Penetration testing and bug bounty hunting

Hey, I'm Lorenzo. I'm a freelance pentester and bug bounty hunter focused on web applications. I look for the bugs, write up how I found them, and share what I learn along the way.

About me

I've been working in tech for about five years. I started out as a developer, building web apps, and somewhere along the way I got more curious about how they break than how they're built. About a year ago I made the jump to offensive security, and I haven't looked back.

These days I do freelance pentests and hunt bugs on public programs, mostly on web applications. Having written the kind of code I now test helps: I know where the shortcuts usually get taken. I'm always studying and picking up new techniques, and this site is where I'll share what I learn.

Pixel-art avatar of Lorenzo Fenderico
My Pentest Methodology, Full BreakdownNot a payload cheat sheet. The scaffolding that gets you unstuck when you don't know where to start.

Contact

Need a web app tested, got a question about a finding, or just want to talk security? I'm available for freelance pentests. Email is fastest.