0xSecure
18 years old from Jeddah, Saudi Arabia.
Cybersecurity isn't just a hobby — it's my passion.
I specialize in ethical hacking and identifying vulnerabilities in web applications.
I continuously sharpen my skills through real-world challenges and practice.
Technical Skills
- Deep understanding of web protocols (HTTP/HTTPS, DNS, TCP/IP).
- Expertise in web security areas: authentication, session handling, validation.
- Experienced with OWASP Top 10 vulnerabilities (XSS, SQLi, CSRF, etc.).
- Linux command-line proficiency.
- Strong HTML, JS & browser security mechanisms knowledge.
Tools I Use
- Burp Suite (Scanner, Repeater, Intruder)
- Nmap, OWASP ZAP, Nikto, Dirsearch, FFUF
- Sublist3r, DNSdumpster, Shodan
- Custom scripts for automation & recon
Bug Hunting Workflow
- Start with recon (passive & active).
- Map endpoints, auth flows, and logic.
- Test inputs manually and with payloads.
- Document impact, PoC, and remediation.
- Submit clear, ethical reports.
Bug Bounty Platforms
- HackerOne
- Bugcrowd
- Intigriti
- Open Bug Bounty
- Private disclosure programs
Achievements
- Featured in Hall of Fame pages.
- Found critical bugs in production systems.
- Secured websites serving thousands of users.
- Recognized for ethical conduct & clear reports.
Current Focus
- Advanced WAF/auth bypass techniques.
- Python/bash automation for recon & scanning.
- Studying SSRF chains, deserialization bugs.
- Exploring mobile app security (Android/iOS).
My Mindset
Curiosity drives discovery.
Ethical hacking protects, not destroys.
Every system has a weakness — I find it first.
Persistence > raw talent.
Future Goals
- Achieve OSCP certification.
- Join a Red Team professionally.
- Create private recon/scanning tools.
- Contribute to open-source security projects.
- Mentor beginners in the community.
Community Engagement
- Active on Twitter, Discord security groups.
- Participate in CTFs & challenges.
- Read writeups & contribute knowledge.
- Encourage ethical, responsible hacking.