HARMAN International(ca.jbl.com)
Authentication Bypass / Brute Force
Brute force and authentication bypass on the login endpoint via HTTP method manipulation, with no effective rate limiting.
Press Esc or Click to enter
$ whoami: hassan_ashraf · web app pentester · bug bounty · ctf. $ cat focus.txt: broken access control, idor, ssrf, open redirect. $ status --now: hunting on bugcrowd / hackerone / yeswehack
01 / ABOUT
Focused on the logic flaws automated scanners miss: IDOR, Broken Access Control, SSRF, and authentication bypasses. Every finding is backed by proof-of-concept steps and remediation guidance.
Built recon9.py, a custom nine-phase reconnaissance tool chaining subfinder, amass, httpx, ffuf, nuclei, and trufflehog to automate repeatable attack surface discovery on bug bounty targets.
Placed 2nd in the FDC Summit CTF finals (Cairo, 2026). I respect program rules, verify impacts with honest CVSS scores, and work responsibly with security teams across platforms.
B.Tech in Networks & Cybersecurity
Elsewedy University of Technology (SUtech)
3rd year · GPA 4.0 / 4.3 · Expected 2028
Cairo, Egypt
Bugcrowd · HackerOne · YesWeHack
● Active researcher
02 / EXPERIENCE
03 / FINDINGS
Authentication Bypass / Brute Force
Brute force and authentication bypass on the login endpoint via HTTP method manipulation, with no effective rate limiting.
Improper Access Control
Improper access control on a feedback endpoint via path manipulation.
IDOR
IDOR allowing chat creation with arbitrary users, including an admin, by manipulating an account identifier. Also enabled user enumeration.
SSRF
Unrestricted webhook URL creating SSRF and data exfiltration risk.
Broken Access Control
Broken access control in the REST and GraphQL APIs that let a cashier create customer groups reserved for higher roles.
Open Redirect
Open redirect, reported with a detailed proof of concept.
04 / PROJECTS
Nine-phase recon automation tool that chains subfinder, amass, httpx, ffuf, waybackurls, gau, nuclei and trufflehog into one repeatable pipeline.
Captures and analyzes live network traffic.
A minimal shell implementing core commands and process management.
Three-role maintenance platform for Admin, Technician and User.
Booking, cancellation and admin modules.
Expense tracking and restaurant delivery web applications.
Routing, switching, VLAN and troubleshooting labs.
05 / SKILLS
06 / CERTIFICATES
Showing 12 certificates
Introduction to Networks
Cisco Networking Academy
CCNA curriculum
Network Basics
Cisco Networking Academy
CCNA Curriculum (completed)
Cisco Networking Academy
eJPT v2
INE Security
Junior Penetration Tester
eWPTX
INE Security · Web Application Penetration Tester eXtreme
eCPPT
INE Security · Certified Professional Penetration Tester
07 / ACHIEVEMENTS
CyberTalents, Cairo. Qualified for the on-site finals, then placed second.
Community outreach and hackathon promotion.
Volunteer at a charity organization.
08 / CONTACT
Email is the fastest way to reach me. For security vulnerability reports or program invitations, I review details and respond promptly.