SAJAY CHANDRAN.

I build things to find out how they break.

I'm a cyber security student who also builds software. Frisyn, an Android app I shipped alone, is the building. Vulnerable lab machines are the breaking, and I write up every one.

Location
Bangalore, India
Degree
BCA, third year
Specialization
Cyber Security & Ethical Hacking
Minor: Digital Forensics

Featured project

Frisyn

Step Into Silence Live on Google Play

An anonymous social app for Android that I designed, built and published on my own. It is designed to collect no email, phone number or real name, and runs on a custom authentication system.

  • React Native
  • Expo SDK 54
  • Firebase
  • Firestore
  • Cloud Functions
  • Argon2id
  • Frisyn welcome screen with the tagline Step Into Silence and options to get started or sign in.
    WelcomeStart or sign in.
  • Frisyn account creation screen asking only for a password, with an age and terms checkbox, and a note that no email, phone number or username is required.
    Sign upPassword only.
  • Frisyn home feed showing anonymous posts attributed to sequential account numbers, with emoji reaction counts and comment counts.
    FeedAccount numbers.
  • Frisyn reaction picker sheet with a grid of emoji and an option to add any custom emoji.
    ReactionsAny emoji.
  • Frisyn profile screen showing the account number as the identity, a 24-hour mood status with an expiry countdown, and post, reaction and comment counts.
    Profile24-hour mood status.
  • Frisyn one-to-one chat conversation between two anonymous accounts.
    ChatOne-to-one.

Ownership

Idea, app, backend, legal pages, store listing and release, all solo. I ran Google Play's closed testing, shipped fixes from tester feedback, and debugged and tested the result. AI tools helped write code; the decisions were mine.

Custom authentication

  • Argon2id password hashing
  • Atomic account numbers with Firestore transactions
  • Hashed one-time recovery codes
  • A version gate that fails open

Full case study → Google Play ↗ Website ↗ GitHub ↗

Security lab write-ups

Machines I've taken apart

Educational exercises on deliberately vulnerable VMs, run from Kali in IBM-guided university sessions. Not professional penetration tests or client work.

WestWild v0.1

VulnHub VMRoot achieved

  1. Nmap
  2. Anonymous SMB
  3. Base64 creds
  4. SSH
  5. Writable dir
  6. Plaintext creds
  7. sudo
  8. Root
Initial weakness
An SMB share allowed anonymous access to a file of credentials. Base64 is encoding, not protection.
Chaining
Those credentials gave SSH. A writable directory held a script with another account's password, which could run sudo su.
Impact
Unauthenticated start to full root control of the host.
Root cause
Guest SMB access, secrets stored in files, unrestricted sudo.
Remediation
Disable guest SMB; keep secrets out of files; prefer SSH keys; limit sudo to specific commands; rotate exposed credentials.

No single issue was the whole problem. Chained, they became a full compromise.

HA: Vedas

VulnHub VMRoot achieved

  1. TCP/UDP scan
  2. SNMP
  3. CeWL + dirb
  4. Credentials
  5. SSH
  6. Port forward
  7. Clues
  8. sudo
  9. Root
Initial weakness
SNMP leaked system details, and a hidden web application had credentials I recovered with a CeWL wordlist.
Chaining
Credentials gave SSH. netstat showed a localhost-only service; forwarding its port revealed clues that unlocked an account with sudo.
Impact
Root access from a network-only starting point.
Root cause
Information leaks, guessable credentials, trust in localhost binding, unrestricted sudo.
Remediation
Restrict SNMP (SNMPv3, allowed hosts); patch the web app and enforce strong passwords with lockout; authenticate internal services; least-privilege sudo.

Binding a service to 127.0.0.1 feels like a boundary until someone already has a session on the box.

Freelance work

Wahat Al Zahar Trading

Website & digital setup

A custom corporate website and full digital setup for a Dubai-based B2B food and beverage wholesaler, designed and delivered on my own as a freelance project. AI tools helped write the code.

  • React
  • Vite
  • Tailwind CSS
  • Netlify Functions
  • Airtable
  • Original brand and UI, with custom SVG graphics and no stock photos
  • A live careers page the client manages in Airtable, with no code changes
  • Inquiry and job-application forms with validated CV upload
  • Domain, Google Workspace email and branded documents

Case study → Live site ↗

Technical skills

What I work with

Practised in security labs

  • Kali Linux, Linux
  • Nmap
  • Metasploit
  • Burp Suite
  • SNMP enumeration
  • CeWL, dirb
  • SSH, port forwarding
  • Privilege escalation via sudo

Used in projects

  • React Native, Expo, EAS Build
  • Firebase, Firestore, Cloud Functions
  • Firestore security rules
  • Custom authentication, Argon2id
  • Git, GitHub
  • Google Play Console, deployment
  • Python
  • Debugging, documentation
  • AI-assisted development workflow

Currently learning

  • JavaScript fundamentals
  • Digital forensics

Education & CTF

Where I'm studying

  • 2024 – present · Year 3, Semester 5BCA — Cyber Security & Ethical Hacking, minor in Digital Forensics
    Yenepoya (Deemed to be University), Bangalore, in collaboration with IBM.
  • IBM sessionsAdvanced Python (built a file organizer) and trainer-guided ethical hacking sessions behind the lab write-ups above.
  • TRIADA CTFParticipant in 2025 and 2026 (24-hour edition) at Yenepoya University.

Contact

Get in touch

Open to internships, entry-level roles and freelance projects in software development and application security.