Ahmed Abdalrhman
alzeaty
I break lab machines on my own time and write down the exact request that worked.
- TARGET
- alzeaty1
- SCOPE
- web applications · networks · recon
- POSTURE
- junior, actively hunting
- STATUS
- [ ● open to opportunities ]
Position
I am a junior penetration tester. I work through self-directed lab machines — TryHackMe rooms, PortSwigger Academy — and write up what I find step by step so I can reread it later.
My focus is web application and network work: authentication and access control flaws, injection, exposed cloud credentials, and traffic analysis.
Proof
- 01 NTI / NTRA Cybersecurity Academy
National Telecom Institute, Ministry of Communications.
- 02 TryHackMe Advent of Cyber 2025
24 challenges completed. Certificate ID THM-I1Q2HMQIIO.
- 03 PortSwigger Web Security Academy
All Access Control and Authentication labs.
Background
Al Nour Tech, 2019–2021 — IT and network engineering.
Freelance web development, 2021–2023. The security work came out of that.
Writeups
- 01
Beach Bar — PyYAML Deserialization RCE and Root Privilege Escalation via Process Arguments
Unsafe Deserialization (PyYAML RCE), Default Credentials, Credential Exposure in Process Arguments, Password Reuse, Privilege Escalation
- 02
Complimentary — Overprivileged Cognito unauthenticated role with dynamodb:Scan
AWS Cognito identity pool misconfiguration, IAM overprivileged role, DynamoDB Scan exposure, NoSQL data exfiltration
- 03
CryptoCabana — Azure Blob SAS token abuse to Key Vault secret rotation
exposed cloud credentials, Azure Blob Storage SAS token, service principal abuse, Azure Key Vault, secret rotation
- 04
Do Not Disturb — NoSQL login bypass to EJS RCE and a loopback Node Inspector pivot
NoSQL Injection, Server-Side Template Injection, Remote Code Execution, Privilege Escalation
Tool
ctf-crypto-analysis-tool — github.com/alzeaty1/ctf-crypto-analysis-tool. A modular crypto analysis CLI with a plugin registry, a pytest suite, MIT licensed. It covers XOR analysis (known-key, single-byte brute force, and repeating-key recovery via column scoring with beam search), entropy and English-language scoring, and ECB repeated-block detection. One cipher family is implemented so far; the rest of the registry is scaffolding.
Notes
A separate set of reading notes on other people’s published bug bounty writeups — what they did, what I would try differently. These are notes on other authors’ findings, not my own.
Contact
- Email ahmedabdalrhman838@gmail.com
- GitHub github.com/alzeaty1
- TryHackMe tryhackme.com/p/ALZeaty
- LinkedIn linkedin.com/in/ahmed-abdalrhman838