Thanks to visit codestin.com
Credit goes to GitHub.com

Skip to content
View Is-Ammar's full-sized avatar

Highlights

  • Pro

Block or report Is-Ammar

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Is-Ammar/README.md
Typing SVG
M4SEC Team 1337 School HackerOne



/root/whoami
I am a Security-Oriented Full Stack Engineer bridging the gap between robust software architecture and offensive security operations.
My approach is dual-faceted: I build scalable web systems using modern stacks (React, Python, C++), and I rigorously stress-test them using advanced exploitation techniques. Currently focused on automating vulnerability reconnaissance and developing custom security tooling.


iammar's 42 stats

πŸ“‘ Featured Projects & Research

(Proof of concept: Building secure systems and breaking insecure ones)

Project Description Stack
πŸ›‘οΈ Security Tooling Developed a custom multi-threaded reconnaissance tool for automating subdomain enumeration and vulnerability scanning. Optimized for low-latency using C++ and Python bindings. Python C++ Bash Docker
πŸ•ΈοΈ Secure Web App A full-stack e-commerce platform built with security-first principles. Implements strict CSP, JWT rotation, and input sanitization to mitigate XSS/SQLi vectors. React Node.js PostgreSQL Redis
🚩 CTF Writeups A curated collection of detailed writeups for Web and Pwn challenges from M4SEC competitions and HackTheBox, focusing on methodology and root-cause analysis. Markdown Ghidra Burp Suite

πŸ’» The Dual Arsenal

Integration of high-level development standards with security operations. Leverages code literacy to audit complex systems, write custom exploits, and implement robust security patches.

πŸ› οΈ Development Stack

Dev Skills
βš”οΈ Security Operations

Sec Skills


🎯 Web Security Research Focus

My research centers on the OWASP Top 10, focusing on the identification of high-impact vulnerabilities in modern web applications.

Vulnerability Class Competency Methodology & Tooling
πŸ’‰ Injection Attacks 🟩 Proficient sqlmap, Union/Error-based extraction, Polyglots
πŸ”“ Access Control 🟩 Proficient IDOR discovery, JWT manipulation, Privilege Escalation
πŸ•ΈοΈ Server-Side Flaws 🟨 Intermediate SSRF (Cloud Metadata), Insecure Deserialization, XXE
πŸ›‘οΈ Client-Side Risks 🟩 Proficient XSS (DOM/Reflected), CSP Bypassing, Prototype Pollution

πŸ“Š Code & Activity


Pinned Loading

  1. push_swap_tester push_swap_tester Public

    Python 7

  2. Libft Libft Public

    C 4

  3. fract-ol fract-ol Public

    C 1

  4. lang-me lang-me Public

    JavaScript 2

  5. ichess ichess Public

    TypeScript