tr0j4n.tech

Rahul Sreenivasan

tr0j4n.tech

A chess player who loves coding and solving complex problems. That eventually led me into cybersecurity, where I now spend my time breaking into web and mobile applications, Active Directory environments, and AI applications.

Available for security work India
Portrait of Rahul Sreenivasan (tr0j4n)
Rahul Sreenivasan tr0j4n · India · security researcher
04
Published CVEs
06
Certifications
02
Open-source tools

Published CVEs

Responsible disclosures in widely-installed WordPress plugins. Expand a row for detail.

  1. 01 CVE-2025-11977 LFI Admin+ Authenticated (Admin+) Local File Inclusion in the HappyForms plugin. Affected HappyForms ≤ 1.26.12Installs 20,000+ Oct 2025

    Local File Inclusion in HappyForms ≤ 1.26.12 via the happyforms_get_form_partial() function, letting an authenticated administrator include and execute arbitrary .php files. CVSS 6.6 (Medium).

    Status Published · CVE record

  2. 02 CVE-2025-10042 SQLi Unauthenticated Unauthenticated SQL Injection via the X-Forwarded-For header. Affected Quiz Maker ≤ 6.7.0.56Installs 20,000+ Sep 2025

    The Quiz Maker plugin trusted the X-Forwarded-For request header in a SQL context, allowing an unauthenticated attacker to inject SQL. Affects installs at ≤ 6.7.0.56 across 20,000+ sites.

    Status Published · CVE record

  3. 03 CVE-2025-9318 SQLi Subscriber+ Authenticated (Subscriber+) SQL Injection via the is_linking query parameter. Affected Quiz and Survey Master (QSM) ≤ 10.3.1Installs 40,000+ Aug 2025

    A low-privilege (Subscriber) account could reach a SQL injection through the is_linking query parameter in Quiz and Survey Master ≤ 10.3.1, deployed on 40,000+ sites.

    Status Published · CVE record

  4. 04 CVE-2025-9637 Broken Access Control Missing authorization exposing unpublished, private and password-protected quiz data and image uploads. Affected Quiz and Survey Master (QSM) ≤ 10.3.1Installs 40,000+ Aug 2025

    Missing authorization checks in Quiz and Survey Master ≤ 10.3.1 exposed unpublished, private and password-protected quiz information and permitted image response uploads without proper authorization.

    Status Published · CVE record

Tools

Open-source offensive-security tooling.

  • mcploit-burp Author Kotlin

    A Burp Suite extension that speaks MCP: connect, enumerate tools / resources / prompts, and hand-craft calls from inside Burp. A Repeater for a protocol Burp does not natively understand.

  • mcploit Contributor Python

    Framework to enumerate and exploit MCP (Model Context Protocol) servers. Created by Heisenbergg4; tr0j4n contributes.

    by Heisenbergg4

Certifications

  • Offensive Security Certified Professional (OSCP) badge
    OSCP Offensive Security Certified Professional OffSec Jan 2024
  • Offensive Security Wireless Professional (OSWP) badge
    OSWP Offensive Security Wireless Professional OffSec Jun 2024
  • Certified Penetration Testing Specialist (CPTS) badge
    CPTS Certified Penetration Testing Specialist Hack The Box Nov 2024
  • Certified Offensive AI Expert (COAE) badge
    COAE Certified Offensive AI Expert Hack The Box Jul 2026
  • Junior Penetration Tester (PT1) badge
    PT1 Junior Penetration Tester TryHackMe Jun 2025
  • eLearnSecurity Junior Penetration Tester (eJPT) badge
    eJPT eLearnSecurity Junior Penetration Tester INE Mar 2023

Recognition & community

  • Team

    Core member, team v1olet

    Core member of v1olet, a competitive security / CTF team.

    Present
  • Community

    Moderator, Adversary Village @ DEF CON

    Built Adversary Simulation challenges for the Adversary Wars CTF (DEF CON 32 & 33) and moderate the Adversary Village community.

    Jul 2024 – Present
  • Community

    Chapter Head, OWASP Amrita

    Led the OWASP student chapter at Amrita School of Engineering, Chennai; organized meetups, webinars and conferences.

    Jul 2022 – Jan 2024

Work with me

Available for focused security engagements. Every engagement ends in a clear, reproducible report: findings, impact, and the fix, not a scanner dump.

  • Web & API penetration testing Manual, depth-first testing of web applications and APIs: auth, access control, injection, and business logic.
  • Source code review Reading the code, not just the surface, to trace vulnerable paths from input to sink.
  • Vulnerability research Digging into a target or dependency for novel issues, up to responsible disclosure and CVE.
  • Security tooling & automation Custom offensive-security tooling to make testing faster and more repeatable.

Scope and terms are set per engagement. Get in touch to talk through what you need.