Directory

Evan Ricafort | @evanricafort

Evan Ricafort

Poblacion, Ipil
Zamboanga Sibugay
7001, Philippines



About

I'm Evan Ricafort, a security consultant/bug hunter from the Philippines who is interested in web application security testing. I was born and raised in the little town of Ipil, Zamboanga Sibugay. studied computer networking at Ateneo de Zamboanga University. I am currently working remotely as an Offensive Security Engineer (Security Consultant) for a Chicago, Illinois-based cybersecurity firm. I've been an active member of the bug bounty community since early 2013, disclosing many types of security vulnerabilities on famous websites such as Microsoft, Google, Twitter, and others. In my spare time, I enjoy biking, playing video games, and other outdoor activities. If you wish to include me in your bug bounty program, please contact me through email or direct message on Twitter (@evanricafort). I'll do my best to provide you with excellent research.

Languages

  • Visayan

  • Tagalog

  • English

Technical Skills

  • Web Application Assessment

  • Network Penetration Testing

Work Experience

Badge & Certificate

  • Cyber Security and Privacy Foundation Pte Ltd - Certified Whitehat Hacker v1 (CWHH) - Certificate ID. UC-SD45SNW8

  • Ben Sadeghipour (@NahamSec) - Intro to Bug Bounty Hunting and Web Application Hacking - Certificate ID. UC-d8e7bc7d-d3eb-4646-9a06-3c09d1bbf5f5

  • TCM Security Inc. - Practical Ethical Hacking - The Complete Course PEH - The Complete Course

  • PentesterLab - PentesterLab's Introduction Badge - Badge ID. PTLN9552

  • PentesterLab - PentesterLab's Essential Badge - Badge ID. PTLE2521

News & Press

Testimonials

  • Dominic Yeadon
  • - Managing Director at Data Harvesting U.K

    "Evan helped us by identifying a vulnerability in our public website, and thanks to Evan's professional standards he did so in accordance with our Responsible Disclosure Policy. Evan is one of the good guys."

  • Corina Mansueto
  • - Director of Social Media & Customer Service at Lavasoft

    "Evan assisted in identifying a vulnerability on our website. He was extremely easy to work with to have this issue resolved in a timely and professional manner. Thanks for all your help Evan, we greatly appreciate it."

  • Max Hunter
  • - Web Development Team Lead at Electronic Frontier Foundation (EFF)

    "Evan's responsible disclosure helped keep our nonprofit's servers secure."

  • Hipmunk
  • - Hipmunk Security Team

    "Thank you Evan for helping us uncover a hidden vulnerability issue in our account management flow. We couldn't have found it without your help! Now our team can work to fix this issue and give more protection to our customers accounts. Thanks!"

Achievements

    I reported valid security vulnerability to the following companies. (Last Update April 22, 2024)

• 123 Contact Form — http://www.123contactform.com/security-acknowledgements.htm
• 4chan — https://hackerone.com/4chan/thanks
• ActiveCampaign — http://www.activecampaign.com/security/
• Adobe — http://helpx.adobe.com/security/acknowledgements.html (2014)
• Advance Custom Fields (WP Plugin) — https://www.advancedcustomfields.com/contact/
• Aha IO — http://aha.io/legal/security
• Aimlab — https://aimlab.gg/bug-bounty
• Airbnb — https://www.airbnb.com/help/policies/responsible_disclosure#responsible_disclosure_policy
• AndroidFreeApps — http://www.androidfreeapp.net/security-researcher-acknowledgments/ (May 2014)
• Appcelerator — https://www.appcelerator.com/privacy/responsible-disclosure-of-security-vulnerabilities/
• Apple — http://support.apple.com/kb/HT1318 (2014, 2021 & 2022)
• Apptentive — https://www.apptentive.com/contact/
• Appointlet — https://www.appointlet.com/
• Artsy — https://artsy.net/security
• AT&T — https://hackerone.com/att/thanks
• Atlassian — https://bugcrowd.com/atlassian/hall-of-fame
• Attack Secure — http://attack-secure.com/whitehat/
• Audiomack — http://www.audiomack.com/about
• Automattic — https://hackerone.com/automattic/thanks
• AVG Technologies — https://support.avg.com/support_contact_form?l=en_US
• AwardWallet — https://app.cobalt.io/awardwallet/awardwallet/hall-of-fame/all
Read More

Write Ups

To read my write ups, just click here!

Free counters!