Breaking Past 403: A Deep Dive into Out-of-Band SQL Injection Discovery
Discovered Out-of-Band SQL Injection on MSSQL server, bypassing 403 restrictions through directory fuzzing and payload crafting.
Read MoreWELCOME TO MY WORLD
I am an experienced penetration tester with 5 years of expertise and certifications including CEHv13, eJPT, CNSP, CAP, and CRTA. Specializing in fortifying security across diverse sectors including Banking, Finance, Ecommerce, and Healthcare.
My name is Septio Noerdiansyah, known online as RyuuKhagetsu — a passionate cybersecurity professional with over 5 years of experience in penetration testing, vulnerability assessment, and red teaming. My journey began as a CTF enthusiast while studying Computer Science, and quickly evolved into a professional career in security.
My mission is to help organizations strengthen their security posture by identifying and mitigating vulnerabilities before they can be exploited by malicious actors. I believe in responsible disclosure and ethical hacking principles.
Expert in black/gray box penetration testing across web applications, networks, mobile apps, and cloud infrastructure.
Experienced bug bounty hunter with a track record of finding critical vulnerabilities across major platforms.
Proficient in analyzing compiled binaries, identifying vulnerabilities, and creating custom exploits.
Deep understanding of network protocols, traffic analysis, and infrastructure hardening techniques.
Specialized in Android app assessments, API security, and mobile app architecture reviews.
Expert in OWASP Top 10 vulnerabilities including XSS, SQLi, CSRF, and business logic flaws.
A collection of tools and applications I've built
LazyScan is an automated reconnaissance & vulnerability scanner that combines various tools for comprehensive scanning with real-time Telegram notifications.
A security compliance tool that performs static analysis on Android APKs and passive security checks on web applications. All findings are automatically mapped to ISO/IEC 27001:2022 controls with CVSS 4.0 scoring for compliance reporting.
Advanced subdomain enumeration tool designed for penetration testers and security researchers. Combines multiple reconnaissance techniques with intelligent analysis to discover and analyze subdomains with actionable pentesting insights.
A simple landing page for a tutoring service called Shirai Education, built with HTML, CSS, JavaScript, and Bootstrap.
A landing page and simple dashboard website for a photocopy service, built with HTML, CSS, JavaScript, and Bootstrap.
Companies and platforms that have recognized my security contributions


Work experiences and another activity.
Jakarta, Indonesia • Full-time
Specialized in enterprise cybersecurity engineering, implementing robust security infrastructure and conducting comprehensive security assessments.
Jakarta, Indonesia • Remote
Participated as a penetration testing team member in a Vulnerability Assessment and Penetration Testing (VAPT) engagement conducted by Linuxhackingid, focusing on API security testing for the cariilmu.co.id platform.
Jakarta, Indonesia • Contract
Conducting comprehensive vulnerability assessment and penetration testing on critical financial systems for Indonesia's national postal service.
Jakarta, Indonesia • Contract
Executed advanced penetration testing on staging web applications, successfully achieving server access through critical vulnerability exploitation.
Jakarta, Indonesia • Contract
Specialized penetration testing of Visa product features within mobile banking application, focusing on payment security and user data protection.
Jakarta, Indonesia • Long-term Contract
Comprehensive security assessment of university IT infrastructure, covering both production and pre-launch educational systems.
Semarang, Indonesia • Project-based
Security assessment of academic information systems with focus on student data protection and system integrity.
Jakarta, Indonesia • Remote
Leading offensive security initiatives and overseeing advanced cybersecurity training programs.
Jakarta, Indonesia • Remote
Leading cybersecurity education and conducting advanced security assessments including network penetration testing and vulnerability analysis.
Brussels, Belgium • Freelance
Active researcher on European bug bounty platform, focusing on advanced reconnaissance techniques and penetration testing methodologies.
San Francisco, CA • Freelance
Active bug bounty hunter on one of the world's leading crowdsourced cybersecurity platforms, identifying critical vulnerabilities for global enterprises.
Remote • Freelance
Long-standing member of the HackerOne community, conducting security research and vulnerability assessments for major technology companies.
Open Source • GitHub
Developed LazyScan, an automated reconnaissance and vulnerability scanning framework designed to support penetration testing and bug bounty activities by integrating multiple popular security tools.
The project focuses on efficiency, automation, and operational visibility to accelerate recon workflows and improve testing productivity.
🔗 Repository: github.com/ryuukhagetsu/lazyscan
Open Source • GitHub
Developed an advanced subdomain enumeration tool designed to support penetration testers and security researchers during the reconnaissance and information gathering phase.
The tool emphasizes actionable intelligence by transforming raw reconnaissance data into structured, prioritized security insights.
🔗 Repository: github.com/ryuukhagetsu/subdomain-enumerator
Open Source • GitHub
seccomp-cli is a security compliance tool that performs static analysis on Android APKs and passive security checks on web applications. All findings are automatically mapped to ISO/IEC 27001:2022 controls with CVSS 4.0 scoring for compliance reporting.
🔗 Repository: github.com/ryuukhagetsu/seccomp-cli
Open Source • GitHub
Developed an educational platform designed to provide learning resources and interactive content for students and educators.
🔗 Repository: github.com/ryuukhagetsu/shirai_education
Open Source • GitHub
Developed a business management application for a photocopy shop, providing features for transaction tracking, inventory management, and sales reporting.
🔗 Repository: github.com/ryuukhagetsu/akbar_photocopy
Universitas Pamulang, Jakarta
Delivered keynote presentation on emerging cybersecurity trends and future threat predictions at National Seminar, featuring live cyber attack demonstrations.
Community Cybersecurity Universitas Gunadarma (CCUG)
Invited speaker for cybersecurity career webinar series, sharing insights on industry opportunities and challenges facing the next generation of cybersecurity professionals.
Indonesia • Various Locations
Received multiple certificates of appreciation from government agencies and prestigious institutions for contributions to cybersecurity awareness and vulnerability research.
Indonesia • Academic Institutions
Honored by multiple prestigious universities for cybersecurity contributions and educational support through vulnerability research and responsible disclosure.
Global • Online & On-site
Continuously advancing professional expertise through industry-leading certifications and specialized training programs.
Professional certifications, achievements, and recognition in cybersecurity field
INE Internetwork Expert
Issued: July 2025
EC-Council
Issued: March 2024
CyberWarFare Labs
Issued: January 2024
SecOps Group
Issued: December 2023
SecOps Group
Issued: November 2023
CertiProf
Issued: June 2024
CertiProf
Issued: June 2024
CertiProf
Issued: June 2024
CertiProf
Issued: March 2025
CSIRT - Cimahi
Issued: December 2024
CertiProf
Issued: June 2027
eSecurity Insitute
Issued: June 2024
OPSWAT Academy
Issued: September 2024
EC Council
Issued: June 2024
EC Council
Issued: Feb 2024
EC Council
Issued: June 2024
utwente
Issued: November 2023
Visma
Issued: November 2023
Wagenigen
Issued: September 2023
NASA
Recognized: February 2024
Recognition for responsible disclosure of security vulnerabilities in NASA systems.
Lenovo
Recognized: January 2024
Acknowledgment for finding critical vulnerabilities in Lenovo enterprise products.
BSSN VVIP Program
Event: 5 - 14 February
eduwork.id
Issued: January 2022
IT Center Pamulang University
Issued: December 2023
CSIRT - KOMINFO
Issued: January 2022
Telkom University
Issued: September 2024
Brawijaya University
Issued: September 2023
BSI University
Issued: Januari 2021
BSI University
Issued: February 2021
detik.com
Issued: January 2023
Pamulang University
Issued: September 2024
Linuxhackingidp>
Issued: May 2024
Linuxhackingid
Issued: March 2024
Sharing knowledge through detailed write-ups and tutorials
Discovered Out-of-Band SQL Injection on MSSQL server, bypassing 403 restrictions through directory fuzzing and payload crafting.
Read More
Discovered Broken Access Control exposing admin dashboard with full CRUD functionality, chained with SQL Injection vulnerability.
Read More
Critical authentication flaw in a university system's security. Responsibly disclosed, unexploited, and reported.
Read More