GET /about HTTP/1.1200 OK
About
I'm mostly into breaking stuff and figuring out how it works 😄
I'm really into web pentesting, AppSec, DevSecOps, CTFs, and lately I've been getting more into low-level stuff like binary exploitation and reverse engineering.
Basically, I just enjoy learning how things work under the hood and seeing what I can make them do.
Outside of tech, I'm a chess player and I enjoy a good hike ♟️🥾
- Degree
- Engineering in Information Systems & Networks, TEK-UP University Tunisia, Sep 2021 to Jul 2026
- Exchange
- Hochschule Schmalkalden, Germany, Academic Mobility Program, Apr 2026 to Mar 2027
- Based
- Germany
- Certs
- eWPTX · eWPT · eJPT · CKA · PCAP
- Languages
- English · French · Arabic
- CRITICALCVE-2025-9094 ↗
Discovered and published a client-side template injection (CSTI) vulnerability in ThingsBoard.
- HIGHIntigriti Monthly Challenge, June 2026
Authored and published the official monthly XSS challenge on Intigriti: dangling markup injection against a strict CSP.
- MEDIUMBug Bounty Research
Ongoing bug bounty research and vulnerability reporting on public and private programs.
L3ak CTF
Team member, top 10 worldwide on CTFtime
Web and misc categories. 1st place at ImaginaryCTF, COMPFEST CTF, PatriotCTF, RITSEC CTF, UMassCTF and BearcatCTF. Top 15 at Blackhat MEA International CTF. Challenge author for L3ak CTF, played by 1000+ teams worldwide.
Securinets TEK-UP
Technical Director
Deployed and ran CTF infrastructure for international competitions. 1st place at CyberSphere Congress Advanced CTF.
- ·Burp Suite
- ·OWASP Top 10
- ·OWASP ASVS
- ·API security testing
- ·CVSS v3.1
- ·PTES reporting
- ·Secure code review (Python)
- ·Threat modeling (STRIDE)
- ·SAST · DAST · SCA
- ·SonarQube
- ·Trivy
- ·Gitleaks
- ·DefectDojo
- ·GitHub Actions
- ·Jenkins
- ·Docker
- ·Kubernetes
- ·Nginx
- ·Wazuh
- ·Python
- ·TypeScript
- ·FastAPI
- ·Bash
- ·SQL
- ·Git