Skip to content
View MHuzaifaJamil's full-sized avatar

Highlights

  • Pro

Block or report MHuzaifaJamil

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
MHuzaifaJamil/README.md

Surah Al-Anfal, Ayah 60

Muhammad Huzaifa Jamil

Live feed ticker

"(¥83|* 53(|_||*17¥ 3|\|&1|\|33|* ₩17# 4 50|=7₩4|*3 3|\|&1|\|33|*1|\|& |=0|_||\||)4710|\|"

{Ask AI to Decode this symbol-based leetspeak cipher into plain English}


About Me

> cat about_me.txt
  • 🔐 Cyber Security Engineer at Virtuosoft, Karachi — running full-scope VAPT engagements, PCI DSS compliance consultancy, and multi-cloud security audits for OTT, e-commerce, and NGO platforms.
  • 🎯 Executed VAPT across 400+ in-scope hosts & API endpoints, surfaced 450+ findings (140+ Critical/High), mapped to OWASP & CIS Controls.
  • 📋 Led PCI DSS gap analyses against ISO/IEC 27001, NIST CSF, SOC 1/2, and HIPAA, remediating 10+ core compliance gaps and executing 200+ validation re-tests.
  • 🕵️ Independent bug bounty hunter on HackerOne & Bugcrowd — 30+ vulnerabilities responsibly disclosed (CORS, BOLA, PII leakage, exposed API keys).
  • 🤖 Building Mugheeraat — an air-gapped, privacy-first autonomous Agentic VAPT lab orchestrating 6 quantized open-weight LLMs entirely offline on 16GB RAM.
  • 🎓 B.E. Software Engineering, NED University of Engineering & Technology.
  • 🕌 Actively studying for CEH, CISA & CISM — pairing offensive tradecraft with enterprise-grade governance.

Featured: Vulnerability PoC & Exploit Portfolio

22 proof-of-concept write-ups across 5 industry verticals — click to expand

A curated collection of 22 proof-of-concept write-ups distilled from real, authorized engagements — every issue documented has already been remediated by the affected organization. Targets, identifiers, and figures are generalized/fictionalized; the focus is the vulnerability mechanism, not any specific system. Organized across 5 industry verticals:

Sector PoCs Highlights
📺 Streaming Platforms 9 BOLA mass PII enumeration, hardcoded client-side crypto keys, QR session fixation → ATO, XML-RPC brute-force
🛒 E-Commerce 6 NoSQL operator injection, unauthenticated Firebase RTDB, payment-webhook forgery, IAM realm confusion
✈️ Travel & Tourism 3 Unauthenticated Kubernetes dashboard (full secret disclosure), BFLA booking void, IDOR guest PII enumeration
🏛️ Government Agencies 2 Service-descriptor leak → search-index injection, pre-auth deserialization code path
🤝 NGOs / Non-Profit 2 Production debug-mode RCE preconditions, client-suppliable role → super-admin privilege escalation

📄 Read the full portfolio (PDF) →

📺 Streaming Platforms

  • MHJ-POC-01 — Broken Object-Level Authorization (BOLA) — Mass PII Enumeration
  • MHJ-POC-02 — Client-Side Hardcoded Cryptographic Key — Transaction Integrity Forgery
  • MHJ-POC-03 — Unverified JWT Client-Side Decode — Business Logic / Score State Manipulation
  • MHJ-POC-04 — QR-Code Session Fixation — Full Account Takeover
  • MHJ-POC-11 — CORS Misconfiguration (Reflected Origin + Credentials) — Cross-Origin Session Hijack
  • MHJ-POC-12 — Business Logic Flaw — Unbounded Negative-Value Integer Manipulation
  • MHJ-POC-13 — Broken Function-Level Authorization (BFLA) — Unauthorized Administrative Write Access
  • MHJ-POC-15 — Unauthenticated Observability Endpoint — Infrastructure & Internal Topology Disclosure
  • MHJ-POC-16 — XML-RPC Multicall Brute-Force — Authentication Rate-Limit Bypass

🛒 E-Commerce

  • MHJ-POC-05 — NoSQL Operator Injection via OTP/Phone Field
  • MHJ-POC-06 — Unauthenticated Firebase Realtime DB — Plaintext Credential Disclosure
  • MHJ-POC-07 — Payment Gateway Callback — Missing Signature Verification
  • MHJ-POC-08 — IAM Realm/Role Confusion — Privileged JWT Issuance
  • MHJ-POC-09 — Systemic Guest-JWT Authorization Bypass — Internal Business Data Disclosure
  • MHJ-POC-10 — Unauthenticated S3 Pre-Signed URL Generation — Arbitrary File Upload

✈️ Travel & Tourism

  • MHJ-POC-17 — Unauthenticated Kubernetes Dashboard — Full Cluster Secret Disclosure
  • MHJ-POC-18 — BFLA — Unauthorized Booking Void via Role-Unchecked Endpoint
  • MHJ-POC-19 — IDOR — Sequential Reservation ID Enumeration Exposes Traveler PII

🏛️ Government Agencies

  • MHJ-POC-20 — Unauthenticated Service Descriptor Disclosure → Backend Search-Index Injection
  • MHJ-POC-21 — Unauthenticated Admin UI Handler — Pre-Auth Deserialization Code Path

🤝 NGOs / Non-Profit

  • MHJ-POC-14 — Debug Mode Enabled in Production — Remote Code Execution Preconditions
  • MHJ-POC-22 — Privilege Escalation to Super-Admin via Client-Suppliable Role Parameter

Certifications — Earned

Certification Issuer Status
Certified in Cybersecurity (CC) ISC2 ✅ Earned — 2025
Introduction to Critical Infrastructure Protection (ICIP) OPSWAT Academy ✅ Earned — 2026
Certified Ethical Hacker (CEH) EC-Council 🟡 In Training (NAVTTC @ PAF KIET) — Expected Nov 2026
Certified Information Systems Auditor (CISA) ISACA 🟡 In Training (3D Educators) — Expected Nov 2026
Certified Information Security Manager (CISM) ISACA 🟡 In Progress — Expected Jun 2027

Awards

  • 🥉 2nd Runner-Up, FYP Extreme — Procom, FAST National University
  • 🥉 2nd Runner-Up, CTF & Cyber Trivia 2026 — Cybersents, NED University
  • 📈 Top 4% — National Skill Competency Test (HEC, P@SHA, PSEB, NCEAC & Virtual University)
  • 🥈 Runner-Up, Web Development — CodeSphere, NED University

Vulnerability & Issues Found Stats

Aggregated from real report data across 4 production VAPT engagements tracked on this device — Streaming, E-Commerce, Travel & Tourism, and NGO clients. Bug-bounty/VDP submissions (HackerOne, Bugcrowd, NASA VDP) use a different triage scale and are tracked separately above, not folded into these counts.

Findings by Severity Severity Mix

Severity Count
🔴 Critical 37
🟠 High 100
🟡 Medium 80
🔵 Low 21
⚪ Issues 236
Total 474
Coverage Count
Hosts / Subdomains Tested 288
API Endpoints / URLs Tested 2,284

Featured Projects

Mugheeraat — Autonomous Agentic VAPT Lab (In Testing) Open-source blueprint for local multi-agent orchestration, deterministic safety gates, and evidence-backed testing workflows — a privacy-first CLI engine chaining 6 quantized 8B open-weight LLMs, entirely air-gapped on 16GB RAM. Template requirement set: Agentic-VAPT-Personal-Lab

FloXript — Intelligent Knowledge Builder (10Pearls FYP Accelerator, Team Lead · NED University Applied R&D) Python + Docker + PocketFlow pipeline with a Gemini/OpenAI-powered RAG layer over vector databases, using Model Context Protocol (MCP) and semantic embeddings to auto-generate threat-focused edge cases, scan repositories for vulnerabilities, and speed up developer onboarding. Contact: Floxript@gmail.com

XploreLoct — Intelligent Event Ecosystem (NED University, Evolutionary Lifecycle Engineering Project) Scalable Event Management System portal leveraging Design Patterns, DBMS, Geolocation Mapping, and Predictive Models to accurately forecast attendee turnout.

Reverse Engineering LLM-Generated Code (NED University Applied Security Research) Disassembled binaries generated by GPT/Gemini/Claude/Grok using Ghidra & Radare2, documenting recurring boundary-check failures in security-constrained code generation.


Arsenal

72-Tool Offensive/Defensive Toolchain — click to expand

Recon & Subdomain Enum

Cloud & Secrets

Live Hosts & Ports

Crawling & Fuzzing

Takeover & GraphQL

Vulnerability Scanning

WAF / Filter Bypass

Exploitation & Injection

Credential Attacks

OOB & Mobile

📖 Full breakdown of every tool in the arsenal, mapped across the VAPT lifecycle: External Tool Arsenal & VAPT Cycle Reference →


Frameworks & Standards

+20 more frameworks, standards, laws & methodologies — click to expand

VAPT Methodologies

Governance & Risk Frameworks

Laws & Regulations


Unique Vulnerability Classes Identified

183 distinct vulnerability/issue classifications logged across every engagement — click to expand
Vulnerability Class Vulnerability Class Vulnerability Class Vulnerability Class
Account Creation Directory Exposure Missing HSTS Shared DB Exposure
Account Takeover Directory Listing Missing Jailbreak Detection Shipping Data Leak
Actuator Exposure DMARC Misconfiguration Missing MFA Signature Bypass
AD Credential Leak Donor Exposure Missing Policy Header SMS Abuse
Admin Escalation DoS Missing Security Headers SMS Bombing
Admin File Upload DRM Hijack Monitor Exposure SSRF
API Docs Email Disclosure No Rate Limit SSO Lockout
API Exposure Email Enumeration NoSQLi Stack Trace
API Key Leak Email Exposure NoSQLi Bypass Stacktrace
Architecture Disclosure Email Relay OAuth Misconfig Staff Enumeration
Asset Inventory Endpoint Bypass Open Auth Staging Bucket Exposure
Attack Surface Endpoint Enumeration OpenAPI Disclosure Staging Exposure
Auth Bypass Error Disclosure OTP Abuse Staging WordPress
BAC Error Log Exposure OTP Brute Force Subdomain Exposure
BFLA Exception Disclosure Outdated OS Subdomain Leak
BOLA External Triggering Order Management Bypass Swagger Exposure
Brute Force File Filter Bypass Order Status Mutation Tech Fingerprinting
Bucket Enumeration File Upload Panel Exposure Testing Env Expose
Bundle Leak Financial Document Disclosure Password Leak Third Login Surface
Business Logic Framework Disclosure Path Exposure Unauth CRUD
Business Logic Bypass GCP Key Exposure Phone Verification Bypass Unauth Endpoint
Callback Manipulation Government ID Exposure PII Disclosure Unauth Endpoint Access
Catalog Discovery GPS Spoofing PII Exposure Unauth ERP
Catalog Enumeration Hardcoded AES Key Platform Access Unauth Print Endpoint
CDN File Upload Hardcoded Key Prerelease Access Unauth Registration
CDN Upload Hardcoded Secret Privilege Boundary Unauth Write
Checkin Bypass Helper Script Privilege Escalation Unauthorized Account Creation
CI/CD Metadata Leak HLS Discovery Public Bucket Listing Unauthorized Write
Clickjacking HMAC Bypass Public File Download Unrestricted File Upload
Cloud Secret Leak Identity Exposure QR Session Fixation Unsafe C APIs
Cognito Exposure IDOR Rate Limit Bypass User Enumeration
Compromise Indicators IDOR Chain Rate Limiting User Impersonation
Comprehensive Assessment Insecure ATS Remediation Tracker User Profile Disclosure
CORS Informational Finding Role Violation Username Enumeration
Credential Abuse Infrastructure Exposure S3 Listing Version Disclosure
Credential Disclosure Invoice Disclosure S3 Upload Abuse VPN Exposure
Credential Leak JWT Abuse Score Manipulation WAF Bypass
CSFR JWT Leak SDK Analytics WAF Missing
CSP Form Action Keycloak JWT Bypass Secret Leak WAF Signature Bypass
Data Disclosure KYC BOLA Security Status Wallet Deactivation
Database Exposure License Enumeration Service Access Webhook Injection
DB Credentials Leak Mass PII Disclosure Service Exposure Webhook Manipulation
DB Error Disclosure Mass Push Notification Service Inventory Write BFLA
DB Schema Exposure Metadata Exposure Service Map Write BOLA
Deprecated TLS Metrics Exposure Session Hijacking XSS
Development Placeholder MFA Exploitation Scope Session Management

Bug Bounty & Vulnerability Research

30+ vulnerabilities responsibly disclosed via HackerOne & Bugcrowd, including CORS misconfigurations, BOLA, PII leakage, sensitive data disclosure, and exposed API keys.


Languages Used

Most Used Languages

Aggregated across all public repositories on this GitHub account.


Current Focus

[Offense]   Penetration Testing · Attack Surface Recon · API/Business-Logic Abuse · CTFs
[Defense]   PCI DSS v4.0.1 · ISO/IEC 27001 · NIST CSF · SOC 1/2 · HIPAA · CIS Controls · COBIT
[Cloud]     AWS · Huawei Cloud · Cloudflare WAF · IAM (OAuth/Keycloak) · Microservices Defense
[AI/Sec]    MCP · RAG Architecture · LLM Red-Teaming · Reverse Engineering LLM-Generated Binaries

Certification Roadmap — Goals (Not Yet Earned, In Sha Allah 🤲)

Everything below is a target, not a claim — actively working toward these, not holding them yet.

Certification Issuer
Certified Penetration Testing Specialist (CPTS) Hack The Box
Certified Defensive Security Analyst (CDSA) Hack The Box
Offensive Security Certified Professional (OSCP) OffSec
Certified Information Systems Auditor (CISA) ISACA
Certified Information Security Manager (CISM) ISACA
Advanced in AI Security Management (AAISM) ISACA
Certified Information Systems Security Professional (CISSP) ISC2
Artificial Intelligence Governance Professional (AIGP) IAPP
Certified Ethical Hacker (CEH) EC-Council
Security+ (Sec+) CompTIA
Junior Penetration Tester (eJPT) INE
Penetration Tester Level 1 (PT1) TryHackMe
Security Analyst Level 1 (SAL1) TryHackMe
Cyber Security 101 (SEC1) TryHackMe
AI Security 1 (AI1) TryHackMe

"Verily, with hardship comes ease." — Qur'an 94:6
m.huzaifa.jamil.cys@gmail.com · m.huzaifa.jamil@outlook.com · LinkedIn · Credly

Popular repositories Loading

  1. PcPartPicker PcPartPicker Public

    Forked from MSK-009/PcPartPicker

    JavaScript

  2. PcPartPicker-Backend PcPartPicker-Backend Public

    Forked from MSK-009/PcPartPicker-Backend

    JavaScript

  3. XploreLoct-fork-archive XploreLoct-fork-archive Public

    Forked from Abdul-Moiz-1/DP_project

    TypeScript

  4. Agentic-VAPT-Personal-Lab Agentic-VAPT-Personal-Lab Public template

    A Template Set of Requirements for building a hands-off, autonomous VAPT orchestration framework running entirely on local hardware. Powered by open-source LLMs deployed in a memory-safe, sequentia…

    Python

  5. MHuzaifaJamil MHuzaifaJamil Public

  6. XploreLoct XploreLoct Public

    TypeScript