• Файл

Дмитро

Фахівець з інформаційної безпеки

Місто:
Київ

Контактна інформація

Шукач вказав телефон та ел. пошту.

Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.

Завантажений файл

Версія для швидкого перегляду

Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.

PENETRATION TESTER

SHAMSHUR
WORK EXPERIENCE

DMYTRO Penetration Tester
H-X Technologies
Sep 2025 – Present
Performed penetration testing of web applications as part of the H-X
PERSONAL DATA: Technologies security team.
[відкрити контакти](див. вище в блоці «контактна інформація») Conducted security testing of production web applications for AIX, MURKA, and
Kyiv DTEK as part of authorized security assessment projects.

Identified and validated 30+ medium/high severity vulnerabilities, primarily in:
authentication and authorization logic
object-level access control (BOPLA / BOLA)
TOOLS AND TECHNOLOGIES:
business logic
BurpSuite
All findings were confirmed by the affected companies and addressed through
This is used for manual auth flow analysis and logic
coordinated remediation.
testing
Repeater
PUBLICATIONS
JWT editor TOTP
Python Authored a technical article examining practical weaknesses of TOTP-based
authentication in production systems. The analysis highlights architectural and
custom automation and test case
logic-level issues in real-world implementations, including flawed verification flows
generation beyond Burp capabilities
and state management, instead of theoretical cryptographic attacks.

Wireshark
for protocol-level inspection (TLS
handshake, token exchange)
FOCUS
cryptography
My primary focus areas include authentication and authorization mechanisms,
IDOR vulnerabilities, race conditions, asynchronous logic issues, and business
LANGUAGES logic flaws.

English B1-B2 API Security:
Authorization and object-level access control (BOPLA/BOLA)
Russian C2 Token handling and session lifecycle issues
Race conditions and async behavior in APIs
Ukrainian C1 Web cache poisoning
Web cache deception

Інші резюме цього кандидата

Схожі кандидати

Усі схожі кандидати


Порівняйте свої вимоги та зарплату з вакансіями інших підприємств: