Founder and Managing Director of HafezSecure · Application security and penetration testing · Burp Suite extension author
I'm the founder and managing director of HafezSecure, a cybersecurity company that delivers vulnerability assessment and penetration testing, secure development, runtime protection and monitoring, and security advisory. My own focus is web, API and mobile application security: I have led vulnerability assessment and penetration testing (VAPT) teams and worked on more than 1,000 enterprise penetration testing projects as a tester, project manager and team lead. I also build open-source Burp Suite extensions and vulnerable-by-design labs, so testers find real issues faster and learners can practise safely.
- 1,000+ enterprise penetration tests across web applications, APIs, Android and iOS apps, desktop software, networks and infrastructure.
- Two extensions in PortSwigger's BApp Store: Backup Finder and CVSS Calculator.
- Open-source tools and training labs starred, forked and pulled by the security community:
- CTF champion with multiple first-place finishes as part of the DCUA team.
| Extension | What it does | Install | Stars |
|---|---|---|---|
| Backup Finder | Finds backup, old, temporary and unreferenced files that leak sensitive data, using payloads generated from the target's own structure (OWASP WSTG-CONF-04) | BApp Store | |
| Admin Panel Finder | Enumerates exposed admin panels and login pages with 1,000+ built-in payloads and technology-aware wordlists (OWASP WSTG-CONF-05) | Release | |
| PassiveDigger | Passively analyses proxied traffic for SQL errors, reflected parameters, LFI hints, serialized data, weak cookie flags and missing security headers | Release | |
| CVSS Calculator | Scores vulnerabilities with CVSS v2 and v3.1 offline, without leaving Burp Suite | BApp Store |
Self-contained Docker labs for practising common web vulnerabilities and filter bypasses.
| Lab | Vulnerability class | Docker pulls |
|---|---|---|
| XSS challenges | Cross-site scripting and XSS filter bypasses | |
| File upload scenarios | Unrestricted file upload and upload-filter bypasses leading to code execution | |
| LFI to RCE | Local file inclusion escalated to remote code execution | |
| RFI scenarios | Remote file inclusion, one new bypass technique per challenge | |
| CAPTCHA logic bypass | Broken CAPTCHA logic that re-enables brute-force attacks | |
| DVWA behind ModSecurity | Attacking a web app protected by a ModSecurity WAF and tuning its rules | Docker Compose (no image) |
- Linux for Cyber Security: an open course with lectures, assignments and scripts, from Linux fundamentals to boot security, firewalls, SSH and hardening.
- Awesome Smart Contract Security: a curated guide to Solidity vulnerabilities (SWC, OWASP), audit tools, papers and courses.
- Cosmos Chain Security: a security guide for Cosmos SDK chains covering IBC, validators and DEXs, with an Osmosis case study.
Web application and API penetration testing · Mobile application security (Android, iOS) · OWASP WSTG and Top 10 · Burp Suite extension development in Java · Vulnerability scoring and management (CVSS) · Smart contract and blockchain security · Leading security testing teams
Need a penetration test, secure development support or security advice? Visit HafezSecure. Found a bug in one of my tools or labs? Open an issue on its repository. For anything else, reach me on LinkedIn.