rootpage.

Amir Zare.

Web security researcher & penetration tester

Systems don’t fail by accident, they fail when someone understands them better than their creators ever did.

Available for security work

#Capabilities

what I do

Web Application Pentesting

Blackbox and WhiteBox assessments. OWASP Top 10, business logic flaws, API security, authentication bypass, and chained exploits.

xss idor ssti ssrf auth

Mobile & Android Security

Android application testing, decompilation and repackaging, insecure storage, rooted device bypasses, and API-level authorization review.

android mobile smali frida

Incident Response & Disaster Management

Post-breach analysis, root cause investigation, containment strategy, and remediation planning. Incident drills and tabletop exercises.

incident forensics recovery drills

#Platforms

where I publish work

Writeups

Technical deep-dives on vulnerabilities, bug bounty findings, and pentest research.

Webapp Pentest Catalog

Categorized reference of vulnerabilities, exploitation techniques, and detection methods.

Challenges

Security challenges, CTF writeups, and hands-on labs for the community.