Hi, I'm Connor Carro. I'm a high school student from Florida focused on cybersecurity and software development.
I've been programming since 2019, starting with Scratch, then Java, and now mainly Python. I've also been working on cybersecurity for the past 4 years.
I've competed in CyberPatriot's Cisco networking category for three years and finished #1 in Florida each year, top 10 nationally. In the 2026 National Cyber League team game I placed in the top 1.3%.
I'm looking for part-time and full-time opportunities in software development, cybersecurity, systems engineering, or networking.
- 8.2CVSS · HighFinancial account takeoverFortune 200 financial technology company. High-severity account takeover vulnerability affecting a developer platform.Details private
- LowCVSS 0.1-3.9Restricted RPC leaks alternative block hashesMonero. The restricted /get_alt_blocks_hashes endpoint leaked alternative block hashes to unauthorized callers.View report
- Secure Chat ApplicationFull-stack secure chat platform with authentication, friend requests, and real-time messaging. Built with a Node.js backend and custom frontend.
- Planet TrackerBackend pipeline for a real-time sky visualization app. Converts celestial data into device-aligned scene positions so motion tracks the sky.
- Christmas Route OptimizerRoute optimizer built for the 2025 Viera Bright Lights Battle. Generates fast driving routes from submitted addresses using OSRM and Google OR-Tools.
- LeafLightweight Java Swing text editor with local file editing, search tools, and a file tree. Includes editor status details and basic Java keyword highlighting.
Working with @int0ha_ has been a genuine pleasure. His reports are consistently well written and clearly communicated, and he pairs them with thoughtful, well-constructed PoC scripts that make his claims easy to verify. Beyond the technical quality, he's professional, friendly, and collaborative throughout as well as quick to respond, quick with informative retests, and refreshingly honest about the limits of his own findings. What set his work apart was the depth: he dug into how our system actually behaves, engaged with the business domain rather than just inputs and outputs, and repeatedly proposed sensible fixes alongside the bug. We welcome his reports any day.
Connor Carro identified and responsibly disclosed a High-severity (CVSS 8.2) account takeover vulnerability in one of our developer platforms through the HackerOne Vulnerability Disclosure Program. His report was exceptionally detailed and technically precise. It demonstrated a mature understanding of GraphQL security, authentication logic, and responsible disclosure best practices.
Throughout the more than one-year remediation process, Connor showed outstanding professionalism, patience, clear communication, and a genuine willingness to assist our team. He proactively provided corrected reproduction steps during retesting and remained respectful and collaborative even when updates were delayed.
Connor's contribution directly helped strengthen the security of our systems and protect our users. We are happy to strongly recommend him for technical internships and future roles in technology. He is a talented, ethical, and highly motivated security researcher and developer who will be an asset to any team fortunate enough to work with him.
