Profile
Mian
Security Researcher | Web Application Penetration Tester | Bug Bounty Hunter. I focus on finding practical web security issues, explaining them clearly, and turning messy application behavior into reproducible, high-impact reports.
Contact
Reach Me
Skills
Core Skills
Deep testing across authentication, authorization, access control, session handling, CSRF, cookies, account lockouts, service workers, file handling, business logic, and high-impact exploit chains.
Mobile app assessment covering API traffic, authentication flows, insecure storage, certificate pinning checks, exported components, and client-side logic review.
AWS-focused review of exposed services, IAM permissions, S3/storage access, cloud configuration issues, metadata exposure, and cloud-hosted application attack surface.
Internal assessment methodology including host discovery, Nmap scanning, service enumeration, SMB/HTTP/SSH review, misconfiguration checks, and privilege escalation paths.
Automation and tooling for recon, request replay, content parsing, proof-of-concept development, and repeatable testing workflows.
Clear vulnerability reporting with business impact, root cause, reproduction steps, exploitability notes, screenshots, and practical remediation guidance.
Team collaboration, instruction, communication, and organizing security work.
Browser behavior, SameSite cookie edge cases, service worker attack paths, JavaScript-heavy application testing, and DOM-driven security issues.
Burp Suite, browser DevTools, Linux, Python, JavaScript, headless browsers, custom scripts, and repeatable HTTP testing workflows.
Experience
Work
Gave speeches and talks with the team at University of Peshawar and helped develop the core course structure with labs.
Pentester Secure Purple / CurrentWeb application penetration tester working on practical assessment, vulnerability discovery, reporting, and client-focused remediation guidance.
Pentester BlackByt3 / Peshawar / 1 yearPentester with the team, offensive team organizer, CTF team lead, and labs instructor.
Education
Learning Path
Project
Headless Browser Parser
A headless browser tool for dynamic parsing of JavaScript-rendered content. Built to handle pages where static scraping falls short and the DOM only exists after scripts run.
Research
Notable Work
Research and writeups that show how I approach practical exploitation, root-cause analysis, and clear reporting.
Investigated SameSite cookie behavior, service worker edge cases, and how browser mechanics can create unexpected attack paths.
Trusted mail relay abuse Business logicExplored how platform trust assumptions can turn normal send flows into abuse primitives.
Account lockout logic DoS / business logicStudied account lockout behavior and how defensive workflows can become user-impacting vulnerabilities.
Growth
Certifications & Focus
Manages collaboration and strategy for the CTF team.
Focused on advanced web exploitation, chaining bugs, and sharpening methodology for deeper application security work.
Advanced web exploitation, browser internals, client-side attack surface, and exploit chaining.
Competitive problem solving, strategy, and continuous practice.
Methodology
How I Test
Understand roles, flows, trust boundaries, assets, state changes, and where business logic actually lives.
Review auth, sessions, CSRF, access control, object ownership, state machines, email flows, and client-side behavior.
Build clear PoCs, chain issues when needed, document root cause, and write remediation-focused reports.
Languages