Hacker × Game Dev × Musician
JOHNYTIGER
Cybersecurity · Developer · Audio Engineer
I break web applications, build game engines and the platforms that run this label, and produce every record in the catalogue. All from the same desk.
Select Class

- Status
- Open to work
- Track
- OSCP in progress
- Base
- Studio · Remote
- Engine
- C++ / SDL2 / Next.js
One operator. Three classes. Same desk.
I break web applications for a living, build the engines and platforms I want to exist, and produce every record in the catalogue. Offensive security, custom game engines, audio plugins, and original releases all come out of the same studio.
This site is part of that practice: the store, the licensing engine, and the blog are hand-built and self-hosted. It is a portfolio that runs as one system.
The Index

A fully functional digital audio workstation built for the RG35XX handheld and similar ARM devices. Features a multi-track sequencer, sample playback engine, effects chain, and a custom SDL2-based UI, all running on embedded Linux with no desktop required.
Loadout
- Web app pentesting82
- OWASP Top 1085
- Vulnerability assessment78
- Auth / session attacks80
- File upload → RCE84
- Report writing88
- C / C++84
- SDL2 · custom engines80
- Procedural generation72
- TypeScript · React · Next.js90
- Node.js · APIs · automation86
- Embedded / ARM · Linux68
- Production95
- Mixing90
- Mastering85
- Sound design86
- Beat making92
- Audio DSP / plugin dev74
Breach
I'm a penetration tester specializing in web application security and vulnerability assessment. My background as a full-stack developer means I don't just run scanners. I understand the auth flows, session handling, and upload logic that attackers target, because I've built them myself. I'm currently pursuing the OSCP certification, with hands-on experience from intensive lab and CTF work (Hack The Box, TryHackMe).
Web Application Penetration Testing
OWASP Top 10 and beyond: injection, broken authentication, access-control failures, insecure file uploads. Manual testing, not just automated scans.
Vulnerability Assessment
Scan, triage, and prioritize. Risk-ranked findings mapped to real business impact, so you fix what matters first.
Security Report Writing
Clear, actionable reports with reproduction steps, evidence, and developer-ready fixes, not raw scanner dumps.
Web App Pentest: File Upload to Remote Code Execution
Authorized assessment of a PHP CMS in a controlled lab. An avatar-upload feature validated files by extension and MIME type only. Using Burp Suite, I bypassed both checks: an alternate PHP extension (.phar) defeated the blacklist, and a GIF89a magic-byte header spoofed the content-type. A polyglot payload passing both checks yielded remote code execution as the web-server user, leading to full application-server compromise.
- +Allow-list extensions instead of blacklisting
- +Verify true file content server-side
- +Store uploads outside the web root
- +Randomize stored filenames
- In progressOSCP (OffSec Certified Professional)
- OngoingHack The Box / TryHackMe, active lab practice
Channel open · send signal
Work With Me
Open for penetration testing engagements and security roles, game and audio tooling, music collaborations, and beat licensing. One email reaches all three classes.







