Irethe_red Profile Banner
Ire Ogunsanya Profile
Ire Ogunsanya

@Irethe_red

Followers
12
Following
39
Media
1
Statuses
104

Security researcher. I break Saas apps before attackers do Web & API pentesting | Bug hunting | Light audits for early stage teams.

Joined July 2025
Don't wanna be here? Send us removal request.
@Irethe_red
Ire Ogunsanya
1 month
Delivered a Lite Audit last week for an early-stage fintech (anonymized). Found key issues in signup, onboarding, and API permissions, all actionable fixes founders can implement immediately. Always satisfying to see teams take security seriously.
0
0
1
@Irethe_red
Ire Ogunsanya
27 days
Looked into a React app today where CORS was “temporarily relaxed” during development. It never got locked back down. Any site could make authenticated requests on behalf of users.
0
0
0
@Irethe_red
Ire Ogunsanya
28 days
File upload endpoint accepted scripts. Executed server-side. One click, full compromise.
0
0
0
@Irethe_red
Ire Ogunsanya
28 days
Weak password reset logic. Unverified accounts? Anyone could reset.
0
0
0
@Irethe_red
Ire Ogunsanya
29 days
Third-party integration leaking tokens. Automated scripts could have taken everything. Nobody noticed.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
I noticed some recurring gaps in Nigerian fintech signup/auth flows that could be abused if left unchecked. Unverified logins & early session issuance risk ops headaches & hurt user trust. Happy to share a short, actionable overview with your team. @Shuttlersng
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Logic flaw in subscription flow. Anyone clever enough could escalate privileges. Most devs never see it. That’s why I do.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Rate limits were lying. Hundreds of OTPs allowed. And everyone thought it was “fine.”
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Internal admin panel. No MFA. Just sitting there, waiting. Attackers could’ve owned it in seconds.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Cloud workflow misconfigured. Payroll info could’ve walked out the door silently. Startups shrugging? They won’t shrug when it hits headlines.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
I found critical gaps in Kindlybook’s signup/login flows that could lead to serious account abuse and operational issues if left unaddressed. I can provide a short, actionable overview directly to help prevent headaches and safeguard your platform. @charles_dairo
1
0
5
@Irethe_red
Ire Ogunsanya
1 month
Clicked through an API. Every endpoint looked fine… until it wasn’t. One chained request later, sensitive data was leaking.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
I was testing a signup flow today. Five minutes in, I had an OTP bypass in my hands. The devs never saw it coming. Users? Exposed.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Ran through Busha’s signup and auth flows, spotted a few gaps that could let abuse slip through quietly and create serious operational headaches. Can share a clear, actionable rundown directly. @MrMoyo_
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
A lot of startups are out here grinding for users but can’t handle one bad request without falling apart. Priorities are upside down.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
You don’t need a full security program. You just need to stop leaving open doors everywhere.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Ran a simple test and the app acted like I committed war crimes. I swear some systems can’t handle the slightest pressure.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
While interacting with Shuttlers’ signup flow, I noticed a critical authentication issue that could allow verification bypass and automated account abuse if left unchecked. Flagging this responsibly. @dammyoloke, happy to share details privately so it can be fixed quickly.
1
0
0
@Irethe_red
Ire Ogunsanya
1 month
Your product breaking under “weird behavior” isn’t an edge case. It’s a preview of your future breach.
0
0
1
@Irethe_red
Ire Ogunsanya
1 month
Founders underestimate attackers because they think everyone uses their product normally. Nobody does. Especially not attackers.
0
0
0
@Irethe_red
Ire Ogunsanya
1 month
Accidentally triggered a logic flaw today because I clicked too fast. That’s how fragile some workflows are.
0
0
0