Skip to content
View xbz0n's full-sized avatar

Block or report xbz0n

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
xbz0n/README.md

Ivan Spiridonov | xbz0n

👨‍💻 Penetration Tester

Specialized in discovering and exploiting security vulnerabilities in web applications, networks, and infrastructure to help organizations improve their security posture.

🛠️ Expertise

  • Web Application Security: Identifying and exploiting vulnerabilities in web applications to prevent potential security breaches
  • Exploit Development: Creating proof-of-concept exploits for discovered vulnerabilities and developing custom security tools for specialized testing scenarios
  • Security Research: Discovering and responsibly disclosing vulnerabilities in software and systems with published CVEs

💻 Tech Stack & Skills

Python Bash PowerShell x86 Assembly C++ C#
Metasploit Burp Suite Wireshark Nmap OWASP ZAP IDA Pro
Kali Linux Windows Linux Active Directory AWS

🔬 Latest Research & Blog Articles

🛠️ Open Source Security Tools

  • AspXVenom: Generates encoded shellcode and embeds it into ASPX webshells for .NET environments testing
  • AutoMSF: Python script for generating and deploying multiple types of Meterpreter reverse_https payloads
  • MacroPhantom: Creates XOR+Caesar encrypted shellcode and embeds it into VBA macros for Office documents
  • GoPhish-Deploy: Automates deployment of the GoPhish phishing framework with SSL and secure defaults
  • InterceptReady: Toolkit for configuring Android emulators with Frida and Burp Suite for mobile security testing

🔐 CVEs Discovered

  • CVE-2025-50674: Privilege escalation vulnerability in OpenMediaVault
  • CVE-2024-32136: SQL injection vulnerability in database systems
  • CVE-2023-0830: Vulnerability in EasyNAS backup allowing arbitrary command execution with root privileges
  • CVE-2024-0365: System components security flaw allowing privilege escalation
  • CVE-2024-0399: Critical vulnerability affecting data integrity and confidentiality
  • CVE-2024-0405: Input validation vulnerability leading to remote code execution
  • CVE-2024-0566: SQL injection vulnerability allowing data exfiltration
  • CVE-2024-30240: Critical SQL injection vulnerability allowing authentication bypass
  • CVE-2024-31370: Injection vulnerability allowing arbitrary code execution
  • CVE-2024-33911: Vulnerability affecting system configurations and security controls

🔗 Connect with me

GitHub Twitter LinkedIn HackTheBox Medium Website Email

Pinned Loading

  1. AspXVenom AspXVenom Public

    AspXVenom automates the process of generating encoded shellcode and embedding it into ASPX webshells, providing a smooth workflow for penetration testers during security assessments. The tool is sp…

    Python 19 7

  2. AutoMSF AutoMSF Public

    AutoMSF is a Python script designed for fast generation and deployment of multiple types of Meterpreter reverse_https payloads. Created to aid in OSEP challenges and exams, it generates C#, EXE, VB…

    Python 19 4

  3. MacroPhantom MacroPhantom Public

    MacroPhantom automates the process of generating XOR+Caesar encrypted shellcode and embedding it into VBA macros for Microsoft Office documents. The tool streamlines the workflow for security profe…

    Python 22 4

  4. gophish-deploy gophish-deploy Public

    GoPhish-Deploy is an automated deployment script for the GoPhish phishing framework, configuring it with SSL and secure defaults.

    Python 15 4

  5. InterceptReady InterceptReady Public

    InterceptReady is an automated toolkit for configuring Android emulators with Frida and Burp Suite for mobile security testing.

    JavaScript 11 4