I'm Evan Ricafort, A web application security researcher/bug hunter from the Philippines interested in web application security testing. I was born in the Province of Ipil, Zamboanga Sibugay, Philippines. Studied Computer Networking at Ateneo De Zamboanga University. Currently working as a Security Researcher at Invalid Web Security, A startup cybersecurity firm based in the Philippines. Since early of 2013 I've been an active member of the bug bounty community reporting multiple different kinds of security vulnerabilities on popular websites such as Microsoft, Google, Twitter and etc. Aside from bug bounty, I also work as a Penetration Tester doing Vulnerability Assessment and Penetration Testing (VAPT) for our clients with my team at Invalid Web Security and AegisOne Cyberdefense Corporation. I spend my off-hours playing video games, riding bike and other outdoor activities. Currently looking for infosec job. If you want to hire me or invite me on your bug bounty program, just hit me up through my email or dm me on twitter I'mma try my best to give you quality research.
Visayan
Tagalog
English
Web Application Security
Music Production
Mobile Photography
Web Application Security Researcher at Finalify Ltd., - https://www.spectrocoin.com (February 2019 - March 2019)
Web Application Security Researcher at Invalid Web Security - https://www.invalidwebsecurity.info (October 2013 - present)
Web Application Security Researcher at AegisOne Cyberdefense Corporation - https://aegisonesecure.com (June 2019 - present)
Cyber Security and Privacy Foundation Pte Ltd - Certified Whitehat Hacker v1 (CWHH) - Certificate ID. UC-SD45SNW8
PentesterLab - PentesterLab's Introduction Badge - Badge ID. PTLN9552
PentesterLab - PentesterLab's Essential Badge - Badge ID. PTLE2521
Featured in SecurityWeek (Google Nest Findings)
Security Week — http://www.securityweek.com/vulnerabilities-found-website-google-owned-nest
Featured in Pinoy Hack News (XSS Vulnerabilities)
Pinoy Hack News — http://www.pinoyhacknews.com/xss-in-natgeo-playstation-and-barack-obama
Featured in CKEditor (4.4.6 Security Patch Released)
Featured in Blesta Security Advisory (XSS Vulnerabilities)
Blest Security Advisory (Core-931) — http://www.blesta.com/2013/12/20/security-advisory-cross-site-scripting-vulnerabilities-2/
Featured in MIT Technology Review
Life as a bug bounty hunter: a struggle every day, just to get paid — https://www.technologyreview.com/s/611896/life-as-a-bug-bounty-hunter/
Featured in Peerio (Security Patch Released)
Security Patch Released — https://github.com/PeerioTechnologies/peerio-desktop/releases/tag/v2.98.7
Featured in Synack Red Team Calendars (2018 & 2019)
The Places You Go with the Synack Red Team (2018 SRT Calendar)
Hacker-to-Hacker (2019 SRT Calendar)
Featured in Wordpress (WordPress 5.2.4 and 5.4.1 Security Patch Release)
WordPress 5.2.4 - https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/
WordPress 5.4.1 - https://wordpress.org/news/2020/04/wordpress-5-4-1/
WPVulnhub - https://wpvulndb.com/vulnerabilities/9908
SecurityWeek - https://www.securityweek.com/wordpress-524-patches-six-vulnerabilities
Rapid7 - https://www.rapid7.com/db/vulnerabilities/freebsd-vid-459df1ba-051c-11ea-9673-4c72b94353b5
MITRE (CVE-2019-17674) - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17674
MITRE (CVE-2020-11025) - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11025
NIST (CVE-2019-17674) - https://nvd.nist.gov/vuln/detail/CVE-2019-17674
NIST (CVE-2020-11025) - https://nvd.nist.gov/vuln/detail/CVE-2020-11025
Featured in Wordpress (WordPress 5.8.1 Security Patch Release)
WordPress 5.8.1 - https://wordpress.org/news/2021/09/wordpress-5-8-1-security-and-maintenance-release/
SoMag News - https://www.somagnews.com/security-focused-wordpress-5-8-1-is-live-heres-whats-new/
Paradox Digital (UK) - https://paradoxdigital.uk/blog/wordpress-5-8-1-security-update/
MITRE (CVE-2021-39202) - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-39202
NIST (CVE-2021-39202) - https://nvd.nist.gov/vuln/detail/CVE-2021-39202
"Evan helped us by identifying a vulnerability in our public website, and thanks to Evan's professional standards he did so in accordance with our Responsible Disclosure Policy. Evan is one of the good guys."
"Evan assisted in identifying a vulnerability on our website. He was extremely easy to work with to have this issue resolved in a timely and professional manner. Thanks for all your help Evan, we greatly appreciate it."
"Evan's responsible disclosure helped keep our nonprofit's servers secure."
"Thank you Evan for helping us uncover a hidden vulnerability issue in our account management flow. We couldn't have found it without your help! Now our team can work to fix this issue and give more protection to our customers accounts. Thanks!"
I reported valid security vulnerability to the following companies. (Last Update October 5, 2021)
To read some of my write ups, just click here!