Statistics and recognitions from various cybersecurity platforms and competitions.
About me
Graduated in Telecommunication Technologies Engineering from the University of Seville.
Cybersecurity Specialist at Wellness Tech / IRIS Sentinel.
Speaker at the SecAdmin 2019 conference.
Finalist CTF Team Spain ECSC 2022 - INCIBE.
Finalist CTF SecAdmin 2022.
Pentester at Telefonica.
I do bug bounty part-time.
Pentesting - HackTheBox
Statistics
Name:
j0tt4
Country:
Spain
Users:
25
Roots:
23
Users 🩸:
0
Roots 🩸:
0
Points:
16
Rank:
Hacker (3/7)
Hall of Fame:
842
Challenges
Reversing
Crypto
Pwn
Web
Misc
Forensics
Mobile
OSINT
Hardware
GamePwn
Blockchain
Pentesting - PortSwigger
Learning Paths
Server-side vulnerabilities
SQL injection
API testing
Web LLM attacks
Clickjacking
Vulnerability labs
Apprentice
Practitioner
Expert
Categories
SQL Injection
XSS
CSRF
Clickjacking
DOM-based
CORS
XXE
SSRF
HTTP Request Smuggling
Command Injection
SSTI
Path Traversal
Access Control
Authentication
WebSockets
WCP
Insecure Deserialization
Information Disclosure
Business Logic
Host Header
OAuth
File Upload
JWT
Essential Skills
Prototype Pollution
GraphQL
Race Conditions
NoSQL Injection
API Testing
LLM
WCD
Bug Bounty - HackerOne
Badges
Bounty Hunter
June 16, 2023
First bounty received
Bounty Hunter
November 7, 2024
Ten bounties received
TrailBlazer
August 3, 2023
Was the first of multiple reporters to report a vulnerability
Insecticide
August 3, 2023
First report closed as resolved
Publish or Perish
August 14, 2023
Publicly disclosed a report
Good Samaritan
October 6, 2023
Resolved a report with a team that doesnt pay bounties
Diversity
October 18, 2024
Reported bugs to 5 different teams
Streaker
July 3, 2024
Two reports in a row were closed as resolved
A1: Injection
August 3, 2023
Reported a valid Injection vulnerability
A3: Sensitive Data Exposure
June 20, 2024
Reported a valid Sensitive Data Exposure vulnerability
A5: Broken Access Control
December 3, 2024
Reported a valid Broken Access Control vulnerability
A7: Cross-Site Scripting (XSS)
July 3, 2024
Reported a valid Cross-Site Scripting (XSS) vulnerability
CTF
CERTS