Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 316,374 coordinated disclosures
186,142 fixed vulnerabilities
370 bug bounties with 805 websites
8,771 researchers, 315 honor badges

metamorfosec | Security Researcher Profile


Security researcher metamorfosec has already helped fix 623 vulnerabilities.



Researcher reputation:  190

Real name:
irfan

About me:
A boutique service that provides consultancy for information security-related domain

How to contact me:
E-mail Address:
info[at]metamorfosec.com

Key Server:
keys.mailvelope.com

Key ID (valid until December 31, 2019):
B4E3D326F01182E3 (Please add 0x as a prefix in the OpenPGP Key Lookup Field)

Award / Bug Bounty I prefer:
Bug bounty payment via PayPal or Bank Transfer, a recommendation on my profile, and/or any interesting stuff or offer

Follow me on:
Twitter

Recommendations and Acknowledgements

    5 February, 2019
     DomainMOD Greg Chetcuti from DomainMOD:
Thank you so much for reporting this vulnerability in a responsible manner! We were able to find and fix this specific vulnerability, as well as another that was related, and we really appreciate your help in getting this sorted out!
    20 January, 2019
     gizmotico Andersen from VegaDesign.net:
Thank you so much for reporting security vulnerability and for the information needed to fix the issues.
    25 October, 2018
     jackwolfskin Christine from Jack Wolfskin:
Thank you very much for helping to make our website even more secure.
    22 August, 2018
     wirthundhorn Support from dtv.de:
Thank you helping us finding and fixing vulnerabilities.
    22 August, 2018
     DanielGuenthe12 Daniel Guenther from Visual Meta GmbH:
Very fast response and very detailed and helpful reply. The observations were all correct and the the HTML which was provided in the response correctly illustrated the vulnerability.

Overall great job and thanks for your efforts!
    17 August, 2018
     tarif4you Alex from DAIR Media:
Thank you very much for a great and in-depth explanation of the issue.
This kind of description makes it very easy to identify and fix the
problem. Really appreciate your help.
    9 August, 2018
     kevinBaseCom Kevin from Online Commerce Ltd:
Thank you foro reporting a security issue with our website and for promptly providing the affected pages.
    26 July, 2018
     sgiannandrea2 sgiannandrea from LepidaSpA:
Thank you so much for reporting XSS vulnerabilities on our websites.
    23 June, 2018
     testmynet CA3LE from TestMy.net:
Thank you for helping me address my XSS issues.
    12 June, 2018
     willy0611 Willy from BOINCstats.com:
Thank you for pointing out a security issue on the BOINCstats website. It helped me find and fix the issue and a few other issues as well.

Shows the first 10 recommendations. See all.

Please login via Twitter to add a recommendation

Awards and Achievements


Number of Secured Websites

10+ Websites
50+ Websites
500+ Websites
WEB SECURITY VETERAN
1000+ Websites

Advanced Security Research

WAF Bypasser
CSRF Master
30+ Reports
AppSec Logic Master
30+ Reports
Fastest Fix
Fix in 24 hours

Outstanding Achievements

Secured OBB
OBB Advocate
Improved OBB

Commitment to Remediate and Patch

Patch Master
55% Patched
Patch Guru
65% Patched
Patch Lord
75% Patched

Recommendations and Recognition

REPUTABLE
10+ Recommends
FAMOUS
25+ Recommends
GLOBALLY TRUSTED
50+ Recommends

Research Statistics



Total reports:2139
Total reports on VIP sites:87
Total patched vulnerabilities:623
Total vulnerabilities on Hold (Open Bug Bounty):753
Recommendations received:12
Active since:30.04.2018

Open Bug Bounty Certificate





No posts in blog yet


Reported Vulnerabilities

All Submissions VIP SubmissionsFeatured Submissions

Domain Reported Status Type
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
17.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting
16.02.2019
On Hold
Cross Site Scripting

  Latest Patched

 17.02.2019 canadapost.ca
 17.02.2019 lentainform.com
 17.02.2019 uchealth.org
 17.02.2019 dainikamadershomoy.com
 16.02.2019 torrentsgroup.com
 15.02.2019 24livenewspaper.com
 15.02.2019 2checkout.com
 15.02.2019 unimed.coop.br
 15.02.2019 hotnigerianjobs.com
 15.02.2019 zlavomat.sk

  Latest Blog Posts

15.02.2019 by ismailtsdln
Adobe Israel Website XSS Vulnerability
07.02.2019 by aye_robot
Reporting CSRF via Openbugbounty
06.02.2019 by Open Bug Bounty
Launching Open Bug Bounty Blog and new platform features

  Recent Recommendations

    14 February, 2019
     DomainMOD:
Thanks a lot for the report! We completely missed this vulnerability ourselves and are happy that you caught it!
    14 February, 2019
     fisher_of_men11:
Thank you for helping me find and fix the XSS vulnerability on mudconnect!
    13 February, 2019
     Koze:
Thank you for reporting a vulnerability on our page very professionally! You did us a great service!
    12 February, 2019
     dsmithgard:
Very helpful and responsive in helping me get my issue fixed.
    11 February, 2019
     fisher_of_men11:
Thank you again, another XSS vulnerability found and fixed!