Hi, I'm Dan Fabro. 👋

I am currently situated in the Philippines.

I'm working as a Senior Software QA Engineer. I'm also deeply passionate about information security, particularly in web and mobile application offensive security.

Been hunting and hacking since 2017 (mostly in private and external bug bounty programs), engaged in multiple CTF events, and participated in different hacking conferences.

In my free time, I enjoy playing computer games, Chess, reading books, mountaineering, cycling, and/or tinkering with electronics.

Education

Bachelor of Science in Computer Engineering, University of Science and Technology of the Southern Philippines | 2015 – 2020 | GWA: 1.9

  • Gold Medalist — Philippine National Skills Competition 2021 (Cybersecurity)
  • Third Place — DICT Hack4Gov: National Cyber Challenge 2019
  • President Ricardo Rotoras Outstanding Student Leadership Awardee (Kahamili)
  • Philippine's Department of Science and Technology Academic Scholar (2017–2020)
  • Constant Dean's Lister (2018–2020)
  • Vice President, Institute of Computer Engineers Student Edition (2017–2020)
  • Multiple guest speaker invitations related to Cybersecurity (2018–2024)

Acknowledgments

Found and reported valid security bugs in these companies and government agencies, there are others I can't disclose (yet):

Skillset

  • Web and Mobile Application Security Auditing
  • Software QA Testing (functional and non-functional)
  • Test Automation + AI Integration (Selenium, Cypress, and Playwright)
  • Project Management (Azure DevOps, Jira, ClickUp, Asana, Trello, Linear)
  • Technical Recruitment
  • Technical Report and Documentation
  • Web Application Development
  • AI Augmentation (Claude Code, MCPs, Webhooks)

Why this blog?

"Start a side project instead of a company. Write a blog post instead of a book. Lower the stakes to increase the odds."

Just to try things out. This internet corner of mine was inspired by the tech blogs created by some people in the information security community and also because of this article as well. Since I am genuinely interested in a broad range of topics, I also needed an avenue to review my thought process when hunting for security bugs and a medium that can act as a resource to the information security community.