Penetration Tester · Security Researcher · Bug Bounty Hunter

Umar Zaid
Ridwan

Security researcher and penetration tester specializing in browser security, mobile application vulnerabilities, UXSS, origin spoofing, and download security. Active bug bounty hunter across HackerOne, Bugcrowd, HackenProof, and Meta.

Browser Security UXSS Origin Spoofing Mobile Security Pentest
umar@security ~

$ whoami

Umar Zaid Ridwan

Subang, Jawa Barat, Indonesia

$ cat top_findings.txt

$$$$ · Flow Wallet UXSS

$$$$ · Facebook Address Bar Spoofing

$$$$ · Facebook Address Bar Spoofing (2)

$$$$ · Arc Browser File Injection

$$$ · 3CX Stored HTML to XSS

$ cat platforms.txt

HackerOne · Bugcrowd · HackenProof · Meta

STATISTICS

Security Statistics

0
Valid Reports
$$$$$
Total Bounty Earned
0
CVEs Assigned
0
Bug Bounty Programs
EXPERIENCE

Bug Bounty Reports

HackerOne
3CX $$$

Stored HTML to XSS vulnerability allowing persistent script injection.

XSSStored
Chainlink $$$

Missing email verification vulnerability in authentication flow.

AuthBypass
Magic Eden $$$

UXSS vulnerability in Android application WebView allowing cross-origin script execution.

UXSSAndroidWebView
Bugcrowd
Opera Beta Android $$$

APK spoofing vulnerability in download menu enabling malicious app installation.

AndroidDownloadSpoofing
Opera Mini Android $$$

External protocol prompt origin confusion allowing attacker to impersonate trusted apps.

Origin ConfusionProtocol
Opera GX Android $$$

Address bar UI bypass enabling login form spoofing within the browser.

Address BarUI Spoof
Opera Android $$$

Incognito mode external protocol origin spoofing bypass.

IncognitoOrigin Spoof
Opera Android $$$

Prompt origin spoofing via cross-origin iframe manipulation.

iframeUXSSOrigin Spoof
Opera Android $$$

Download security UI bypass leading to origin spoofing in download confirmation dialog.

DownloadUI Bypass
HackenProof
Other Programs
Orion Browser $$$$

RTLO (Right-to-Left Override) spoofing vulnerability on macOS enabling filename deception.

RTLOmacOSUnicode
Orion Browser $$

Link preview spoofing via long URL encoding hiding true destination domain from users.

Link PreviewURL Spoof
RESEARCH

Areas of Expertise

ACTIVE
🧪

Penetration Testing

Web application and mobile application penetration testing. Vulnerability assessment across web platforms, APIs, and browser environments.

Web AppSecMobileAPIBurp Suite
MEDIUM
🌐

Browser Security Research

Security research in major browsers including Arc, Opera, Samsung Browser, Orion, And Other. Specializing in address bar spoofing and UI deception.

ArcOperaOther
HIGH
⚡

Cross-Site Scripting (XSS & UXSS)

Universal XSS and stored XSS research across web applications, mobile browsers, and crypto wallet WebViews. javascript: URI sandbox bypass techniques.

UXSSStored XSSWebViewSandbox
MEDIUM
🔗

Origin Spoofing

Origin verification bypass in browsers, in-app WebViews, and crypto wallets. Cross-origin prompt spoofing via iframe manipulation, protocol confusion, and RTL characters.

iframeRTLProtocolWallet
MEDIUM
📥

Download Security

Dangerous file download behaviors including .url extension exploitation, APK spoofing, filename manipulation, and arbitrary local file read via OS-level resolution bypass.

ChromeAPK SpoofFile ReadCVE
LOW
🔤

RTLO / Unicode Attacks

Right-to-Left Override (RTLO) and RTL Unicode character abuse for filename spoofing, browser address bar manipulation, and PWA install prompt deception.

RTLORTL/LTRPWAPunycode
CONTACT

Get In Touch

Open to security research collaborations, responsible disclosure discussions, and penetration testing engagements. Based in Subang, Jawa Barat, Indonesia.