corraldev

Security researcher · Software engineer

I find the flaws your team missed.

I'm Javier Corral. I report vulnerabilities to bug bounty programs and build software for companies. I've been doing both at once for years.

OWASP WSTG · ASVS

Live hacking events

Edge-first engineering

Vulnerabilities reported and accepted at

  • Apple
  • PayPal
  • Adobe
  • Palantir

And other Fortune 500 companies, through their bug bounty programs.

See the reports on HackerOne

I attack systems and I build software.

They're two different jobs, but they feed each other. Once you've watched a system come apart from the inside, you design differently.

Javier Corral at a live hacking event

Live hacking event · Singapore

  1. 01

    Offensive security

    Bug bounty and manual pentesting. Scanners find what's already catalogued; the rest sits in business logic and in chaining flaws that are worth nothing on their own. Every finding comes with a proof of concept you can reproduce.

    • IDOR
    • SSRF
    • Auth bypass
    • Race conditions
    • GraphQL
  2. 02

    Software engineering

    Multi-tenant SaaS, payment integrations and applications your team will have to maintain long after I'm gone. I write with that in mind, and with the security work done before the first release.

    • TypeScript
    • Next.js
    • APIs
    • SaaS
    • Integrations
  3. 03

    Performance at the edge

    Performance, slow queries and cloud bills that grew while nobody was watching. I measure first and change things second; where it pays off, the deployment moves to the edge to sit closer to whoever is using it.

    • Cloudflare
    • Edge
    • Core Web Vitals
    • Cloud cost

On the ground

Where this has taken me.

Javier Corral photographing agricultural machinery during a hacking event

01Des Moines, Iowa

Targets that aren't a website

Connected farm machinery, in Des Moines. When the target has no browser, half of what you know about web work is useless and you pick up the protocol as you go.

The Spanish hacker team posing with the Ambassador World Cup trophy

02Ambassador World Cup 2024

First at the finals.

I finished first in the Championship Finals of HackerOne's Ambassador World Cup, with the Spanish team. You compete as a team: targets get split, everything that turns up gets shared, and the individual score comes out of that.

See the leaderboard

Live hacking

Three days breaking OKX in Singapore.

H1-65: HackerOne put a room of researchers in Singapore for three days to hack OKX live. The video is from that event.

Watch on YouTube

Work

If you hire me, I'm the one working.

No sales rep in front, no junior behind doing the work. You talk to the same person from start to finish.

  1. 01

    Offensive security

    Web and API pentesting, audits and recurring reviews. OWASP methodology, plus the things that work in bug bounty and aren't in the guide.

  2. 02

    Software consulting

    Web development, custom SaaS and integrations with the systems you already run. The security review is included in the price.

  3. 03

    Performance and infrastructure

    Performance, databases and the cloud bill. I start by measuring, and you get the before and after when it's done.

Got something to break, or something to build?

A pentest, an audit, a product you want to ship, or just a bug you've found and can't tell how bad it is. Write, and I'm the one who answers.

Response time

Under 24 business hours

Research

hackerone.com/corraldev