∞ 1nf1n1ty/ prince barai
MISSIONCPENT ///EXAM_LOADING
UTC --:--:--
PB://SECURE-BIOS v6.20%
⟵ drag to spin the loop ⟶
security researcher · bug bounty · tool dev
// known in the wild as 1nf1n1ty — because the grind never terminates

PRINCE BARAI

$ 

I break things responsibly. Hunting vulnerabilities on Bugcrowd, HackerOne, Intigriti & Comolho since 2022, building recon automation other researchers actually fork, and earning acknowledgments — including one from NASA. Current objective locked: CPENT.

view arsenal → open channel
0
years hunting
0
tryhackme world
0
payload environs
0
bounty platforms
01

WHOAMI

$ cat /etc/1nf1n1ty/passwd

Cybersecurity undergraduate at Parul University (B.Tech Cybersecurity, '23–'27) with real operational experience — not just labs. Since November 2022: XSS, SQL injection, authentication bypass, IDOR, and hardcoded credentials exposing employee PII (CVSS 9.1 Critical) — hunted across Bugcrowd, HackerOne, Intigriti & Comolho, responsibly disclosed every single time.

Delivered a critical-severity finding for a production client — SFS Group Schweiz AG (via Intigriti) with a clear, structured business-impact report. In 2025, NASA's Vulnerability Disclosure Program sent a Letter of Appreciation for responsible reporting on their public infrastructure.

I build my own weapons: a recon automation framework forked and deployed by other researchers, a 13-environment reverse shell generator, and an E2EE messenger stress-tested against its own author. Core member of The Hacker's Meet-Up — running CTFs, mentoring offensive security.

// current objectiveClear the CPENT exam. Loop the grind. ∞
operator cardPB-∞-0x7C3
∞
ALIAS 1nf1n1ty
NAME Prince Barai
BASE Vadodara, IN
STATUS ● ACTIVE
OP CPENT CERT
NETCPUMEM
clearance: responsible disclosure · est. 2022
02

FIELD OPERATIONS

$ tail -f /var/log/ops.log
nov 2022 — presentLIVE

Bug Bounty Hunter · Vulnerability Researcher

Bugcrowd · HackerOne · Intigriti · Comolho — Remote
  • Identified and responsibly disclosed critical vulnerabilities — XSS, SQL Injection, authentication bypass, IDOR, and hardcoded credentials with employee PII exposure (CVSS 9.1 Critical) — across multiple production platforms on Bugcrowd, HackerOne, and Intigriti.
  • Delivered a CVSS 9.1 critical-severity finding for a production client — SFS Group Schweiz AG (via Intigriti) — producing a clear, structured business-impact report for stakeholders.
  • NASA VDP 2025: Letter of Appreciation for responsible disclosure on public-facing infrastructure.
  • Actively hunting on Comolho for the past few months — expanding coverage across emerging programs.
  • Built automated recon tooling adopted in daily bounty workflows — collapsing manual discovery time.
  • Structured reports fusing OSINT, automated scanning & manual exploitation.
aug 2024 — presentLIVE

Core Member — Cybersecurity Club

The Hacker's Meet-Up · Parul University
  • Organised CTF competitions and hands-on workshops for 100+ students.
  • Mentored peers in web exploitation, offensive techniques & threat analysis.
jul 2024 — presentLIVE

Google Student Ambassador

Google — Remote
  • Drove tech education through workshops and community events across campuses.
jul 2024 — apr 2025COMPLETE

Microsoft Learn Student Ambassador

Microsoft — Remote
  • Delivered live sessions on Azure AI, VMs & NLP to 100+ students.
  • Embedded security awareness into cloud & NLP workshops.
03

DEPLOYED ARSENAL

$ ls -la ~/arsenal --sort=time
ADV-PB-0001 · 2022→HIGH IMPACT

Recon Framework

github.com/1cYinfinity/recon · Shell

End-to-end automated vulnerability discovery: subdomain enumeration & takeover detection, WHOIS, sitemap extraction, hidden admin panels, parameter discovery & XSS scanning — one pipeline, many sources. Forked by researchers; lives in real bounty workflows.

OSINTSUBTAKEOVERXSSAUTOMATION
SURFACE: webREAD SOURCE ↗
ADV-PB-0002 · 2024CRITICAL

Reverse Shell Generator

multi-language payload forge · Python

Generates reverse shells across 13 environments — Bash, Python, PHP, Perl, PowerShell, Ruby, Node.js, Java, Lua, Netcat, ASP, C#. Battle-tested in CTF finals & engagements.

PAYLOADSRED TEAMCTF
TYPE: offensive utilREAD SOURCE ↗
ADV-PB-0003 · 2024MEDIUM · HARDENED

LockChat

end-to-end encrypted messaging · Python + Crypto

E2EE messaging app adversarially tested against simulated attack vectors, with documented resilience metrics. Built to survive its own author.

E2EECRYPTOGRAPHYADVERSARIAL
TYPE: defensive cryptoREAD SOURCE ↗
04

PROOF OF WORK

$ grep -ri "rank\|cvss" ~/achievements.log
EventResultIntelLoad
🎯 SFS Group Schweiz AGCVSS 9.1 CRITICALProduction client · via Intigriti — clear, structured business report
🛰 NASA VDP★ ACKNOWLEDGEDLetter of Appreciation 2025 — rare for students globally
HackZero'26 CTF#48,800 pts — team event, top-tier finish
KashiCTF 2026#86,446 pts — top-10 team
Bugcrowd BlackHat USA CTF 2025#22 GLOBALPremier industry competition
NahamCon 2025 CTF#42 / 2,9308,127 pts · 75% solved — top 1.5%
Bugcrowd Student CTF 2025#18 / 1567/16 challenges solved
TryHackMeTOP 4%Web exploitation · network security · reversing
05

SKILL MATRIX

$ ./assess.sh --verbose

languages & scripting

Pythonprimary weapon
Bash / Shelladvanced
Cproficient
C++proficient

security tooling

Burp Suitedaily driver
Nmapdaily driver
Metasploitadvanced
Wiresharkadvanced
Kali Linuxhome turf

offensive concepts

OWASP Top 10core
Web Exploitationspecialist
Privilege Escalationadvanced
Subdomain Takeoverspecialist
Red Teamingadvanced

platforms & craft

Bugcrowd / HackerOnelive hunter
Intigritilive hunter
Comolhoactive — few months
Hack The Boxactive
Reporting & Writingadvanced
Public Speaking100+ sessions
06

CREDENTIALS VAULT

$ gpg --list-keys prince
// mission in progress

CPENT — Certified Penetration Testing Professional

EC-Council · 24-hour live practical exam · currently grinding ∞
exam readinessLOADING…
google · 2023

Cybersecurity Professional Certificate

Google Career Certificates
ec-council · 2023

Ethical Hacking Essentials (EHE)

EC-Council
ec-council · 2023

Network Defense Essentials (NDE)

EC-Council
COPIED ✓
prince barai // command paletteESC TO CLOSE
›
guest@barai.local — /bin/sh — 80×24
guest@barai:~$
↑↓ HISTORY · ESC CLOSE · TRY: help · nmap prince.barai · matrix · sudo rm -rf / · 1nf1n1ty