$ whoami
Passionate cyber security enthusiast — building tools, breaking apps,
and documenting the path from script kiddie to security professional.
$ cat ~/.motto
"True power lies in the ability to see what others cannot."🐛 Bug Bounty Contributions
Search Engine
Governments / Municipalities
Domain Providers
Hotel Chains
...
📒 Discover more about my related work in my blog articles.
🤝 CVE Contributions
CVE-2024-51490
CVE-2024-51486
CVE-2024-51489
CVE-2024-51380
CVE-2024-51381
...
Explore my full collection of CVEs in the CVE repository.
| ➜ Hacking Notes (RedTeam & BlueTeam) ⬅ | ➜ Roadmap to Hacking Mastery ⬅ |
|---|---|
| Unlock a wealth of hacking wisdom in my notes. Curated by seasoned experts, they offer concise insights into the world of cybersecurity. Perfect for beginners and veterans alike — dive in and elevate your hacking prowess today. | Discover the roadmap to hacking mastery. Whether you're a hobbyist, aspiring certifier, or degree seeker, our curated resources and structured paths will guide you. From networking basics to advanced penetration testing, cultivate the hacker mindset. |
| ➜ Note Taking - BurpSuite Obsidian Integration ⬅ | ➜ ClickMe - Multistep Clickjacking Tool ⬅ |
|---|---|
| Struggling with chaotic notes? Learn my effective note-taking system, including a specialized tool and structured methodology, designed to enhance productivity and collaboration. | ClickMe is a powerful multi-step clickjacking tool designed for security professionals. Create, visualize, and demonstrate complex clickjacking attacks with customizable elements and real-time preview. |
| Tool | Description | |
|---|---|---|
| 🖱 | ClickMe | Multi-step clickjacking POC framework |
| 🧬 | HR-Smuggler | HTTP request smuggling detection (HTTP/1.1 & HTTP/2) |
| 🌐 | Subdomain-Takeover | Subdomain enumeration & takeover detection |
| 🕸 | Wayback-Crawler | Async subdomain discovery via Wayback + CT logs |
| 🔎 | Endpoint-JS-Explorer | Bookmarklet to extract endpoints from JS |
| 💤 | lazy-js | Extract lazy-loaded filenames from webpack maps |
| 🔑 | JWT | Chrome extension for JWT security testing |
| 🧩 | Extensions | Curated Chrome extensions for hackers |
| 🔖 | Bookmarks | Curated hacker bookmark collection |
| Guide | Description | |
|---|---|---|
| 🗺 | Hacker-Roadmap | The complete path from beginner to pro |
| 🟠 | BSCP | Burp Suite Certified Practitioner exam guidance |
| 🔴 | RedTeam | Offensive security notes |
| 🔷 | BlueTeam | Defensive security notes |
| 🧾 | CVE | Documented CVE research |

