Profile

Mian

Security Researcher | Web Application Penetration Tester | Bug Bounty Hunter. I focus on finding practical web security issues, explaining them clearly, and turning messy application behavior into reproducible, high-impact reports.

Peshawar, Pakistan Location
5 years Hands-on security experience
Black Owlz CTF team leader
CWEE Currently studying

Contact

Reach Me

Skills

Core Skills

Web App Pentesting

Deep testing across authentication, authorization, access control, session handling, CSRF, cookies, account lockouts, service workers, file handling, business logic, and high-impact exploit chains.

Android Application Testing

Mobile app assessment covering API traffic, authentication flows, insecure storage, certificate pinning checks, exported components, and client-side logic review.

Cloud and AWS Security

AWS-focused review of exposed services, IAM permissions, S3/storage access, cloud configuration issues, metadata exposure, and cloud-hosted application attack surface.

Internal Network Testing

Internal assessment methodology including host discovery, Nmap scanning, service enumeration, SMB/HTTP/SSH review, misconfiguration checks, and privilege escalation paths.

Python Scripting

Automation and tooling for recon, request replay, content parsing, proof-of-concept development, and repeatable testing workflows.

Report Writing

Clear vulnerability reporting with business impact, root cause, reproduction steps, exploitability notes, screenshots, and practical remediation guidance.

Soft Skills

Team collaboration, instruction, communication, and organizing security work.

Client-Side Research

Browser behavior, SameSite cookie edge cases, service worker attack paths, JavaScript-heavy application testing, and DOM-driven security issues.

Security Stack

Burp Suite, browser DevTools, Linux, Python, JavaScript, headless browsers, custom scripts, and repeatable HTTP testing workflows.

Experience

Work

Education

Learning Path

Project

Headless Browser Parser

A headless browser tool for dynamic parsing of JavaScript-rendered content. Built to handle pages where static scraping falls short and the DOM only exists after scripts run.

Research

Notable Work

Research and writeups that show how I approach practical exploitation, root-cause analysis, and clear reporting.

Growth

Certifications & Focus

Black Owlz Team Leader

Manages collaboration and strategy for the CTF team.

CWEE Studying

Focused on advanced web exploitation, chaining bugs, and sharpening methodology for deeper application security work.

Current Learning Research track

Advanced web exploitation, browser internals, client-side attack surface, and exploit chaining.

CTF and Chess Player Interests

Competitive problem solving, strategy, and continuous practice.

Methodology

How I Test

Map the application

Understand roles, flows, trust boundaries, assets, state changes, and where business logic actually lives.

Break assumptions

Review auth, sessions, CSRF, access control, object ownership, state machines, email flows, and client-side behavior.

Prove impact

Build clear PoCs, chain issues when needed, document root cause, and write remediation-focused reports.

Languages

Languages

Urdu
English
Pashto