Skip to content
View xivks's full-sized avatar
🎯
Focusing
🎯
Focusing
  • Chennai

Block or report xivks

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
xivks/README.md

πŸ‘‹ Hi, I'm Varun (xivks)

🧠 Security Researcher | Senior IT Administrator | SRD Applicant

I specialize in behavioral vulnerability research (SSRF, Webhook, Fetcher, and CORS behavior) and secure infrastructure management (Windows/Linux/Azure).

Currently:

  • 🧩 Participating in Bugcrowd programs – Atlassian & Glean (responsible disclosure)
  • 🍏 Apple Security Research Device (SRD) applicant – iOS Private Cloud Compute and Lockdown Mode focus
  • πŸ”¬ Building small-scale PoCs, automation scripts, and safe fuzzing setups for SaaS security
  • πŸ’‘ Strong advocate of ethical testing, coordinated disclosure, and real-world defense improvement

🧰 Tech & Research Stack

  • Security: SSRF, CORS, Redirects, Fetch Analysis, XSS, API Hardening
  • Cloud & Infra: Azure, Hyper-V, Active Directory, Linux System Admin
  • Scripting: PowerShell, Bash, Python, Node.js
  • Tools: Burp Suite, curl, Wireshark, Postman, nmap, Zaproxy

πŸ“‚ Featured Repositories

Repo Description
atlassian-behavioral-ssrf-poc Safe demo showing how webhook fetchers respond differently across address spaces (RFC1918, metadata, external).
glean-webhook-probe-lab Test harness replicating safe outbound fetch and error handling behaviors, used for vendor coordination.
srd-prep-tools Scripts and environment setup used for iOS behavioral analysis and logging.
infra-scripts-automation PowerShell and Bash automation for server configuration, patch management, and diagnostics.

🧩 Contact


β€œExploring vulnerabilities to strengthen security β€” one responsible disclosure at a time.” πŸ”

Pinned Loading

  1. xivks-glean-webhook-research xivks-glean-webhook-research Public

    Python

  2. atlassian-behavioral-ssrf-poc atlassian-behavioral-ssrf-poc Public

  3. bugbounty-reports bugbounty-reports Public

  4. ios-fuzzing-harness ios-fuzzing-harness Public

    Python

  5. ios-security-research-notes ios-security-research-notes Public

    Structured notes & methodology for iOS security research