Skip to content
Elsons

JUST A TECH
CURIOUS GUY!!!

Cairo, Egypt · Available worldwide

elsons@security: ~
LIVE SESSION

$ whoami: hassan_ashraf · web app pentester · bug bounty · ctf. $ cat focus.txt: broken access control, idor, ssrf, open redirect. $ status --now: hunting on bugcrowd / hackerone / yeswehack

FDC Summit CTF Finals
2nd
FDC Summit CTF Finals
Reported Findings
6
Reported Findings
GPA / 4.3 (SUtech)
4.0
GPA / 4.3 (SUtech)

01 / ABOUT

See the system.
Secure the path.

01 / OFFENSIVE TESTING

Web Application Security

Focused on the logic flaws automated scanners miss: IDOR, Broken Access Control, SSRF, and authentication bypasses. Every finding is backed by proof-of-concept steps and remediation guidance.

OWASP Top 10Burp Suite
02 / AUTOMATION & RECON

Reconnaissance Pipelines

Built recon9.py, a custom nine-phase reconnaissance tool chaining subfinder, amass, httpx, ffuf, nuclei, and trufflehog to automate repeatable attack surface discovery on bug bounty targets.

recon9.pyPython / Linux
03 / COMPETITIVE DEFENSE

CTF Player & Disclosure

Placed 2nd in the FDC Summit CTF finals (Cairo, 2026). I respect program rules, verify impacts with honest CVSS scores, and work responsibly with security teams across platforms.

FDC CTF 2nd PlaceResponsible Disclosure
Education

B.Tech in Networks & Cybersecurity

Elsewedy University of Technology (SUtech)

3rd year · GPA 4.0 / 4.3 · Expected 2028

Location & Status

Cairo, Egypt

Bugcrowd · HackerOne · YesWeHack

● Active researcher

Languages
ArabicNative
EnglishUpper intermediate

02 / EXPERIENCE

Track record &
field experience.

01 / Bugcrowd · HackerOne · YesWeHack

Independent Security Researcher (Bug Bounty)

2026 – Present
  • ―Test live web applications on Bugcrowd, HackerOne and YesWeHack using OWASP Top 10 methodology.
  • ―Find, exploit and responsibly disclose Broken Access Control, IDOR, SSRF and Open Redirect.
  • ―Built recon9.py, a nine-phase Python recon tool integrating subfinder, amass, httpx, ffuf, waybackurls, gau, nuclei and trufflehog.
  • ―Write professional reports with PoC, CVSS scoring, impact analysis and remediation guidance.
02 / MCS

Cybersecurity Intern

2025
  • ―Trained in networking fundamentals, OS hardening and penetration testing methodologies.
  • ―Ran vulnerability assessments and wrote structured findings reports with remediation advice.
03 / Petrojet

IT Intern

2025
  • ―Supported SAP ERP workflows and corporate IT operations, including hardware and software troubleshooting.

03 / FINDINGS

Verified findings.
Responsible disclosure.

Details withheld in line with program disclosure policies.
CriticalCVSS 9.4

HARMAN International(ca.jbl.com)

Authentication Bypass / Brute Force

Brute force and authentication bypass on the login endpoint via HTTP method manipulation, with no effective rate limiting.

STATUSRTFS
HighCVSS 8.6

CyberGhost VPN

Improper Access Control

Improper access control on a feedback endpoint via path manipulation.

STATUSDuplicate
HighCVSS 8.5

TeamViewer

IDOR

IDOR allowing chat creation with arbitrary users, including an admin, by manipulating an account identifier. Also enabled user enumeration.

STATUSInformative
LowP4

Lightspeed Retail

SSRF

Unrestricted webhook URL creating SSRF and data exfiltration risk.

STATUSDuplicate
InformationalP5

Lightspeed Retail

Broken Access Control

Broken access control in the REST and GraphQL APIs that let a cashier create customer groups reserved for higher roles.

STATUSDuplicate
Unrated#06

Slickdeals

Open Redirect

Open redirect, reported with a detailed proof of concept.

STATUSSubmitted, awaiting triage

04 / PROJECTS

Proof beyond
the browser.

PROJECT 01todoGitHub

recon9.py

Nine-phase recon automation tool that chains subfinder, amass, httpx, ffuf, waybackurls, gau, nuclei and trufflehog into one repeatable pipeline.

  • Python
  • Recon
  • Automation
PROJECT 02

Python Packet Sniffer

Captures and analyzes live network traffic.

  • Python
  • Networking
PROJECT 03

Basic Unix Shell in Python

A minimal shell implementing core commands and process management.

  • Python
  • Linux
  • Processes
PROJECT 04

UniTrack Maintenance Request System

Three-role maintenance platform for Admin, Technician and User.

  • PHP
  • Laravel
PROJECT 05

Bus Reservation System

Booking, cancellation and admin modules.

  • Java
  • MySQL
  • SQLite
PROJECT 06

Expenses Tracker & Restaurant Delivery System

Expense tracking and restaurant delivery web applications.

  • JavaScript
  • React.js
  • Node.js
PROJECT 07

Cisco Packet Tracer Labs

Routing, switching, VLAN and troubleshooting labs.

  • Cisco Packet Tracer
  • Routing
  • VLANs

05 / SKILLS

Core capabilities &
methodologies.

01 / CATEGORY

Pentesting

  • Web app pentesting
  • OWASP Top 10
  • Burp Suite
  • Nmap
  • Wireshark
02 / CATEGORY

Vulnerability classes

  • IDOR
  • Broken Access Control
  • Open Redirect
  • SSRF
  • XSS
  • SQLi (theory)
03 / CATEGORY

Programming

  • Python
  • JavaScript
  • PHP
  • Java
  • HTML
  • CSS
04 / CATEGORY

Frameworks

  • React.js
  • Node.js
  • Laravel
05 / CATEGORY

Databases

  • MySQL
  • SQLite
06 / CATEGORY

OS & Systems

  • Ubuntu Linux (primary)
  • Kali Linux
  • Windows
  • Basic shell scripting
07 / CATEGORY

Networking

  • TCP/IP
  • Packet analysis
  • Subnetting
  • Cisco Packet Tracer
08 / CATEGORY

Reporting

  • CVSS scoring
  • PoC documentation
  • Responsible disclosure

06 / CERTIFICATES

Learning, with
evidence.

Verified certifications, university programs, intensive training, and CTF competitions. Select any credential to view the original certificate.

Showing 12 certificates

  • Networking

    Introduction to Networks

    Cisco Networking Academy

    CCNA curriculum

  • Networking

    Network Basics

    Cisco Networking Academy

  • Networking

    CCNA Curriculum (completed)

    Cisco Networking Academy

  • Security

    eJPT v2

    INE Security

    Junior Penetration Tester

IN PROGRESS & CURRENT PREPARATION

  • eWPTX

    INE Security · Web Application Penetration Tester eXtreme

    studying
  • eCPPT

    INE Security · Certified Professional Penetration Tester

    studying

07 / ACHIEVEMENTS

Achievements &
community.

Competitive cybersecurity CTFs, international hackathon promotion, and community service.
Competition2026

2nd place · FDC Summit CTF Finals

CyberTalents, Cairo. Qualified for the on-site finals, then placed second.

Community

Marketing Member · NASA Space Apps Challenge (Cairo Hub)

Community outreach and hackathon promotion.

Volunteering

Volunteer · Charity organization

Volunteer at a charity organization.

08 / CONTACT

Make the system
more dependable.

For penetration testing, bug bounty programs, security research, or offensive security opportunities, send the environment, scope, and what success looks like.
DIRECT INQUIRIES

A conversation starts here.

Email is the fastest way to reach me. For security vulnerability reports or program invitations, I review details and respond promptly.