"(¥83|* 53(|_||*17¥ 3|\|&1|\|33|* ₩17# 4 50|=7₩4|*3 3|\|&1|\|33|*1|\|& |=0|_||\||)4710|\|"
{Ask AI to Decode this symbol-based leetspeak cipher into plain English}
> cat about_me.txt- 🔐 Cyber Security Engineer at Virtuosoft, Karachi — running full-scope VAPT engagements, PCI DSS compliance consultancy, and multi-cloud security audits for OTT, e-commerce, and NGO platforms.
- 🎯 Executed VAPT across 400+ in-scope hosts & API endpoints, surfaced 450+ findings (140+ Critical/High), mapped to OWASP & CIS Controls.
- 📋 Led PCI DSS gap analyses against ISO/IEC 27001, NIST CSF, SOC 1/2, and HIPAA, remediating 10+ core compliance gaps and executing 200+ validation re-tests.
- 🕵️ Independent bug bounty hunter on HackerOne & Bugcrowd — 30+ vulnerabilities responsibly disclosed (CORS, BOLA, PII leakage, exposed API keys).
- 🤖 Building Mugheeraat — an air-gapped, privacy-first autonomous Agentic VAPT lab orchestrating 6 quantized open-weight LLMs entirely offline on 16GB RAM.
- 🎓 B.E. Software Engineering, NED University of Engineering & Technology.
- 🕌 Actively studying for CEH, CISA & CISM — pairing offensive tradecraft with enterprise-grade governance.
22 proof-of-concept write-ups across 5 industry verticals — click to expand
A curated collection of 22 proof-of-concept write-ups distilled from real, authorized engagements — every issue documented has already been remediated by the affected organization. Targets, identifiers, and figures are generalized/fictionalized; the focus is the vulnerability mechanism, not any specific system. Organized across 5 industry verticals:
| Sector | PoCs | Highlights |
|---|---|---|
| 📺 Streaming Platforms | 9 | BOLA mass PII enumeration, hardcoded client-side crypto keys, QR session fixation → ATO, XML-RPC brute-force |
| 🛒 E-Commerce | 6 | NoSQL operator injection, unauthenticated Firebase RTDB, payment-webhook forgery, IAM realm confusion |
| 3 | Unauthenticated Kubernetes dashboard (full secret disclosure), BFLA booking void, IDOR guest PII enumeration | |
| 🏛️ Government Agencies | 2 | Service-descriptor leak → search-index injection, pre-auth deserialization code path |
| 🤝 NGOs / Non-Profit | 2 | Production debug-mode RCE preconditions, client-suppliable role → super-admin privilege escalation |
📄 Read the full portfolio (PDF) →
📺 Streaming Platforms
- MHJ-POC-01 — Broken Object-Level Authorization (BOLA) — Mass PII Enumeration
- MHJ-POC-02 — Client-Side Hardcoded Cryptographic Key — Transaction Integrity Forgery
- MHJ-POC-03 — Unverified JWT Client-Side Decode — Business Logic / Score State Manipulation
- MHJ-POC-04 — QR-Code Session Fixation — Full Account Takeover
- MHJ-POC-11 — CORS Misconfiguration (Reflected Origin + Credentials) — Cross-Origin Session Hijack
- MHJ-POC-12 — Business Logic Flaw — Unbounded Negative-Value Integer Manipulation
- MHJ-POC-13 — Broken Function-Level Authorization (BFLA) — Unauthorized Administrative Write Access
- MHJ-POC-15 — Unauthenticated Observability Endpoint — Infrastructure & Internal Topology Disclosure
- MHJ-POC-16 — XML-RPC Multicall Brute-Force — Authentication Rate-Limit Bypass
🛒 E-Commerce
- MHJ-POC-05 — NoSQL Operator Injection via OTP/Phone Field
- MHJ-POC-06 — Unauthenticated Firebase Realtime DB — Plaintext Credential Disclosure
- MHJ-POC-07 — Payment Gateway Callback — Missing Signature Verification
- MHJ-POC-08 — IAM Realm/Role Confusion — Privileged JWT Issuance
- MHJ-POC-09 — Systemic Guest-JWT Authorization Bypass — Internal Business Data Disclosure
- MHJ-POC-10 — Unauthenticated S3 Pre-Signed URL Generation — Arbitrary File Upload
- MHJ-POC-17 — Unauthenticated Kubernetes Dashboard — Full Cluster Secret Disclosure
- MHJ-POC-18 — BFLA — Unauthorized Booking Void via Role-Unchecked Endpoint
- MHJ-POC-19 — IDOR — Sequential Reservation ID Enumeration Exposes Traveler PII
🏛️ Government Agencies
- MHJ-POC-20 — Unauthenticated Service Descriptor Disclosure → Backend Search-Index Injection
- MHJ-POC-21 — Unauthenticated Admin UI Handler — Pre-Auth Deserialization Code Path
🤝 NGOs / Non-Profit
- MHJ-POC-14 — Debug Mode Enabled in Production — Remote Code Execution Preconditions
- MHJ-POC-22 — Privilege Escalation to Super-Admin via Client-Suppliable Role Parameter
| Certification | Issuer | Status |
|---|---|---|
| Certified in Cybersecurity (CC) | ISC2 | ✅ Earned — 2025 |
| Introduction to Critical Infrastructure Protection (ICIP) | OPSWAT Academy | ✅ Earned — 2026 |
| Certified Ethical Hacker (CEH) | EC-Council | 🟡 In Training (NAVTTC @ PAF KIET) — Expected Nov 2026 |
| Certified Information Systems Auditor (CISA) | ISACA | 🟡 In Training (3D Educators) — Expected Nov 2026 |
| Certified Information Security Manager (CISM) | ISACA | 🟡 In Progress — Expected Jun 2027 |
- 🥉 2nd Runner-Up, FYP Extreme — Procom, FAST National University
- 🥉 2nd Runner-Up, CTF & Cyber Trivia 2026 — Cybersents, NED University
- 📈 Top 4% — National Skill Competency Test (HEC, P@SHA, PSEB, NCEAC & Virtual University)
- 🥈 Runner-Up, Web Development — CodeSphere, NED University
Aggregated from real report data across 4 production VAPT engagements tracked on this device — Streaming, E-Commerce, Travel & Tourism, and NGO clients. Bug-bounty/VDP submissions (HackerOne, Bugcrowd, NASA VDP) use a different triage scale and are tracked separately above, not folded into these counts.
| Severity | Count |
|---|---|
| 🔴 Critical | 37 |
| 🟠 High | 100 |
| 🟡 Medium | 80 |
| 🔵 Low | 21 |
| ⚪ Issues | 236 |
| Total | 474 |
| Coverage | Count |
|---|---|
| Hosts / Subdomains Tested | 288 |
| API Endpoints / URLs Tested | 2,284 |
Mugheeraat — Autonomous Agentic VAPT Lab (In Testing) Open-source blueprint for local multi-agent orchestration, deterministic safety gates, and evidence-backed testing workflows — a privacy-first CLI engine chaining 6 quantized 8B open-weight LLMs, entirely air-gapped on 16GB RAM. Template requirement set: Agentic-VAPT-Personal-Lab
FloXript — Intelligent Knowledge Builder (10Pearls FYP Accelerator, Team Lead · NED University Applied R&D) Python + Docker + PocketFlow pipeline with a Gemini/OpenAI-powered RAG layer over vector databases, using Model Context Protocol (MCP) and semantic embeddings to auto-generate threat-focused edge cases, scan repositories for vulnerabilities, and speed up developer onboarding. Contact: Floxript@gmail.com
XploreLoct — Intelligent Event Ecosystem (NED University, Evolutionary Lifecycle Engineering Project) Scalable Event Management System portal leveraging Design Patterns, DBMS, Geolocation Mapping, and Predictive Models to accurately forecast attendee turnout.
Reverse Engineering LLM-Generated Code (NED University Applied Security Research) Disassembled binaries generated by GPT/Gemini/Claude/Grok using Ghidra & Radare2, documenting recurring boundary-check failures in security-constrained code generation.
72-Tool Offensive/Defensive Toolchain — click to expand
Recon & Subdomain Enum
Cloud & Secrets
Live Hosts & Ports
Crawling & Fuzzing
Takeover & GraphQL
Vulnerability Scanning
WAF / Filter Bypass
Exploitation & Injection
Credential Attacks
OOB & Mobile
📖 Full breakdown of every tool in the arsenal, mapped across the VAPT lifecycle: External Tool Arsenal & VAPT Cycle Reference →
+20 more frameworks, standards, laws & methodologies — click to expand
VAPT Methodologies
Governance & Risk Frameworks
Laws & Regulations
183 distinct vulnerability/issue classifications logged across every engagement — click to expand
| Vulnerability Class | Vulnerability Class | Vulnerability Class | Vulnerability Class |
|---|---|---|---|
| Account Creation | Directory Exposure | Missing HSTS | Shared DB Exposure |
| Account Takeover | Directory Listing | Missing Jailbreak Detection | Shipping Data Leak |
| Actuator Exposure | DMARC Misconfiguration | Missing MFA | Signature Bypass |
| AD Credential Leak | Donor Exposure | Missing Policy Header | SMS Abuse |
| Admin Escalation | DoS | Missing Security Headers | SMS Bombing |
| Admin File Upload | DRM Hijack | Monitor Exposure | SSRF |
| API Docs | Email Disclosure | No Rate Limit | SSO Lockout |
| API Exposure | Email Enumeration | NoSQLi | Stack Trace |
| API Key Leak | Email Exposure | NoSQLi Bypass | Stacktrace |
| Architecture Disclosure | Email Relay | OAuth Misconfig | Staff Enumeration |
| Asset Inventory | Endpoint Bypass | Open Auth | Staging Bucket Exposure |
| Attack Surface | Endpoint Enumeration | OpenAPI Disclosure | Staging Exposure |
| Auth Bypass | Error Disclosure | OTP Abuse | Staging WordPress |
| BAC | Error Log Exposure | OTP Brute Force | Subdomain Exposure |
| BFLA | Exception Disclosure | Outdated OS | Subdomain Leak |
| BOLA | External Triggering | Order Management Bypass | Swagger Exposure |
| Brute Force | File Filter Bypass | Order Status Mutation | Tech Fingerprinting |
| Bucket Enumeration | File Upload | Panel Exposure | Testing Env Expose |
| Bundle Leak | Financial Document Disclosure | Password Leak | Third Login Surface |
| Business Logic | Framework Disclosure | Path Exposure | Unauth CRUD |
| Business Logic Bypass | GCP Key Exposure | Phone Verification Bypass | Unauth Endpoint |
| Callback Manipulation | Government ID Exposure | PII Disclosure | Unauth Endpoint Access |
| Catalog Discovery | GPS Spoofing | PII Exposure | Unauth ERP |
| Catalog Enumeration | Hardcoded AES Key | Platform Access | Unauth Print Endpoint |
| CDN File Upload | Hardcoded Key | Prerelease Access | Unauth Registration |
| CDN Upload | Hardcoded Secret | Privilege Boundary | Unauth Write |
| Checkin Bypass | Helper Script | Privilege Escalation | Unauthorized Account Creation |
| CI/CD Metadata Leak | HLS Discovery | Public Bucket Listing | Unauthorized Write |
| Clickjacking | HMAC Bypass | Public File Download | Unrestricted File Upload |
| Cloud Secret Leak | Identity Exposure | QR Session Fixation | Unsafe C APIs |
| Cognito Exposure | IDOR | Rate Limit Bypass | User Enumeration |
| Compromise Indicators | IDOR Chain | Rate Limiting | User Impersonation |
| Comprehensive Assessment | Insecure ATS | Remediation Tracker | User Profile Disclosure |
| CORS | Informational Finding | Role Violation | Username Enumeration |
| Credential Abuse | Infrastructure Exposure | S3 Listing | Version Disclosure |
| Credential Disclosure | Invoice Disclosure | S3 Upload Abuse | VPN Exposure |
| Credential Leak | JWT Abuse | Score Manipulation | WAF Bypass |
| CSFR | JWT Leak | SDK Analytics | WAF Missing |
| CSP Form Action | Keycloak JWT Bypass | Secret Leak | WAF Signature Bypass |
| Data Disclosure | KYC BOLA | Security Status | Wallet Deactivation |
| Database Exposure | License Enumeration | Service Access | Webhook Injection |
| DB Credentials Leak | Mass PII Disclosure | Service Exposure | Webhook Manipulation |
| DB Error Disclosure | Mass Push Notification | Service Inventory | Write BFLA |
| DB Schema Exposure | Metadata Exposure | Service Map | Write BOLA |
| Deprecated TLS | Metrics Exposure | Session Hijacking | XSS |
| Development Placeholder | MFA Exploitation Scope | Session Management |
30+ vulnerabilities responsibly disclosed via HackerOne & Bugcrowd, including CORS misconfigurations, BOLA, PII leakage, sensitive data disclosure, and exposed API keys.
Aggregated across all public repositories on this GitHub account.
[Offense] Penetration Testing · Attack Surface Recon · API/Business-Logic Abuse · CTFs
[Defense] PCI DSS v4.0.1 · ISO/IEC 27001 · NIST CSF · SOC 1/2 · HIPAA · CIS Controls · COBIT
[Cloud] AWS · Huawei Cloud · Cloudflare WAF · IAM (OAuth/Keycloak) · Microservices Defense
[AI/Sec] MCP · RAG Architecture · LLM Red-Teaming · Reverse Engineering LLM-Generated Binaries
Everything below is a target, not a claim — actively working toward these, not holding them yet.
| Certification | Issuer |
|---|---|
| Certified Penetration Testing Specialist (CPTS) | Hack The Box |
| Certified Defensive Security Analyst (CDSA) | Hack The Box |
| Offensive Security Certified Professional (OSCP) | OffSec |
| Certified Information Systems Auditor (CISA) | ISACA |
| Certified Information Security Manager (CISM) | ISACA |
| Advanced in AI Security Management (AAISM) | ISACA |
| Certified Information Systems Security Professional (CISSP) | ISC2 |
| Artificial Intelligence Governance Professional (AIGP) | IAPP |
| Certified Ethical Hacker (CEH) | EC-Council |
| Security+ (Sec+) | CompTIA |
| Junior Penetration Tester (eJPT) | INE |
| Penetration Tester Level 1 (PT1) | TryHackMe |
| Security Analyst Level 1 (SAL1) | TryHackMe |
| Cyber Security 101 (SEC1) | TryHackMe |
| AI Security 1 (AI1) | TryHackMe |
"Verily, with hardship comes ease." — Qur'an 94:6
m.huzaifa.jamil.cys@gmail.com · m.huzaifa.jamil@outlook.com · LinkedIn · Credly