G3kSec.

Security Researcher

// security researcher & bug hunter

Find. Report.
Secure.

Bug hunter finding and reporting vulnerabilities in web applications and APIs.

900+HackerOne Rep
18+Vulns Patched
7+Orgs Secured
1Writeups

// experience

Bug Bounty

I hunt vulnerabilities in web applications and APIs, disclosing them responsibly through public and private bug bounty programs. My focus is manual testing — access control flaws, business logic errors, and auth issues that scanners miss — backed by automated tools when it helps widen coverage.

~/hackerone/g3ksec

G3kSec
HackerOne

@g3ksec

Security Researcher

900+Reputation
17.50Impact
7.00Signal
View Full Profile

Hunting In

Mercado LibreLATAM AirlinesUPSBitwarden+Private Programs

// skills

Technical Skills

Web Assessment

Burp SuiteOWASP Top 10DevToolsNucleiSQLmapffuf

Reconnaissance

OSINTNmapSubfinderAmasshttpxShodanGoogle DorkingWappalyzer

Scripting & Review

PythonBashJavaScriptGitRegex

// research & disclosure

Writeups

Bug reports and research I've published.

// builds

Projects

Tools I've built.

~/hxhunt

HxHuntBug bounty tools built and maintained by G3kSec — shared identity, one ecosystem.
Since Jul 2026

HxHashFavicon

Favicon fingerprinting tool to extract Shodan/Fofa compatible MurmurHash3 signatures. Useful for asset discovery and mapping hidden attack surfaces.

Next.jsTypeScriptTailwind CSS v4OSINT

HxBugLetter

Self-curating archive of verified bug bounty writeups and research. A GitHub Actions bot fetches trusted sources daily, classifies each entry, and auto-commits it — content-as-code, no database.

Next.jsTypeScriptTailwind CSS v4Bug Bounty

HxBugLabs

Self-hosted, Docker-based labs for practicing bug bounty vulnerabilities and recon techniques. IDOR, XSS, SSRF, auth, and OSINT — each a real app with multiple objectives, nothing telegraphed in the UI.

Next.jsTypeScriptDockerBug Bounty

G3kSec|Luciano Griffa

GitHub

© 2026