ENGLISH / TÜRKÇE
I'm Abdulhalim, a web application penetration tester focused on web & API security.
Access control, authentication, injection, and business logic are at the center of my work.
I map the attack surface, validate the impact, and build tools to make testing repeatable.
Explore my technical focus
- Access control — broken authorization, IDOR / BOLA, and privilege boundaries.
- Authentication — login flows, token handling, JWT validation, and session management.
- Injection — SQL injection, XSS, and the way applications handle untrusted input.
- SSRF — server-side requests and trust boundaries between services.
- APIs & business logic — REST / GraphQL, undocumented endpoints, and workflow abuse.
- Reconnaissance & automation — asset discovery, endpoint mapping, and Python / Bash tooling.
Open the complete toolkit
| Discipline | Tools & technologies |
|---|---|
| Reconnaissance | Nmap, Amass, subfinder, httpx, katana, ffuf, gobuster, waybackurls, Shodan |
| Web & API testing | Burp Suite, OWASP ZAP, Nuclei, Postman, GraphQL, JWT, browser DevTools |
| Targeted testing | sqlmap, XSStrike, Metasploit |
| Credential auditing | Hydra, Hashcat, John the Ripper |
| Traffic & networks | Wireshark, tcpdump, mitmproxy, OpenVPN |
| Scripting & development | Python, JavaScript, Bash, Node.js, HTML, CSS, MySQL |
| Environment | Linux, Docker, Git, GitHub, VS Code |
Code, experiments, and contributions.
Explore repositories ↗ · View GitHub activity
altuntashalim123@gmail.com
All security testing is carried out on systems I own or have written authorization to assess.
