Curriculum vitae / 2026

Sukhbat Zundui

deprrous · Security Researcher · Bug Bounty Hunter · CTF Player

Profile

Independent security researcher focused on web applications, open-source software, and trust-boundary failures. Public work includes four CVEs, six GitHub advisory credits, five validated bug-bounty findings across HackerOne and Immunefi, and maintainer-accepted upstream fixes. One year of DevOps, systems engineering, and white-box security testing experience at Onlime Network LLC.

4 CVEs 6 advisory credits 5 validated findings 1 yr Onlime Network

Professional & Research Experience

DevOps & Systems Engineer · Security Testing

Onlime Network LLC · Telecommunications

  • Operate and improve production infrastructure as a DevOps and systems engineer.
  • Perform white-box security assessments for CallPro Teams, CallPro Platform, and LIME Mongolia, coordinating remediation with product teams.

Independent Security Researcher

Open source · HackerOne · Coordinated disclosure

  • Identified access-control, parser, path-boundary, SSRF, XSS, and input-validation vulnerabilities across Rocket.Chat, Auth.js, LangChain, fast-xml-parser, and pdfme.
  • Produced reproducible proof-of-concept reports and worked through public advisory processes, remediation, and coordinated disclosure.
  • Public HackerOne record: three validated findings on @deprrous, including a resolved Supabase Medium 4.3 report; one resolved Vercel Open Source Medium 6.3 / Tier 1 finding on @deprrouslalruda. One additional valid Low-severity Immunefi report remains private.

Upstream Fixes & Contributions

Apache Struts · Authelia · libpcap

  • Diagnosed Struts lazy-interceptor concurrency behavior in PR #1815; the scenario and test were carried into merged successor #1816 with co-authorship.
  • Reported Authelia’s OTC DELETE nil-pointer panic, leading to merged fix #11500 and public bug-contributor credit.
  • Authored merged libpcap PR #1709 restoring the Clang diagnostic-state helper.

CTF Player · Hackratic / C47 / R47

Web and Crypto · Mongolia

  • At AITU CTF 2026, C47 ranked #3 overall and #1 international in qualification (839 entrants reported; 270 teams on CTFtime’s scoreboard), then placed 10th of 20 at the Astana final. C47 also won the official GeoGuessr tournament.
  • Contributed within a team ranked #27 overall and #3 in Mongolia on CTFtime in 2026, with 455.552 rating points across 36 events.
  • Hackratic placed 9th at the VolgaCTF 2026 Qualifier and qualified for the September 14–18 final, with attendance planned.
  • Placed 24th of 185 at HackDay Qualifications, inside the 25-team final cutoff; the team could not attend the Paris final because travel funding was unavailable.
  • Advanced to finals or Stage 2 in multiple Mongolian domestic CTFs; no podium placement is claimed.

Selected Public Research