Bangkit portrait

FIELD LOG — 0xnhsec

Bangkit Eldhianpranata Pengestu

Independent Web Application Security Researcher

Self-taught since 20 Apr 2025. Loving in Research and couriousiting in Learning.

"Lost in the layers of abstraction, where the patterns define reality and the filter dictates what survives." - 0xnhsec

Security Researcher Ex Software Engineer
RCE in cookie PoC JWT XSS PoC Portswigger Labs PoC Race Condition PoC
CASM banner JXSS banner Basic IDOR PoC Fastfetch custom Pecut AI Pecut AI first BLR me

CASE—001

jxs in dev

Passive JS capture & analysis pipeline. mitmproxy → js-beautify → LinkFinder → mantra → SQLite → React Flow. Next: AI-driven sink/source analysis to replace static pattern matching.

PythonFastAPI

CASE—002

CASM in dev

Concentrated Attack Surface Methodology — strategic framework for web exploitation & bug bounty hunting. Read methodology

FrameworkOODA

CASE—003

nhsec-waf

WAF blind spot research tool with XSS mutation engine, canary injection, and blind XSS tracking via ngrok.

FastAPIOWASP CRS v4

CASE—004

breachme

Intentionally vulnerable C2C marketplace lab. Phased roadmap: XSS, BAC, IDOR, Business Logic, File Upload, SSRF, XXE.

PHP 8.1Docker

HUB—01

PortSwigger Academy

Lab-by-lab breakdown across SQLi, XSS, BAC, JWT, OAuth, Auth, DOM, Race Conditions, and more — grouped by vulnerability class.

Web Security120+ labs

HUB—02

Meta4sec — CTF2026

13 challenges solved: pwn, reverse engineering, crypto, ICS/OT, and misc/blockchain — full PoC walkthroughs.

pwnreversecrypto