
Hello!
In this blog I aim to share my experiences, opinions, advise, and knowledge on various topics that resonate with me - from web app pentesting to AI red teaming.
Whoami
I’m Said-Abbosxon Nabijonov - cybersecurity professional (penetration tester), who started his journey in cyber from 0 back in May, 2024. Found 100+ vulnerabilities in various kinds of software and sectors - LLMs, Web apps, APIs, in sectors from Medicine to Logistics.
Interests:
- Internal Penetration Testing
- Active Directory Penetration testing
- AI Red Teaming
- Web Application Penetration Testing
Notable findings:
Bug Bounties and Security Testing outside of job:
- Reflected XSS
- HTML Injection
- Prompt Injection
- LLM Sensitive Information Disclosure
- 2FA Bypass
- Stored XSS
Penetration Tests:
- IDORs
- Stored and Reflected XSS
- SQL Injection
- XXE
- API Vulnerabilities
- Default credentials that led to an exposure of 5000+ records of sensitive data
- 403 Bypass
And many, many other ones…
My Social Media:
- X: @0trccc
- LinkedIn: in/0trc
- Medium: @0trccccc
- HackTheBox: my public profile
Additional:
Additionally, I created my own obsidian theme named “SAzure Glass”, which you can take a look at here:
Certs:
- eJPT
Junior Penetration Tester cert from INE Security. My very first cert in this field. After this course, I was familair with what EternalBlue is, and comofrtable with using the terminal, especially with using tools like Nmap and Metasploit.
- eWPT
Professional Web Application Penetration Tester cert from INE Security. Built a deeper understanding in me about Web Application security, learnt deeper about such automated tools like BurpSuite, OWASP ZAP, Nuclei, Nikto, and WPScan.
- eCPPT
Certified Professional Penetration Tester cert from INE Security. This exam was no joke. The course was awesome, but I believe that there are some sections in it that should be removed, and some techniques are, I believe, outdated. Great course to build fundamental understanding and experience of how internal and AD pentests work, how to privesc, brute force, and move laterally. Prerequisites: Have understanding of core penetration testing topics, some real world experience, and I’d recommend you would go here maybe after both eWPT and eJPT, alongside with real life experience.
- COAE
Certified Offensive AI Expert from HackTheBox. The exam was challenging, truly, but I enjoyed the exam. The course is as good as it gets - it builds your understanding of ML, LLMs, underlaying concepts and their use cases from 0 and then it takes you to a whole new, expert level. The course teaches you about both ML and LLM attacks, not just the prompt injection but whole spectre - awesome course, awesome. Prerequisites: Have prior web, reporting, and internal pentesting knowledge. I recommend you go here after CWES and CPTS or similair web and internal pentest certs.