Student Security Portfolio

Web Pentesting, Agent Security, and Vulnerability Research.

Cybersecurity student focused on web exploitation, access-control flaws, agent offense and defense, and responsible disclosure. This preview intentionally redacts target details, payloads, endpoints, and personal identifiers.

Focus Web AppSec
Record 9 campus reports
Current USYD MCompSci

Profile

Short, technical, verifiable

I am a security-focused computing student with hands-on work across university systems, especially identity flows, student-service platforms, and legacy web applications.

The public version should emphasize classes of findings and reporting discipline rather than raw exploit detail. That makes the page stronger and safer at the same time.

Current direction: web pentesting, agent offense and defense, vulnerability research, traditional visual algorithms such as KCF, introductory open-source research, and turning private reports into clean public case studies.

Selected Research

Sanitized highlights
Identity and Verification Flows Auth logic

Reported weaknesses in account and verification flows, including abusive verification paths and exposure in account-related records.

Student-Service Access Control IDOR / authz

Reported access-control issues affecting leave-management and booking systems, where personal or workflow data could be returned across users.

Legacy Campus Web Apps XSS / exposure

Documented XSS-class issues, guest-access mistakes, and file-exposure problems in older campus platforms. Public copy stays intentionally high level.

Education

2020 to now
University of Sydney Current

Master of Computer Science.

Qihang Computer Society, Dalian Maritime University 2020-2024

Head of the Network Security Department.

Graduate Disclosure Note Redacted

During graduate study, reported a vulnerability affecting a university service platform. Technical details remain private in this preview.

Recognition

What to publish
Responsible Disclosure Record 2021-2024

The material you provided supports a public claim of nine responsibly reported findings across SSO, library, leave-management, OA, and campus web systems.

Institutional Recognition Verified

One document is an institutional certificate recognizing vulnerability reporting and remediation support.

Privacy-Safe Public Version Required

Avoid real student IDs, target URLs, payloads, screenshots, report contacts, and any direct reproduction steps.