Hey There!
I’m Ibrahim Saify

Cybersecurity Researcher and Ethical Hacker.

  • 10 Websites Secured
  • 85+ TryHackMe Labs Completed
  • 100+ PortSwigger Labs completed

About Me

I am currently a Final year Computer Science and Engineering Student at IET DAVV, Indore. I have had a passion for Cybersecurity and Ethical Hacking since 3 years now and am continuosly looking to grow and get better. Always looking for opportunities to gain exposure and hands on experience in the industry and make valuable contributions in securing the digital world.

Core Skills

  • Web Security
  • System Security
  • Kali Linux
  • Steganography
  • OSINT
  • Digital Forensics
  • Burp Suite
  • Metasploit
  • Nmap
  • Python
  • Binary Exploitation

Other Skills

  • Computer Networks
  • MySQL
  • PHP
  • Cryptography

Work Experience

Nov 2023 - Present

CTF Developer

YCF Team

I am part of YCF's CTF Development and hosting team, for organizing University and Organisation based CTF Competitions. I contribute challenges over a wide range of categories such as Web Application Security, Steganography, OSINT, Binary Exploitation, and Digital Forensics. I have created over 30 challenges for CTFs which include:

  • University-based CTFs - CyberMania 2.0 2023, Cyber Knight CTF 2024, and Techonquer CTF 2024.
  • Organization-based CTFs - KnightCTF 2024, Nexus CTF 2024 and RVCExIITB CTF 2024
June 2023 - March 2024

VDPs (Vulnerability Disclosure Programs)

Security Researcher (VAPT)

I have performed VAPT (Vulnerability Assessment and Penetration Testing) on several VDPs and have discovered and reported security vulnerabilities to the organizations and websites. Some of the organizations that I have secured are:

  • NASA - Reflected XSS (P3 - Resolved) - Got Hall of Fame in NASA.
  • Duke University - Open Redirection and Reflected XSS (Resolved)
  • Merkle Inc. - Host Header Injection leads to Open Redirect and Possible Broken Authentication (Acknowledgement)
  • Online Learning Platform - Discovered massive PII leak of students and teachers (Full name, email addresses and phone numbers) on an online learning Platform via an API call's response [Critical Vulnerability]

Latest Project

OnePass

OnePass is a secure Password Management tool for Unix-Based Systems. It is developed using Python and has features for all your password services to ensure digital safety and make password management a breeze.

Details

Certificates and Achievements

CNSP - Certified Network Security Practitioner

Successfully passed the CNSP Exam with Merit. This exam by the SecOps Group, checks the understanding of core fundamentals in relation to network security topics. It also tests the knowledge of common security misconfigurations, the best security practices, defense-in-depth measures as well as an overview of how vulnerabilities can be exploited in the real world scenario.

Finalist (On-site) - IIT Bombay

Finalist at IIT Bombay's Trust Lab's Nation-wide CTF where the Finale was held at the campus of IIT Bombay itself. My team was part of the top 50 teams that were shortlisted among 800 teams in the First round which was held online.

1st Rank - CloudSEK 2024

Secured the First Rank in the CloudSEK Global Hiring CTF first online round out of 600 participants. It was a challenging competition which enhanced my skills and encouraged solving CTF challenges at a good pace.

Hall of Fame - NASA

Secured a place in NASA's Hall of Fame for discovering a Reflected Cross-Site Scripting vulnerability (XSS) which can lead to session hijacking of a logged in user/admin on one of their subdomains. The vulnerability was marked as P3 Priority and has now been resolved.

8th Rank - Vulnx CTF 2024

Secured 8th rank among 240 participants in the VulnX CTF 2024, featuring unique challenges that brought new concepts to light. An enjoyable experience overall.

King of The Hill - TryHackMe

I have won the KOTH tournament in TryHackMe where we have to compete with 5 other players to attack and defend a single Machine and maintain root access for the longest duration. We also have to keep capturing flags along the way and patch the virtual machine's vulnerabilities to ensure other players don't gain access or dont escalate privileges and ensure your persistence as root.

Advent of Cyber 2023 - TryHackMe

Successfully completed the 24-day Advent of Cyber 2023 challenge from TryHackMe. This intensive program featured daily cybersecurity challenges across a variety of categories, encompassing both Red Teaming and Blue Teaming disciplines.