> For the complete documentation index, see [llms.txt](https://shohamshilo.gitbook.io/shohamshilo/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://shohamshilo.gitbook.io/shohamshilo/vulnerability-research/research.md).

# Overview

I research vulnerabilities in public bug-bounty programs and reproduce known CVEs to understand vulnerability classes in depth. This section collects that work.

## Areas of focus

* **Web application vulnerabilities** — the OWASP Top 10, with particular interest in injection and access-control issues.
* **PoC development** — turning a vulnerability into a clean, reliable proof of concept (see [CVE-2018-16763](/shohamshilo/projects-and-tools/fuel-cms-rce.md)).
* **Bug bounty** — applying recon and manual testing to real, in-scope targets.

## Contents

* [Bug Bounty Notes](/shohamshilo/vulnerability-research/bug-bounty.md)

***

➡️ [Bug Bounty Notes](/shohamshilo/vulnerability-research/bug-bounty.md)
