I’m a cybersecurity enthusiast on a mission to keep applications safe from the bad guys (Bad Actor / Threat). I’ve got my hands in a bunch of different areas like UI/UX design, CTFs, red team tool development, web development, and freelancing. I’ve also tackled a bunch of major projects for students, helping them out with web dev and cybersec stuff. Always up for a new challenge and ready to dive into the next adventure!
EXPERIENCE
2023 June - 2023 July [ 45 days ]
Cybersecurity research intern
Secure Cyber Future
I had the awesome opportunity to dive into a client’s domain and hunt for security vulnerabilities. It was an exciting and educational journey that really leveled up my skills.
Here’s the scoop on what I found:
Cross-Site Scripting (XSS): I uncovered both reflected and stored XSS vulnerabilities. These could let sneaky attackers inject malicious scripts, potentially messing with user data and the app’s overall security.
SQL Injection (SQLi): I spotted several SQL injection points. These vulnerabilities could allow attackers to tamper with the database, leading to unauthorized data access and potential breaches.
CORS Misconfigurations: I found some issues with Cross-Origin Resource Sharing (CORS). These misconfigurations could let unauthorized domains access the app, posing a serious security risk.
Information Disclosure: I stumbled upon files that leaked sensitive data. This exposed info could be used by attackers to get insights into the app’s structure and user data.
2023 July - 2023 August [ 1 Month ]
Anti-Pishing Intern
Beffoji NGO
I dove deep into the world of phishing emails and live websites. I actively hunted down various forms of phishing attempts and reported them consistently. Not only was this a thrilling experience, but it also felt great knowing I was helping to make the internet a safer place for everyone.