Skip to content
View mehedi-hasan-sami98's full-sized avatar

Block or report mehedi-hasan-sami98

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Hi πŸ‘‹, I'm Mehedi Hasan Sami

Junior Penetration Tester | Web Application Security | CEH Certified

πŸ“ Dhaka, Bangladesh Β |Β  πŸ“§ samicse18@gmail.com Β |Β  πŸ“ž +880 1778-233649 Β |Β  πŸ”— LinkedIn 🌐 website


πŸ™‹ About Me

Detail-oriented Junior Penetration Tester with hands-on internship experience in vulnerability assessment, web application security, and network security testing. CEH-certified, proficient in Burp Suite, Nmap, Wireshark, Metasploit, and OWASP ZAP. Skilled at identifying, documenting, and reporting security vulnerabilities with clear, actionable remediation recommendations.

  • πŸ”­ Currently strengthening skills in web application penetration testing and network security
  • 🎯 Seeking opportunities to apply analytical skills to strengthen organizational cybersecurity posture
  • 🌱 Continuous learner β€” always exploring new offensive security techniques and methodologies
  • πŸ’¬ Ask me about vulnerability assessment, OWASP Top 10, or network reconnaissance

πŸ› οΈ Skills & Tools

Cybersecurity Domains Penetration Testing Β· Vulnerability Assessment Β· Web Application Security Β· Network Security Β· Information Security Β· Security Testing

Operating Systems Kali Linux Β· Linux Β· Windows

Tools Nmap Β· Burp Suite Β· Wireshark Β· Metasploit Β· OWASP ZAP Β· Nessus Β· John the Ripper Β· Cisco Packet Tracer

Soft Skills Problem Solving Β· Analytical Thinking Β· Teamwork Β· Communication Β· Time Management Β· Report Writing


πŸŽ“ Education

Bachelor of Science in Computer Science and Technology Z.H. Sikder University of Science and Technology, Shariatpur β€” Graduated 2022


πŸ’Ό Experience

Penetration Tester Intern β€” Creative IT Institute, Dhanmondi, Dhaka February 2026 – June 2026

  • Completed a 5-month hands-on internship in penetration testing and cybersecurity with a 100% completion rate
  • Performed vulnerability assessments on web applications, identifying SQL Injection, XSS, and CSRF issues
  • Participated in real-world security assignments and technical workshops using industry-standard tools and methodologies
  • Assessed and prioritized security vulnerabilities based on risk using structured analytical methods
  • Authored professional vulnerability assessment and traffic analysis reports with actionable remediation recommendations

πŸ† Certifications

Certification Issuer Date
Certified Penetration Testing – Level 4 National Skills Development Authority (NSDA) May 2026
Certified Ethical Hacker (CEH) Creative IT Institute July 2024
Ethical Hacker CISCO July 2026
Certified Phishing Prevention Specialist Hack & Fix December 2025
Intro to Critical Infrastructure Protection OPSWAT December 2025
Certified Cybersecurity Educator Professional Red Team Leaders June 2026
CCNA Khulna University of Engineering & Technology July 2023

πŸ”— Featured Projects

  • πŸ”“ DVWA-ZAP-PENTEST β€” Web application security assessment of DVWA using OWASP ZAP; vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report
  • 🌐 nmap-recon-toolkit β€” Professionally documented Nmap reconnaissance reference covering host discovery, port scanning, OS fingerprinting, and NSE scripting
  • πŸ›‘οΈ nessus-vulnerability-assessment β€” Nessus-based vulnerability scanning and assessment reporting
  • πŸ”‘ Password Security Analysis β€” Password strength testing in a controlled lab using John the Ripper; recommended strong password policies
  • πŸ“‘ Network Monitoring using Wireshark β€” Captured and analyzed HTTP, DNS, and TCP traffic; identified suspicious packets and protocol behavior
  • πŸ—οΈ Cisco Packet Tracer Enterprise Network Design β€” Designed a secure enterprise network topology with VLANs, ACLs, DHCP, and OSPF

πŸ₯‡ Awards

Cybersafe (Securing Assets for the End User) β€” DASPIB, July 2025 Completed training on cybersecurity fundamentals, protecting digital assets, identifying cyber threats, and maintaining safe online practices.


πŸ“Š GitHub Stats

GitHub Streak

Mehedi's GitHub stats Top Langs


🌐 Languages

English Β· Bangla (Native)


πŸ“« Let's connect and strengthen cybersecurity together!

Popular repositories Loading

  1. nmap-recon-toolkit nmap-recon-toolkit Public

    A professionally documented Nmap reconnaissance reference covering host discovery, port scanning, OS fingerprinting, and NSE scripting β€” with flag-by-flag breakdowns, example output, and ethical-us…

    Shell 1

  2. burpsuite-pentest-guide burpsuite-pentest-guide Public

    Practical Burp Suite guide for web application penetration testing β€” proxy setup, core modules (Repeater, Intruder, Decoder), and real-world testing examples (SQLi, XSS, IDOR, brute-force).

    1

  3. feroxbuster-recon-lab feroxbuster-recon-lab Public

    Hands-on lab guide to feroxbuster β€” recursive content discovery for web app penetration testing, with real scan walkthrough and findings.

    1

  4. DVWA-ZAP-PENTEST DVWA-ZAP-PENTEST Public

    Web application security assessment of DVWA using OWASP ZAP β€” vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

  5. nessus-vulnerability-assessment nessus-vulnerability-assessment Public

    Network vulnerability assessment using Tenable Nessus β€” scan methodology, severity analysis, and remediation reporting.

  6. whois-dns-lookup whois-dns-lookup Public

    A web based tool to gather WHOIS domain registration info and DNS records (A, AAAA, MX, NS, TXT, SOA, CNAME) with automatic DNS health checks β€” built for security recon and domain monitoring.

    Python