Pasindu Sandeepa. Junior Researcher specializing in Penetration Testing and Network Defense. Based in Sri Lanka.
Hi, I am Pasindu, a 2nd year Computer Science undergraduate at Eastern University Sri Lanka. My interest has always been in Cyber Security. I want to ensure that security is a top priority within our quickly developing world and would like to contribute to a more secure environment.
I like to keep myself relevant by solving Capture The Flags on HackTheBox and working through PortSwigger Web Security Academy labs - publishing 250+ detailed writeups along the way. I also build open-source security tools like an XSS Scanner and an HTTP Request Smuggling Detector to sharpen my practical skills.
I would like to improve myself within the Cyber Security field in order to become a professional Penetration Tester. I always keep a close eye on newly discovered vulnerabilities and like to challenge myself with unsolved weaknesses. I am someone who wants to make the world a more secure place, even if it goes unnoticed.
I focus on turning complex security theory into hands-on execution. My approach is simple: detect, exploit, report, and defend.
Custom Python tool for automated, low-false-positive XSS detection.
Identifying CL.TE / TE.CL desync vulnerabilities at the raw request level.
Open-source Python utilities built for real-time security monitoring.
OWASP Top 10, SQL/NoSQL Injection, XSS, SSRF, Authentication Bypass, CSRF, IDOR, HTTP Request Smuggling.
Burp Suite, Nmap, RustScan, Metasploit, Wireshark, SQLMap, Hashcat, John the Ripper, Nuclei.
Python, Bash Shell Scripting, Java, Git, GitHub, Quartz V4.
Kali Linux, Ubuntu, HackTheBox, TryHackMe, PortSwigger, Bugcrowd, HackerOne.
I am currently open to new opportunities, particularly in penetration testing, vulnerability research, and security engineering roles. Whether you have a question about my writeups or want to discuss a potential project, feel free to reach out!