identified in AMD, where unauthenticated users were able to access backend infrastructure functionality due to missing authorization checks. This issue could allow attackers to interact with internal services, potentially leading to data exposure or unauthorized actions.

Resolved
Jan 2026

Criminal IP — Exposed Twitter API Credentials

An exposed API credentials vulnerability was identified in Criminal IP, where sensitive Twitter (X) API keys were publicly accessible due to improper security controls. This issue could allow unauthorized access to the associated account, enabling actions such as data retrieval, posting, or account manipulation.

Resolved
Mar 2026

AbsorbLMS — Leaked AWS, Firebase & Oauth Credentials

Found leaked credentials which allowed read and write operation in the internal environment.

Resolved
June 2025

Impact Guru — Unauthenticated access to donor PII & thousands of directly downloadable payment receipts

Found leaked cached API responses contain confidential financial information including transaction details, customer payment data, merchant banking details, and authorization credentials.

Resolved
Nov 2025

Phemex — Authentication Bypass via Web Archive Access

Discovered restricted API endpoints returning 403 Forbidden responses can be accessed through Wayback Machine. This authentication bypass allows access to potentially sensitive API data that should be properly authenticated and authorized.

Resolved
April 2026

TVH — env.js file exposed in public

An information disclosure vulnerability was identified in TVH, where a publicly accessible env.js file exposed sensitive configuration details such as API endpoints or keys. This exposure could allow attackers to gather internal information and potentially exploit related services.

Resolved

Tech Stack

Automation & Scripting

Building custom scanners and automation tooling

Python Bash Go Node.js

Security Operations

Network analysis, interception, and reverse engineering

Burp Suite Wireshark Nmap Caido

Platforms

Where I deploy code and engage with the community

GitHub HackerOne AWS Linux

Projects

FinderX

Soon - Open Sourcing

FinderX – Go-Based JavaScript Asset Discovery & Secret Hunting Pipeline Automated subdomain enumeration, JS extraction, and sensitive data detection for authorized security testing.

#Secret Finder ##Awesome Scanner #Security

OriginFinder

Open Source

OriginFinder is a multi-source reconnaissance tool that uncovers real origin IPs behind CDNs using intelligence aggregation, confidence scoring, and active verification.

#Awesome Scanner #IP Detection #Security

SubTakerX

Open Source

SubTakerX is a high-performance Go CLI tool for detecting subdomain takeover vulnerabilities using DNS analysis, fingerprinting, and automated HTTP probing.

#Awesome Scanner #Takeover Detection #Security

ZerOn

ZerOn is an AI-powered automated penetration testing platform that leverages LLM reasoning to perform intelligent reconnaissance, vulnerability detection, and professional security reporting.

#Awesome Scanner #Vulnerability Detection #Security

ZerOn

Zybl is the next-gen Sybil-resistance layer for Web3. Real people. Real proofs. Real revenue.

#Blockchain #Web3 #Security

AppSec

Open Source

AppSec is a full-stack application security system that combines multi-factor authentication, real-time intruder detection, and alerting to protect apps from unauthorized access.

#Application Security #Secured Application
#Security