xxhalyl · Application Security Suite v2026.8 · project: gammar-portfolio.burp

GET /about HTTP/1.1200 OK

About

Response bodytext/plain

I'm mostly into breaking stuff and figuring out how it works 😄

I'm really into web pentesting, AppSec, DevSecOps, CTFs, and lately I've been getting more into low-level stuff like binary exploitation and reverse engineering.

Basically, I just enjoy learning how things work under the hood and seeing what I can make them do.

Outside of tech, I'm a chess player and I enjoy a good hike ♟️🥾

Degree
Engineering in Information Systems & Networks, TEK-UP University Tunisia, Sep 2021 to Jul 2026
Exchange
Hochschule Schmalkalden, Germany, Academic Mobility Program, Apr 2026 to Mar 2027
Based
Germany
Certs
eWPTX · eWPT · eJPT · CKA · PCAP
Languages
English · French · Arabic
Certifications0x05 entries
Security researchdisclosure log
  • Discovered and published a client-side template injection (CSTI) vulnerability in ThingsBoard.

  • HIGHIntigriti Monthly Challenge, June 2026

    Authored and published the official monthly XSS challenge on Intigriti: dangling markup injection against a strict CSP.

  • MEDIUMBug Bounty Research

    Ongoing bug bounty research and vulnerability reporting on public and private programs.

Community0x02 entries
  • L3ak CTF

    Team member, top 10 worldwide on CTFtime

    Web and misc categories. 1st place at ImaginaryCTF, COMPFEST CTF, PatriotCTF, RITSEC CTF, UMassCTF and BearcatCTF. Top 15 at Blackhat MEA International CTF. Challenge author for L3ak CTF, played by 1000+ teams worldwide.

  • Securinets TEK-UP

    Technical Director

    Deployed and ran CTF infrastructure for international competitions. 1st place at CyberSphere Congress Advanced CTF.

Issue activity · skills by severity5 categories
CRITICALWeb Penetration Testing
  • ·Burp Suite
  • ·OWASP Top 10
  • ·OWASP ASVS
  • ·API security testing
  • ·CVSS v3.1
  • ·PTES reporting
HIGHAppSec & Secure SDLC
  • ·Secure code review (Python)
  • ·Threat modeling (STRIDE)
  • ·SAST · DAST · SCA
  • ·SonarQube
  • ·Trivy
  • ·Gitleaks
  • ·DefectDojo
MEDIUMDevSecOps
  • ·GitHub Actions
  • ·Jenkins
  • ·Docker
  • ·Kubernetes
  • ·Nginx
  • ·Wazuh
LOWDevelopment
  • ·Python
  • ·TypeScript
  • ·FastAPI
  • ·Bash
  • ·SQL
  • ·Git
© 2026 Mohamed Khalil Gammar
Tab: About21:22:51 UTC