web app security and pentesting — learning through labs, writeups, and building tools.
- SQLi, IDOR, SSRF, XSS, and path traversal
- offensive Python and HTTP internals
- proxies, raw sockets, and web security labs
- http-proxy-lab — wrote a full HTTP proxy from raw sockets with zero frameworks, just to see if I actually understood HTTP. turns out I did — right down to the attack surface I built into it myself.
- dir-brute — a multithreaded directory brute-forcer and crawler. finds hidden paths from a wordlist, filters by status code, keeps crawling. my most used tool.
- pentools — port scanner, hash cracker, PDF password auditor, and a blind SQLi extractor that exploits a PortSwigger lab condition-by-condition.
- 85+ TryHackMe rooms — Pre-Security, Cyber Security 101, Jr Penetration Tester path
- 34 PortSwigger labs across Access Control, SQLi, XSS, SSRF, and Path Traversal, with writeups for each
- 10 documented labs on DVWA, WebGoat, and Metasploitable 2 — 4 CVEs exploited with Metasploit
DOM XSS, API security, JWTs, and better pentesting methodology. don't care much for certs without reps behind them.
web app pentesting / appsec internships — VAPT roles and bug bounty are all welcome. if we talk, ask me to walk through my tools or solve a lab live; that's a better interview than telling you im passionate.
