ABOUT

Cristian Vargas
HackerOne / @rollinx1I’m Cristian Vargas, a pentester focused on web applications and APIs.
I work on penetration testing and bug bounty research, mainly access control and application logic.
I build reconnaissance tools and Caido extensions to automate parts of my testing workflow.
This site
I post CTF writeups, technical notes, and documentation for my tools here.
Focus areas
- Web & API pentesting
- Access control and business logic
- Reconnaissance and security automation
- CTFs and practice labs
- Building tools for my own workflow
Certifications & education
- BSCP
Burp Suite Certified Practitioner
PortSwigger · July 2024
- CWEE
Certified Web Exploitation Expert
Hack The Box
- CWES
Certified Web Exploitation Specialist
Hack The Box
- CPTS
Certified Penetration Testing Specialist
Hack The Box
Diploma in Red Teaming
Additional training
Bachelor’s Degree in Cybersecurity
2022–2025
Languages
Read the posts Spanish Native
English Professional proficiency