$ whoami

Hi, I'm Yuda

SOFTWARE DEVELOPER

Software Developer & Cybersecurity Enthusiast. Building secure, performant web experiences and exploring the offensive side of security.

// about_me

Behind the keyboard.

> Builder by day. Breaker by night.

I'm a final-year IT student who already works full-time in IT at Astra Infra Toll Road (Tangerang-Merak) — managing real systems while finishing my degree. Outside of work, I build web apps with the modern Next.js + React stack, dive into CTFs, and read security write-ups for fun. I like things that work — and understanding why they break.

Final-year IT StudentBased in Serang, IDCTF CuriousAlways learningCoffee fueled
about.ts

// Who's behind the keyboard?

const yuda = {

role: ["Software Dev", "Cybersec Enthusiast"],

location: "Serang, Indonesia",

stack: ["Next.js", "React", "Python"],

learning: ["Web Security", "Pentesting Basics"],

currently: "Building internal tools @ Astra Infra Toll Road (Tangerang - Merak)",

fuel: "Coffee & curiosity",

};

// tech_stack

Tools of the trade.

The stack I reach for when building, and the gear I run when breaking. Nothing exotic — just tools I've put real hours into.

>Frontend

React
Next.js
TypeScript
Tailwind

>Languages & Backend

Python
JavaScript
Node.js
PostgreSQL

>Tools

Git
GitHub
Docker

>Security

Linux
Burp Suite
Parrot OS

// projects

Things I've built.

A mix of shipped work, side projects, and security writeups. Hover the cards to inspect them — literally.

SIPATROL

Featured

Production internal ticketing system used by Astra Infra Solutions ops team. Built with hybrid 2-layer auth (NextAuth v5 + Prisma on Edge runtime), WhatsApp notifications via Fonnte API, server-side Excel report generation, and automated image compression with Sharp.

Next.jsPostgreSQLPrismaNextAuth v5Fonnte API

yuda.dev

This portfolio site. Built with Next.js 16, React 19, Tailwind 4, and a custom DecryptedText animation. Server components by default, client components only where needed.

Next.jsReactTypeScriptTailwind

Burp Suite Practitioner Track

Self-directed learning track on PortSwigger Web Security Academy — working toward Burp Suite Certified Practitioner. Currently 50% through the Web Cache Deception path, with focus on SQL injection and authentication flaws. Learning by breaking, one lab at a time.

Burp SuitePortSwiggerWeb SecurityOWASP

// cybersec

When I'm not building, I'm breaking.

Security started as curiosity and stuck around as a habit. Most weekends I'm grinding PortSwigger labs, dissecting writeups, or breaking sandboxed apps so I don't break things at work.

~/cybersec

yuda@parrot:~$ whoami

Yuda — cybersecurity enthusiast, web pentest student, builder.

yuda@parrot:~$ cat focus.txt

  • - Web Application Security
  • - Authentication & Session Flaws
  • - SQL Injection & Web Cache Deception
  • - OWASP Top 10

yuda@parrot:~$ ls platforms/

portswigger/ hackthebox/ tryhackme/

yuda@parrot:~$ history | tail

  • Working through Burp Suite Practitioner Track — 50% Web Cache Deception path
  • Reading security writeups & docs — PortSwigger, HackTricks, OWASP
  • Building secure web apps by day, breaking them in labs by night

yuda@parrot:~$

// contact

Open to collaboration, freelance, or just a chat about web, security, or anything in between. My inbox is open — drop a line and I'll get back to you.

> Response time: usually within 24h.