Research Capabilities Projects About Contact
AVAILABLE FOR RESEARCH & COLLABORATION

RAJ
HRIDOY

Programmer & Security Researcher — based in Sirajganj, Bangladesh

I study how software fails — where networks, browsers, and the applications built on top of them make assumptions that don't hold — and I build small tools that put that research to use.

BaseSirajganj, BD
PathSelf-taught
FocusSecurity & Code
Status● Active
01 / FOCUS

Where the research goes

Three threads run through everything here — writing software, studying how systems get misused, and practicing offense in controlled, legal environments.

01ProgrammingScripts, small tools, and full projects — mostly JavaScript and Python — built to automate the boring parts and understand the software I depend on.
02Security ResearchStudying how networks, browsers, and web applications get misconfigured — and what it actually takes to lock them down properly.
03Ethical HackingPracticing offensive techniques in safe, legal environments — learning to think like an attacker so I can build things that hold up against one.
02 / RESEARCH

Independent vulnerability research

Security testing and responsible disclosure through public vulnerability disclosure programs, tracked on HackerOne.

HackerOne@rajhridoy404
U.S. Department of Defense · Vulnerability Disclosure Program
Status: Resolved

Security Contributions to the U.S. Department of Defense

Independent vulnerability research and responsible disclosure through the DoD's public Vulnerability Disclosure Program on HackerOne — reported directly to the VDP team, validated, and resolved.

03 / CAPABILITIES

What I actually work with

ENGINEERING

Programming

JavaScript, Python, and Bash — building tools, automating workflows, and reading other people's code closely enough to understand its assumptions.

NETWORKING

Systems & Protocols

HTTP, TCP/IP, and DNS fundamentals — how requests actually travel, and where that path can be observed, redirected, or abused.

RESEARCH

Security Practice

Reconnaissance, enumeration, and controlled testing against deliberately vulnerable environments — the discipline before the exploit.

04 / PROJECTS

Selected work

Three projects, each built to go deeper into a specific area — privacy, browser behavior, and interactive systems.

Privacy Engineering

VaultChat

A privacy-focused peer-to-peer messaging platform built around temporary, encrypted sessions — no permanent message storage, no server-side history.

WebRTCJavaScriptAES-256-GCMSecurity Research
View project
Security Research

Phantom

A browser intelligence and privacy analysis platform exploring fingerprinting, browser APIs, and exactly how much a site can learn about a visitor without asking.

JavaScriptBrowser APIsPrivacy Engineering
View project
Interactive Systems

Signal Graph

An experimental interactive visualization system exploring data flow and digital signals through animated node relationships — currently in development.

Next.jsTypeScriptThree.jsGSAP
In development — no public build yet
05 / ABOUT
I like taking systems apart to see how they're put together — then putting them back together a little more secure.
Profile

Curious about how the web works under the hood, and how that work can be undone. Most of my time goes into networking fundamentals, scripting, and studying attacker techniques.

Education

Dhangara High School for the fundamentals — everything past that, in programming and security, I'm teaching myself one concept at a time.

Approach

Read, break, rebuild, repeat. I learn best by poking at something until it does something unexpected, then figuring out exactly why.

06 / METHOD

How I approach a system

01

Understand

Map the architecture — what talks to what, and where trust is assumed rather than enforced.

02

Test

Challenge those assumptions directly, in a controlled, legal environment.

03

Validate

Reproduce the behavior reliably before drawing any conclusions from it.

04

Document

Write it down clearly enough that someone else could follow the same reasoning.

07 / CONTACT

Let's talk.

For code, security research, or just to say hello — I'm reachable across a few places.

FacebookRaj Hridoy
Instagram@wzz_hridoy