Thanks to visit codestin.com
Credit goes to dimasc.tf

Skip to content

All corners ↑

DENPASAR, BALI / AN OPEN DOOR

Dimas
Maulana.

Security researcher. Open-source builder.
Founder of TCP1P.

Dimas’ illustrated avatar
Research. Build. Share.A personal space, from Bali.

PICK A CORNER, OR KEEP SCROLLING

A little room.
A bigger world.

02 / THE WORKBENCH

Tools, experiments,
and shared work.

Tools to remove friction, labs to learn from, and things built with a community.

3 closer looks · 9 projects in the collection

Security monitoring · personal projectVWA-Wazuh (Mini Lab SOC)A practice lab that connects web applications with security monitoring.
The problem
Learning an application and learning its monitoring stack often happen separately.
My work
A containerized lab integrating four practice web apps with Wazuh and Discord alerts.
The result
A reusable local environment for exploring applications alongside a monitoring dashboard.

Mar 2023 - Present

Wazuh dashboard screenshot from the project README.
Wazuh dashboard screenshot from the project README.
  • Security
  • Wazuh
  • IDS
  • Database Security
Source & documentation on GitHub ↗
CLI tooling · personal projectCTFIFYFind, download, and organize challenges from the terminal.
The problem
Competition files and challenge discovery can interrupt the work itself.
My work
A Go command-line tool with challenge search by name, category, or tag, plus local downloads.
The result
An open-source workflow for finding and managing CTF challenges in one place.

Jan 2023 - Present

Repository README preview — documentation, not a running terminal session.
Repository README preview — documentation, not a running terminal session.
  • CTF
  • Go
  • CLI
Source & documentation on GitHub ↗
Competition UI · TCP1P team projectTCP1P ThemeA recognizable front door for a community-run competition.
The problem
A CTF platform needs an identity that feels like the community running it.
The contribution
CTFd theme work within TCP1P, extending the existing core-beta theme.
The result
An open-source TCP1P-branded interface. This is team work built on CTFd, not a platform built from scratch.

Nov 2023 - Present · TCP1P

TCP1P Theme homepage preview from the project repository.
TCP1P Theme homepage preview from the project repository.
  • HTML
  • Python
  • Jinja
  • Bootstrap
Source & documentation on GitHub ↗
6 more projects · the full workbench
CTF-XSS-BOTCTF · XSS

CTF-XSS-BOT

Craft engaging XSS challenges effortlessly with CTF-XSS-BOT. This template simplifies setting up an environment for Capture The Flag competitions.

  • CTF
  • XSS
  • Puppeteer
  • Containerization

Aug 2023 - Present

Explore CTF-XSS-BOT on GitHub ↗
Dockerized Wordpress Debug SetupDocker · Containerization

Dockerized Wordpress Debug Setup

A Dockerized WordPress development environment with two configurations, one using Nginx and the other using Apache. Includes Xdebug for debugging.

  • Docker
  • Containerization
  • PHP
  • WordPress

Dec 2023 - Present

Explore Dockerized Wordpress Debug Setup on GitHub ↗
CTF Challenge Difficulty CalculatorCTF · Next.js

CTF Challenge Difficulty Calculator

A Next.js program designed to assess the difficulty of a Capture The Flag (CTF) challenge more efficiently.

  • CTF
  • Next.js
  • JavaScript

Nov 2023 - Present

Explore CTF Challenge Difficulty Calculator on GitHub ↗
CTF AssistantJavaScript · Discord

CTF Assistant

Discord bot for managing CTF written in Bun programming language.

  • JavaScript
  • Discord
  • TypeScript
  • Databases

Oct 2022 - Present

Explore CTF Assistant on GitHub ↗
Paradigmctf BlockChain Infra ExtendedSolidity · Python

Paradigmctf BlockChain Infra Extended

Setup from Paradigm CTF blockchain challenges with new features, including a web interface and additional challenge setup.

  • Solidity
  • Python
  • Blockchain

Nov 2023 - Present · TCP1P

Explore Paradigmctf BlockChain Infra Extended on GitHub ↗
Cyber-Security-Learning-ResourcesLearning · Cybersecurity

Cyber-Security-Learning-Resources

Material untuk belajar Cyber Security.

  • Learning
  • Cybersecurity
  • Resources

Mar 2022 - Present

Explore Cyber-Security-Learning-Resources on GitHub ↗
Everything on GitHub ↗

03 / THE NOTEBOOK

Leave the
notebook open.

Competition writeups and the references I keep within reach.

Browse the complete writing library

Blog posts

Field notes

04 / THE PHOTO WALL

The people
behind the flags.

From Bali to Vietnam and China. A few moments with the people behind the work.

Project Sekai holding the 5,000 USD prize check at the Security Analyst Summit CTF 2024 finals in Bali
SAS CTF 2024 Security Analyst Summit finals in Bali, a 5,000 USD win with Project Sekai.

1 / 7 · SAS CTF 2024

7 MOMENTS / 5 TEAMS

The teams behind the memories

More about the teams

P1G SEKAI ↗

Member

A merging of Project Sekai and r3kapig

  • Web Security
  • Binary Exploitation
  • Cryptography
  • Forensics
  • Reverse Engineering
  • Blockchain
  • OSINT
  • Mobile Security

Project Sekai ↗

Member

SEKAI{I5_A_CTF_t3Am_w/_38+_mbRs,_p4r71CiP4t1ng_in_164+_c0nt3Stz}

  • Web Security
  • Binary Exploitation
  • Cryptography
  • Forensics
  • Reverse Engineering
  • Blockchain
  • OSINT
  • Mobile Security

TCP1P ↗

Founder

Indonesia's #1 nationally ranked CTF community on CTFtime. We organize internationally rated events (TCP1P CTF 2023 & 2024, sponsored by OffSec, Ottersec, and Google SecLab Indonesia) and maintain open-source CTF infrastructure.

  • Web Security
  • Binary Exploitation
  • Cryptography
  • Forensics
  • Reverse Engineering
  • Blockchain
  • OSINT
  • Mobile Security

SKSD ↗

Member

Indonesian CTF Team that rarely participate in CTF competitions in 2025

  • Web Security
  • Binary Exploitation
  • Cryptography
  • Forensics
  • Reverse Engineering
  • Blockchain
  • OSINT
  • Mobile Security

HCS ↗

Member

CTF Team from ITS, often participate in CTF competitions on CTFTime

  • Web Security
  • Binary Exploitation
  • Cryptography
  • Forensics
  • Reverse Engineering
  • Blockchain
  • OSINT
  • Mobile Security

05 / THE TROPHY SHELF

Every award.
A story behind it.

Individual competition, team finals, and research recognition. Different parts of the same journey.

8first-place results21recorded results

Team scoreboards verify team results; entries without a source are labelled as portfolio records.

  1. 1st Place

    XCTF 2025 Professional Division

    Individual · November 2025

    XCTF

    Portfolio archive · public source not yet linked

  2. 2nd Place

    ISITDTU CTF 2024 Finals Attack & Defense

    Project Sekai · December 2024

    ISITDTU

    CTFtime team scoreboard ↗
  3. 1st Place

    Patchstack February 2025 Bug Bounty Program

    Individual · February 2025

    Patchstack

    Portfolio archive · public source not yet linked

The rest of the record · 18 results
  1. 1st Place

    idekCTF 2024

    P1G SEKAI · August 2024

    Team results archive ↗
  2. 1st Place

    Backdoor CTF 2024

    Ada Indonesia Coy · December 2024

    Portfolio archive · public source not yet linked

  3. 1st Place

    Cyber Jawara International 2024

    TCP1P x SNI x MAGER · October 2024

    Portfolio archive · public source not yet linked

  4. 1st Place

    Seleknas Cyber Security 2024

    Team · November 2024

    KEMNAKER

    Portfolio archive · public source not yet linked

  5. 1st Place

    NCW 2023

    TEAM · December 2023

    PETIR Cyber Security

    Portfolio archive · public source not yet linked

  6. 1st Place

    WorldSkills ASEAN Cyber Security 2024 · National & Regional Selection

    Individual · 2024

    WorldSkills

    Portfolio archive · public source not yet linked

  7. 2nd Place

    TPCTF 2025

    Project Sekai · March 2025

    CTFtime team scoreboard ↗
  8. 2nd Place

    Patchstack Alliance CTF S02E01 - WordCamp Asia

    Individual · February 2025

    Patchstack

    Portfolio archive · public source not yet linked

  9. 2nd Place

    THE SAS CON CTF 2024

    P1G SEKAI · October 2024

    KASPERSKY

    Team results archive ↗
  10. 2nd Place

    Patchstack End-of-Year Alliance CTF 2025

    Individual · December 2025

    Patchstack

    Portfolio archive · public source not yet linked

  11. 2nd Place

    Patchstack Alliance CTF S01E01

    Individual · 2024

    Patchstack

    Portfolio archive · public source not yet linked

  12. 2nd Place

    WRECKIT 5.0

    Team · 2024

    Portfolio archive · public source not yet linked

  13. 2nd Place

    CTF ARA 5.0 2024

    Team · 2024

    Portfolio archive · public source not yet linked

  14. 2nd Place

    Patchstack January 2024 Bug Bounty

    Individual · January 2024

    Patchstack

    Portfolio archive · public source not yet linked

  15. 3rd Place

    AlpacaHack Round 2 (Web)

    Individual · 2024

    Portfolio archive · public source not yet linked

  16. 3rd Place

    Patchstack WCUS CTF 2024

    Individual · 2024

    Patchstack

    Portfolio archive · public source not yet linked

  17. 3rd Place

    Cyber Jawara International 2023

    Team · 2023

    Portfolio archive · public source not yet linked

  18. 3rd Place

    Patchstack February 2024 Bug Bounty

    Individual · February 2024

    Patchstack

    Portfolio archive · public source not yet linked

Meet the teams ↗

06 / THE BOOKSHELF

Always adding
to the toolkit.

Learned by building, researching, and sharing.

Offensive Security

Penetration Testing · Web Exploitation · Vulnerability Research

Programming

Python · Go · JavaScript

Security Automation

AI-assisted Vulnerability Triage · CVE-hunting Tooling · Custom Exploit Scripts

Cloud & Infrastructure

AWS · Docker · Kubernetes

Certifications

Certified AppSec Pentester (CAPen) · with Merit · CompTIA Linux+ ce

Complete toolkit & credentials

Offensive Security

  • Penetration Testing
  • Web Exploitation
  • Vulnerability Research
  • Exploit Development
  • Reverse Engineering
  • Binary Exploitation
  • CVE Discovery
  • Secure Code Review
  • SAST & DAST

Programming

  • Python
  • Go
  • JavaScript
  • TypeScript
  • PHP
  • Solidity
  • Bash

Security Automation

  • AI-assisted Vulnerability Triage
  • CVE-hunting Tooling
  • Custom Exploit Scripts

Cloud & Infrastructure

  • AWS
  • Docker
  • Kubernetes
  • HashiCorp Nomad
  • CI/CD
  • Linux Administration
  • Wazuh (SIEM/IDS)

Certifications

  • Certified AppSec Pentester (CAPen) · with Merit
  • CompTIA Linux+ ce

07 / THE STORY WALL

The person
behind the desk.

Based in Denpasar, Bali. Turning research into tools, training, and community.

6 roles · Research, engineering, training & community

Patchstack Alliance2024 - Present · Security Researcher · Bug Bounty

Security Researcher · Bug Bounty

2024 - Present · Remote · Freelance

Reported 170+ validated WordPress CVEs across plugins and themes, including CVE-2025-26909 (CVSS 9.6), a critical LFI-to-RCE flaw in WP Ghost affecting 200,000+ sites. Built AI-assisted tooling to accelerate CVE hunting across large plugin codebases.

  • Vulnerability Research
  • WordPress Security
  • CVE Discovery
  • AI Tooling
HackTheBox2025 - Present · Content Creator (Outsourced)

Content Creator (Outsourced)

2025 - Present · Remote · Outsourced

Develop original security training content and challenges for the HackTheBox platform as an outsourced contributor.

  • Challenge Design
  • Training Content
  • Web Security
ArchonLabs SSDAug 2025 - Jan 2026 · DevSecOps Intern

DevSecOps Intern

Aug 2025 - Jan 2026 · Jakarta · Remote

Built container automation with HashiCorp Nomad to orchestrate containerized workflows, and helped secure and harden container-based deployments.

  • HashiCorp Nomad
  • Container Security
  • DevSecOps
TCP1PAug 2022 - Present · Founder & Infrastructure Engineer

Founder & Infrastructure Engineer

Aug 2022 - Present · Indonesia

Founded and lead TCP1P, Indonesia's #1 nationally ranked CTF team on CTFtime (top 6 every year since 2022). Organized TCP1P CTF 2023 and 2024, internationally rated events sponsored by OffSec, Ottersec, and Google SecLab Indonesia.

  • Leadership
  • CTF Infrastructure
  • Community
  • Event Organizing
Visit TCP1P ↗
C2C & Cyber JawaraDec 2025 - Feb 2026 · Cloud Engineer & Challenge Author

Cloud Engineer & Challenge Author

Dec 2025 - Feb 2026 · Indonesia · Contract

Engineered and operated cloud-based CTF infrastructure and authored challenges for two of Indonesia's national cybersecurity competitions.

  • Cloud Infrastructure
  • Challenge Design
  • CTF
Project Sekai · IntechFest · TECHCOMFEST · HOLOGY2022 - 2026 · Challenge Author & Infrastructure Engineer

Challenge Author & Infrastructure Engineer

2022 - 2026 · Remote · Freelance

Authored web exploitation challenges for Project Sekai CTF, an internationally recognized competition, and designed challenges and deployment infrastructure for national events across multiple annual editions.

  • Web Security
  • Challenge Design
  • Infrastructure
CREDITED RESEARCHCVE-2025-26909

WP Ghost · CVSS 9.6 · Published March 2025

Read the credited advisory ↗Researcher profile & reports ↗
More about me

I'm a security researcher and award-winning competitive hacker based in Denpasar, Bali, Indonesia. I've discovered 170+ CVEs in widely used software, including CVE-2025-26909, a critical flaw that affected 200,000+ WordPress sites.

I founded @TCP1P , Indonesia's #1 nationally ranked CTF team on CTFtime, and compete internationally with @project-sekai-ctf as well as the SKSD and HCS teams.

I enjoy creating CTF challenges, developing security tools, and sharing what I learn through writeups and tutorials on my blog.

08 / THE REVIEW FOLDER

Source code review.
Clear, useful fixes.

I run AI-assisted reviews over real codebases, triage the bugs that are actually exploitable, and hand back ready-to-merge fixes with a plain-English report.

Starting at$99per project · about Rp 1.780.000
  • AI reviews your code, I triage what's real
  • Potential vulnerabilities, exploitable ones flagged
  • Dynamic checks that the program still works
  • Suggested, ready-to-merge fixes in a plain report

Usually 1–2 days when available · One free re-test

Let’s scope a review ↗
What’s included, process & common questions

How it works

1. Share your code

Send a private GitHub or GitLab invite, or just zip it up and email it over. NDA on request.

2. Review and run

An AI agent reviews your codebase for potential vulnerabilities, and I run the program to check it behaves correctly. I triage the results and flag the ones that are actually exploitable.

3. Report and fixes

You get a plain-English report in PDF and Markdown, with a suggested fix for every finding.

What you get

  • Your whole codebase reviewed by an AI agent
  • Potential vulnerabilities surfaced, with the genuinely exploitable ones flagged
  • Dynamic checks that the program runs and works correctly
  • A suggested, ready-to-merge fix for each finding
  • One free re-test after you apply the fixes

Scope and limits

  • Static code review plus dynamic checks that the program runs correctly
  • No live production or infrastructure penetration testing
  • Languages: JavaScript and TypeScript, Python, PHP, Go, and most web backends
  • Turnaround is usually 1 to 2 days when I'm not busy
  • Patches are provided as-is, so test before you deploy

Your code stays private

I review your code in an isolated workspace, never share it, and delete it after delivery on request. NDA available on request. Send a private repository invite or a zip over email.

Questions

Is this just an automated scanner?
It is AI-driven, but I triage every finding by hand and tell you which are actually exploitable, which are only potential, and which are just hardening. You get a reviewed report, not a raw tool dump.
What if you don't find anything?
You still get a report of everything the review checked, plus hardening notes. I won't pad it with findings that are not real.
Which languages do you cover?
JavaScript and TypeScript, Python, PHP, Go, and most web backends. Ask if yours is not listed.
How do I send my code?
A private GitHub or GitLab invite works best, but a plain zip over email is fine too. Whatever is easiest for you.
How does payment work?
We agree on the scope and price first, then you pay by bank transfer or your preferred method before I start.
Service details & demo ↗

09 / BACK HOME

There’s room for
one more story.

Research, a project, or a simple hello. Tell me what you have in mind.

[email protected] Services & pricing ↑

Thanks for stopping by.