OFFENSIVE SECURITY & BUG BOUNTY
A hands-on, live bug bounty training — taught by a researcher who actively hunts on real programs, not someone reciting tutorials.
Change one number in a URL, and see what you're not supposed to see. That's the first lesson: IDOR and Broken Access Control, taught by finding them live.
These are programs and platforms I'm actively working on. The techniques taught in the course are the same ones applied here.
Before investing in any training, you should know who's behind it.
Working real programs on Intigriti and YesWeHack right now — not a dormant profile.
IDOR, Broken Access Control and Business Logic are the core focus, with a strong lean toward API reconnaissance.
A law degree means the ethical and legal boundaries of hacking are taught properly, not glossed over.
Ramez Medhat is an active bug bounty researcher and cybersecurity practitioner, specialized in identifying and reporting Insecure Direct Object References, Broken Access Control and business logic flaws through structured API reconnaissance.
Alongside hunting, he builds his own tooling — including a recon methodology tool and an Android companion app — rather than relying only on off-the-shelf scanners. This course is built on the same methodology he uses day to day.
6 weeks, 12 live sessions, built for beginner-to-intermediate hunters who want a real, structured path.
Target discovery & hidden endpoint mapping
Practical API testing
Broken Access Control hunting, step by step
Business logic flaws scanners miss
Writing a report & PoC that gets triaged
Ethical hacking boundaries & cybercrime law
A single-file recon dork tool with severity badges and a guided review mode — the same methodology applied in live hunts.
An Android companion app (Jetpack Compose + Room) that structures the hunting workflow from recon to report — built for personal use first.