Offensive security practitioner specializing in identifying, exploiting, and analyzing vulnerabilities across modern web applications and digital footprints.
Approach centered on adversarial thinking, disciplined methodology, and precision in both exploitation and documentation.
Focus areas:
- Web exploitation (RCE, SSRF, IDOR, LFI/RFI, XXE, upload bypasses)
- Cryptanalysis and CTF cipher challenges
- OSINT investigations and metadata intelligence
- Secure coding for Android and web platforms
- Methodical enumeration, exploitation, and remediation reporting
Professional-level writeups covering:
- Web exploitation chains
- OSINT identity reconstruction
- RSA and XOR cryptanalysis
- Forensic-style problem solving
Designed with a pentest-report mindset, not student-level narrative.
Reproduction and exploitation of high-impact vulnerabilities:
- Template injection to remote code execution
- SSRF leading to internal network exposure
- File upload → server-side execution
- Wrapper-based local file inclusion
- Broken access control escalation
Security-focused Android project implementing:
- Encrypted local storage
- Authentication logic
- Defensive coding patterns
- Modular design for future hardening
- Manual exploitation over tool-reliance
- Attack surface mapping and threat modeling
- Payload construction and bypass strategies
- Input validation subversion
- Code-assisted vulnerability research
- RSA low-exponent recovery
- XOR key extraction and inversion
- Classical cipher reconstruction
- Fault pattern detection
- Metadata extraction and correlation
- Geolocation tracing from visual signals
- Username pivoting across platforms
- Behavioral and digital footprint analysis
Languages: Java, Python, C++, JavaScript, SQL, HTML/CSS
Frameworks/Platforms: JSP/Servlets, Android Studio
Security tooling: Burp Suite, Kali Linux, curl, grep, SQLmap, dig, exiftool, Packet Tracer
- Release full offensive CTF portfolio with professional-standard documentation
- Develop Python tooling for reconnaissance and automation
- Advance secure development practices across Android and web
- Participate regularly in CTF competitions
- Pursue foundational certifications (eJPT, Security+)
- Build toward an IT consulting path focused on security and AI systems
GitHub: https://github.com/praisi-tech
Email: [email protected]