#About Me

sifat.pr@kali: ~/about
sifat.pr@kali:~$

Education:
- Self-taught in:
  * Penetration Testing
  * Bug Bounty Hunting
  * Web Development
sifat.pr@kali:~$

As a Computer Science student specializing in cybersecurity, I've developed a passion for exploring the intersection of web development and security. My journey began with learning fundamental programming concepts and quickly evolved into a dedicated pursuit of ethical hacking and secure application development.

#Projects

sifat.pr@kali: ~/projects
$ ls -la ~/projects
sifat.pr@kali: ~/projects/view

Select a project file from the directory tree to view the contents.

SupplySync

A secure tracking system for supply chain management

ReactNode.jsMongoDB

SecureBank

Banking security analysis tool for penetration testing

PythonDjangoReact

VulnScanner

Automated web application vulnerability scanner

PythonFlask

#Bug Bounty Reports

sifat.pr@kali: ~/bug_bounty
$ cat bug_bounty_reports.log
CSRF in user settings
[2025-04-19]
Platform:HackerOne
Company:Social Media Platform
Severity:Medium
Bounty:$100
Discovered Cross-Site Request Forgery vulnerability in the user settings that could allow attackers to change victim account settings without their knowledge.
Resolved
DOM XSS in main dashboard
[2025-02-15]
Platform:HackerOne
Company:PrivateProgram-A
Severity:High
Bounty:$
Discovered DOM-based Cross-Site Scripting vulnerability in the main dashboard that allowed attackers to execute arbitrary JavaScript code in victim browsers.
Disclosed
Open Redirect on login page
[2025-03-22]
Platform:Bugcrowd
Company:E-Commerce Platform
Severity:Medium
Bounty:$
Found an open redirect vulnerability in the login flow that could be used to redirect users to malicious sites after authentication.
Disclosed
Exposed API Keys in client-side code
[2025-04-07]
Platform:Private Program
Company:FinTech Startup
Severity:Critical
Bounty:$
Identified exposed API keys with admin privileges in client-side JavaScript that could be extracted and used to access sensitive user data.
Disclosed
SQL Injection in search function
[2025-04-30]
Platform:Private Program
Company:Healthcare Provider
Severity:Critical
Bounty:$
Found SQL injection vulnerability in the patient search function that could allow unauthorized access to sensitive patient records and medical data.
Disclosed
$ cat overall_stats.txt

Total Bounties

$100

Vulnerabilities Found

8+

Total Bug Reports

5+

#Certifications & Achievements

sifat.pr@kali: ~/certifications
$ ls -la ./certificates/
Access Control Concepts

Access Control Concepts

Issuer: ISC2

Covers the fundamentals of access control methods and strategies.

Incident Response

Incident Response

Issuer: ISC2

Understanding the process and methods for effective incident response.

Network Security

Network Security

Issuer: ISC2

Principles and practices for securing network infrastructure.

Security Operations

Security Operations

Issuer: ISC2

Explores operational security processes and frameworks.

Security Principles

Security Principles

Issuer: ISC2

Foundational concepts in information security and risk management.

CSS

CSS

Issuer: HackerRank

Basic understanding and application of Cascading Style Sheets.

Frontend Developer (React)

Frontend Developer (React)

Issuer: HackerRank

Proficiency in React for frontend web development.

JavaScript (Basic)

JavaScript (Basic)

Issuer: HackerRank

Fundamental JavaScript programming knowledge.

JavaScript (Intermediate)

JavaScript (Intermediate)

Issuer: HackerRank

Intermediate level skills in JavaScript programming.

Pre-Assessment

Pre-Assessment

Issuer: ISC2

Initial assessment of cybersecurity knowledge and readiness.

Problem Solving (Basic)

Problem Solving (Basic)

Issuer: HackerRank

Covers basic algorithmic and logical problem-solving skills.

Problem Solving (Intermediate)

Problem Solving (Intermediate)

Issuer: HackerRank

Intermediate challenges in algorithmic thinking and coding.

Python (Basic)

Python (Basic)

Issuer: HackerRank

Basic Python programming certification.

ICIP

ICIP

Issuer: OPSWAT Academy

Introduction to Critical Infrastructure Protection.

SQL Injection

SQL Injection

Issuer: EC Council

Understanding SQL injection vulnerabilities and mitigation.

Type certifications --view in the terminal to browse certificates.

#Contact Me

sifat.pr@kali: ~/contact/form
$Enter your name:
$Enter your email:
$Enter your message:
sifat.pr@kali: ~/contact/links
$ cat contact_links.txt

$ echo "Built by sifat.pr"

[Last updated: 5/16/2025]

with Next.js, Tailwind CSS & Framer Motion

© 2025 Sifat Sarkar. All rights reserved.