Security researcher and penetration tester specializing in browser security, mobile application vulnerabilities, UXSS, origin spoofing, and download security. Active bug bounty hunter across HackerOne, Bugcrowd, HackenProof, and Meta.
$ whoami
Umar Zaid Ridwan
Subang, Jawa Barat, Indonesia
$ cat top_findings.txt
$$$$ · Flow Wallet UXSS
$$$$ · Facebook Address Bar Spoofing
$$$$ · Facebook Address Bar Spoofing (2)
$$$$ · Arc Browser File Injection
$$$ · 3CX Stored HTML to XSS
$ cat platforms.txt
HackerOne · Bugcrowd · HackenProof · Meta
_
Stored HTML to XSS vulnerability allowing persistent script injection.
Missing email verification vulnerability in authentication flow.
Abuse of showDirectoryPicker() API leading to malicious file injection into user filesystem.
UXSS vulnerability in Android application WebView allowing cross-origin script execution.
APK spoofing vulnerability in download menu enabling malicious app installation.
External protocol prompt origin confusion allowing attacker to impersonate trusted apps.
Address bar UI bypass enabling login form spoofing within the browser.
Incognito mode external protocol origin spoofing bypass.
Prompt origin spoofing via cross-origin iframe manipulation.
Download security UI bypass leading to origin spoofing in download confirmation dialog.
Universal Cross-Site Scripting (UXSS) vulnerability in Android in-app browser via javascript: URI sandbox bypass, enabling credential phishing inside the official wallet application.
Address bar spoofing vulnerability leading to credential theft via timing attack in iOS in-app browser.
Facebook iOS in-app browser spoofing vulnerability allowing attacker-controlled content to appear under trusted domains.
RTLO (Right-to-Left Override) spoofing vulnerability on macOS enabling filename deception.
Link preview spoofing via long URL encoding hiding true destination domain from users.
Web application and mobile application penetration testing. Vulnerability assessment across web platforms, APIs, and browser environments.
Security research in major browsers including Arc, Opera, Samsung Browser, Orion, And Other. Specializing in address bar spoofing and UI deception.
Universal XSS and stored XSS research across web applications, mobile browsers, and crypto wallet WebViews. javascript: URI sandbox bypass techniques.
Origin verification bypass in browsers, in-app WebViews, and crypto wallets. Cross-origin prompt spoofing via iframe manipulation, protocol confusion, and RTL characters.
Dangerous file download behaviors including .url extension exploitation, APK spoofing, filename manipulation, and arbitrary local file read via OS-level resolution bypass.
Right-to-Left Override (RTLO) and RTL Unicode character abuse for filename spoofing, browser address bar manipulation, and PWA install prompt deception.