Skip to content
View odaysec's full-sized avatar
🖤
Loved secure code
🖤
Loved secure code

Block or report odaysec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 250 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
odaysec/README.md

Profile Views

Nominate me as a GitHub Star Support My Nomination
If you believe in my contributions to cybersecurity and open source,
please consider nominating me as a GitHub Star Nominate me here


Advanced GitHub Stats for odaysec

Advanced LeetCode Stats for odaysec

Dynamic Typing Animation





  • Name: アンドリー・アンドリ

  • Residing in: East of Java, Khuvukiland

  • Field of Study: Computer Science

  • Proficient in: GNU/Linux and FreeBSD

  • Skilled in: JavaScript, TypeScript, PHP, Go, and Python

  • Highly experienced with: Docker, Cloudflare, Vercel, and CI/CD

  • Languages: Bahasa, Bahasa Melayu, English, and 日本語





As an independent security researcher under Google’s Vulnerability Reward Program (VRP), I contributed to strengthening the security of Google products and services through responsible disclosure of previously unknown vulnerabilities.

Key Achievements:

  • Discovered and reported multiple vulnerabilities in Google systems
  • Earned 5 official security awards (including secret-level recognitions such as Tiger, Pig, Rabbit, Rat)
  • Active contributor since July 2021
  • Recognized for the first valid report within the first month of joining

Acknowledged by the Microsoft Security Response Center (MSRC) for reporting a vulnerability that impacted Microsoft Online Services.

  • Officially published on May 31, 2025
  • Listed among recognized MSRC security researchers

I have been an active security researcher on the HackerOne platform since 2018, contributing to both public and private programs across diverse industries.Over the years, I’ve managed multiple accounts (each tied to different private programs) to avoid overlap and ensure focus on specific engagements.

Accounts & Highlights:

  • Deb0con — Created in 2018, active until 2019–2020

    • Recognized as a Top Researcher in the U.S. Department of Defense program
    • Achieved 3200+ reputation points from the Pentagon
    • Earned multiple acknowledgments for impactful reports
  • Hackeronanywhere — Second account focused on blockchain security research

    • Reported critical vulnerabilities in Cosmos Network and related ecosystems
    • Specialized in blockchain and decentralized infrastructure security
  • Odaysec — My current active account, created after duplicate account policy enforcement

    • Focused on large-scale projects and reporting critical vulnerabilities
    • Collaborated with programs for timely vulnerability remediation
    • Recognized as a Top 3 GitHub Expert Researcher for high & critical reports in GitHub programs

Research Focus on HackerOne:

  • Web application security
  • IoT Vulnerabilities
  • Blockchain vulnerabilities
  • Others

On the Bugcrowd platform, I reported critical vulnerabilities in two private programs. This account is now set to private, while I continue contributing as an independent researcher. Reported critical vulnerabilities across two programs. This account is now set to private while continuing active security research.



“People with evil intent can do evil things without lying. And not all liars are evil.” – Elaina                                                         contact : github@zerodaysec.org

Top Contributed Stats

Gambar 1
GitHub Sponsors - 0daysec

Pinned Loading

  1. path-crawler path-crawler Public

    Path Crawler is a simple CLI tool built with Node.js that scans a website asnd extracts all relative paths

    JavaScript 8 1

  2. NetWatch NetWatch Public

    Network Command Center Real-time network monitoring and security analysis and provides real-time network analysis, security monitoring, and infrastructure management capabilities.

    TypeScript 20 5

  3. Cybersec Cybersec Public

    Modern cybersecurity tools platform built with React and TypeScript. This provides a collection of essential security tools with a sleek, dark-themed interface designed for cybersecurity profession…

    TypeScript 21

  4. ptscanner ptscanner Public

    🦖 PTScanner is a powerful tool for detecting Path Traversal and Local File Inclusion (LFI) vulnerabilities. developed as part of the ApachSAL project, it has been fully ported to Node.js, featuring…

    JavaScript 10

  5. NewsCrap NewsCrap Public

    NewsCrap adalah alat scraping berita Google berbasis Command Line Interface (CLI) yang dirancang untuk riset, investigasi, dan pengumpulan data OSINT. Dengan fitur canggih seperti rotation proxy, s…

    Python 51 11

  6. SaaS-ZeroTraffic SaaS-ZeroTraffic Public

    SaaS Zero - Network Traffic Monitor Professional network traffic monitoring and security analysis platform

    TypeScript 50 8