Maksudur Rahman

Professional Web Application Penetration Tester | Cybersecurity Specialist | Ethical Hacker

📧 Contact Me

About Me

I am Maksudur Rahman Rony, a passionate Web Application Penetration Tester & Cybersecurity Specialist with hands-on experience in:

✅ Web Application Security (OWASP Top 10, API Security, Authentication & Access Control Testing).

✅ Reconnaissance & Bug Bounty Hunting (Subdomain Enumeration, JS File Analysis, Secret Hunting, Github Recon, API Fuzzing).

✅ Advanced Exploitation Techniques (SSRF, SSTI, XXE, SQLi, XSS, CSRF, CORS, Host Header Injection, File Upload Exploits).

✅ Vulnerability Assessment using industry tools like Burp Suite, Nuclei, Subfinder, Katana, FFUF, wpscan etc.

✅ Cloud & Source Code Security (Secret Leakage, Git Dorking, API Key Exposure, JWT Attacks).

I have completed CEH (10+ modules), covered almost all of OSCP (Active Directory pending), and hold a strong track record in practical platforms like TryHackMe 30+ rooms solved.

💡 My goal is to secure applications by identifying and fixing vulnerabilities before attackers exploit them.

My Resume/CV

View My CV

🛡️ Skills

Languages: C, Python, Bash Scripting

🚀 Highlighted Projects

🔗 User Input Injection Cheatsheet

View Project
All known user input-based injection methods categorized with payloads.

🔗 Bugscope-pro

View Project
Automated bug bounty scanning tool.

🔗 ShadowSpectre

View Project
Red team reconnaissance and enumeration toolkit.

🔗 CVEHawk

View Project
Real-time CVE scanner for critical vulnerabilities.

🔗 NoSQL Injection Writeup

View Project
Detailed walkthrough of exploiting NoSQL-based login bypasses.

🔗 TryHackMe Writeups

View Project
All of Maksudur Rahman's detailed challenge solutions on TryHackMe.

🔗 Social Links

💼 Services Offered

Web Application Pentest

Comprehensive black-box and gray-box testing of web applications to find security flaws following OWASP standards.

Vulnerability Assessment + Report

Automated and manual scanning with detailed reporting including risk ratings and remediation steps.

Bug Bounty Style Testing

Simulated bug bounty engagements focused on real-world attack vectors with PoC writeups.

🏅 Labs & Achievements

My Tryhackme Profile

https://tryhackme.com/p/Maksudurrahman495