Skip to content
View abdulhalimaltuntas's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report abdulhalimaltuntas

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
abdulhalimaltuntas/README.md

ENGLISH   /   TÜRKÇE

Abdulhalim Altuntaş — Web Application Pentester. Web and API security, reconnaissance, and security tooling.

Email Explore repositories Instagram

I explore how applications break — and how to make them stronger.

I'm Abdulhalim, a web application penetration tester focused on web & API security.
Access control, authentication, injection, and business logic are at the center of my work.
I map the attack surface, validate the impact, and build tools to make testing repeatable.

Security expertise: access control and IDOR/BOLA; authentication, sessions and JWT; injection and XSS; SSRF; API security and business logic; reconnaissance and automation.

Explore my technical focus
  • Access control — broken authorization, IDOR / BOLA, and privilege boundaries.
  • Authentication — login flows, token handling, JWT validation, and session management.
  • Injection — SQL injection, XSS, and the way applications handle untrusted input.
  • SSRF — server-side requests and trust boundaries between services.
  • APIs & business logic — REST / GraphQL, undocumented endpoints, and workflow abuse.
  • Reconnaissance & automation — asset discovery, endpoint mapping, and Python / Bash tooling.

My methodology: define scope and authorization; map assets and endpoints; test and validate; connect findings to their impact; report reproducible steps and remediation.

Animated illustration of an authorized assessment workflow: scope, map, inspect access controls, validate impact, and prepare a report. This is a workflow preview, not a live scan or an actual finding.

Tools and technologies: Python, Bash, JavaScript, Linux, Docker, Git, Burp Suite, Nmap, Wireshark, Nuclei, Postman, and ffuf.

Open the complete toolkit
Discipline Tools & technologies
Reconnaissance Nmap, Amass, subfinder, httpx, katana, ffuf, gobuster, waybackurls, Shodan
Web & API testing Burp Suite, OWASP ZAP, Nuclei, Postman, GraphQL, JWT, browser DevTools
Targeted testing sqlmap, XSStrike, Metasploit
Credential auditing Hydra, Hashcat, John the Ripper
Traffic & networks Wireshark, tcpdump, mitmproxy, OpenVPN
Scripting & development Python, JavaScript, Bash, Node.js, HTML, CSS, MySQL
Environment Linux, Docker, Git, GitHub, VS Code

BUILDING IN PUBLIC

Code, experiments, and contributions.

Explore repositories ↗   ·   View GitHub activity

An isometric view of my public GitHub contributions.

Animated snake following my GitHub contribution history.

Let’s talk security. Web security, testing methodology, and tooling. Email Abdulhalim Altuntaş.

altuntashalim123@gmail.com

All security testing is carried out on systems I own or have written authorization to assess.

Popular repositories Loading

  1. capsaicin capsaicin Public

    Next-generation intelligent Web Fuzzer & Directory Scanner written in Go. Features WAF detection, secret scanning, auto-calibration, and smart 403 bypass

    Go 28 7

  2. JSHarvest JSHarvest Public

    Browser extension that inventories every JavaScript a page loads — deduplicated, classified first- vs third-party, with hidden-chunk discovery, source-map recovery and risk flags.

    JavaScript 6

  3. StyxWire StyxWire Public

    C 2 1

  4. noctis noctis Public

    A calm, AI-aware coding environment for the terminal, built on Neovim. Run Claude Code, Codex, Opencode or Kimi side by side with your code, watch every file change they make live, and review or sa…

    Lua 2

  5. chimera chimera Public

    Research-grade C2 Framework leveraging advanced LSB Steganography to conceal encrypted command traffic within PNG images. Powered by Go (Agent) and Python (Server) with mTLS authentication.

    Python 1

  6. abdulhalimaltuntas abdulhalimaltuntas Public

    Python