Bug Bounty Training · Live Cohorts

RV_U

OFFENSIVE SECURITY & BUG BOUNTY

A hands-on, live bug bounty training — taught by a researcher who actively hunts on real programs, not someone reciting tutorials.

Change one number in a URL, and see what you're not supposed to see. That's the first lesson: IDOR and Broken Access Control, taught by finding them live.

3+Years active
IDOR · BACSpecialization
JDLaw background
GET /api/v1/invoices/4471
#4471
200 OK — your own data
The server returned another account's data — with no check that this ID actually belongs to you. That's a textbook Broken Access Control finding, the kind we hunt for in the course.
02 / Where I Hunt

Real programs, not a demo environment

These are programs and platforms I'm actively working on. The techniques taught in the course are the same ones applied here.

$ cat active_targets.log
target.01

Bentley Systems

IDOR · BAC focus
target.02

Exoscale

API recon
target.03

Kube-DC

Business logic
target.04

Thüringer Aufbaubank

IDOR candidate
Intigriti YesWeHack Independent disclosure
03 / Fit Check

Is this training for you?

A good fit if you:

  • Want to start in offensive security the right way
  • Are beginner-to-intermediate and want a real, structured path
  • Want to actually understand IDOR, BAC and business logic — not just watch a demo
  • Want to learn from someone who is still hunting, not just teaching

Not a good fit if you:

  • Are looking for a shortcut with no effort
  • Don't have time to practice between sessions
  • Expect results overnight
  • Just want a certificate to hang on a wall
04 / About the Instructor

Meet Ramez Medhat

Before investing in any training, you should know who's behind it.

CRITICAL

3+ years hunting, actively

Working real programs on Intigriti and YesWeHack right now — not a dormant profile.

HIGH

Deep, not broad

IDOR, Broken Access Control and Business Logic are the core focus, with a strong lean toward API reconnaissance.

MEDIUM

Law background

A law degree means the ethical and legal boundaries of hacking are taught properly, not glossed over.

about.json

Ramez Medhat is an active bug bounty researcher and cybersecurity practitioner, specialized in identifying and reporting Insecure Direct Object References, Broken Access Control and business logic flaws through structured API reconnaissance.

Alongside hunting, he builds his own tooling — including a recon methodology tool and an Android companion app — rather than relying only on off-the-shelf scanners. This course is built on the same methodology he uses day to day.

05 / What You Get

A live, 6-week curriculum

6 weeks, 12 live sessions, built for beginner-to-intermediate hunters who want a real, structured path.

$ cat curriculum.json
module.01

Recon

Target discovery & hidden endpoint mapping

module.02

API

Practical API testing

module.03

IDOR

Broken Access Control hunting, step by step

module.04

Logic

Business logic flaws scanners miss

module.05

Report

Writing a report & PoC that gets triaged

module.06

Legal

Ethical hacking boundaries & cybercrime law

Live sessions are delivered in Arabic — 6 weeks / 12 sessions.
06 / Toolkit

Not just teaching — this is what I actually run

// reconforge.html

ReconForge

A single-file recon dork tool with severity badges and a guided review mode — the same methodology applied in live hunts.

// rv_u.apk

RV_U Methodology

An Android companion app (Jetpack Compose + Room) that structures the hunting workflow from recon to report — built for personal use first.

07 / FAQ

Frequently asked questions

01Do I need prior experience?+
No. The course is built for beginner-to-intermediate hunters, starting from fundamentals and building up to IDOR, BAC and business logic hunting. The only real requirement is willingness to practice.
02What language is it taught in?+
Live sessions are delivered in Arabic, over 6 weeks and 12 sessions.
03What will I actually learn?+
Recon methodology, practical API testing, IDOR and Broken Access Control hunting, business logic flaws, writing a convincing PoC and report, and the legal boundaries of ethical hacking.
04Is Ramez actively hunting, or just teaching?+
Actively hunting — on Intigriti and YesWeHack, on real programs. The course is built directly on that ongoing work.
05How do I join, and what does it cost?+
Each cohort has limited seats to keep the mentorship real. Get in touch for current pricing and the next cohort's dates.
08 / Join

If you want to get into this field the right way

Next cohort

Reserve your seat

6 weeks
12 live sessions
Limited seats