Bypassing Facial Verification (KYC) via Response Manipulation
Defeated a financial app's BVN/NIN face-match gate by rewriting a single API response — deep dive into the trust-boundary failure and the fix.
Read writeup →8
Writeups published
3
Certifications
3
Domains: web · mobile · API
Android
Core specialty
Defeated a financial app's BVN/NIN face-match gate by rewriting a single API response — deep dive into the trust-boundary failure and the fix.
Read writeup →Dismantled Android apps through RCE exploits — command injection in CyclicScanner, from discovery to impact.
Read writeup →Dismantled Android apps through RCE exploits — command injection in CyclicScanner, from discovery to impact.
Read writeup →CMPen Android
The SecOps Group
API Security
APISec University
Certified in Cybersecurity
ISC2
Credly Verified
Credly
Web Pentesting
Burp Suite Pro, Postman, sqlmap, ffuf, Nuclei
OWASP Top 10 coverage, authentication bypasses, and business-logic flaws across modern web stacks.
Mobile Pentesting
Frida, Objection, Jadx, MobSF, Apktool
Android assessments: reverse engineering, insecure storage, intents, and weak crypto in production apps.
API & Cloud
REST, GraphQL, AWS, Azure, GitHub Actions
API abuse, BOLA/BFLA patterns, and CI/CD misconfigurations that leak secrets or widen blast radius.
Open to penetration testing roles, engagements, and security research collaborations. The fastest way to reach me is email.
Recruiters: CV and verified credentials are on LinkedIn. A one-line brief of scope and timeline gets a faster reply.