Hello, I am an IT enthusiast with a genuine passion for exploring the dynamic world of information technology. My fascination with IT goes beyond mere professional interest; it's a personal drive that fuels my continuous learning and exploration in this ever-evolving field. I am dedicated to leveraging technology to solve challenges and contribute to the exciting advancements within the IT landscape. Let's connect and delve into the limitless possibilities that IT has to offer.
Skills
Web Application Security
Proficient in identifying and mitigating web application vulnerabilities:
Remote Code Execution (RCE) SQL Injection
Cross-Site Scripting (XSS) Cross-Site Request Forgery (CSRF) Broken Access Control (BAC) Web Cache Poisoning (WCP) Web Cache Deception (WCD) Insecure Direct Object References (IDOR) Denial Of Service (DOS)
I have successfully identified and remediated numerous web vulnerabilities in high-profile corporate websites, such as:
Microsoft: Cross-Site Scripting on their official webapp store, High Severity.
Microsoft Security Response Center has acknowledged me for those findings. (Specific date: Jun 30, 2020).
Sendgrid: Account Take-Over (ATO), Critical Severity.
Backblaze: Cross-Site Scripting, High Severity.
Miro: Broken Access Control, High Severity
HuffingtonPost: Cross-Site Scripting on multiple websites, High Severity.
and a lot more..
Automated Penetration Testing:
Conducted comprehensive penetration tests using frameworks and workflows that I personally developed, using Bash/Shell, Javascript/Nodejs, Python and or all of them combined to make some efficient frameworks and workflows to find web vulnerabilities.
Spoken Languages
Arabic - All Flavors
★★★★★
English
★★★★
French
★★★
Spanish
★
Education
Hiring?
if (needAnITSpecialist) { marwane@emailll.com } else { closePage() }