$ whoami

Hi Stranger! I am Youssef Aboukir known as onevilx, a Bug Bounty Hunter and Software Engineer at 1337 School (42 Network · Level 10.22) based in Casablanca, Morocco.

My pursuit is centered around a simple offensive doctrine: finding the friction points where abstract system architecture breaks under real-world protocol mechanics. Whether intercepting HTTP pipeline traffic, uncovering parser confusion in microservices, or building custom UNIX servers from scratch in raw C/C++, I dissect technology to master how it functions—and how to make it fail.

I like to break things lol


My Approach

  • Web Security Research — Actively hunting for logic flaws, authorization bypasses, and race conditions across multi-cloud architectures.
  • Low-Level Engineering — Building custom network protocols, shells, and UNIX daemons from scratch in C/C++ without relying on heavy frameworks.
  • CTFs & Wargames — Competing in advanced web exploitation, OSINT, and cryptography challenges.

Bug Bounty Experience

Actively hunting across Intigriti (100% Valid Ratio · View Profile) and Bugcrowd (66.67% Accuracy · View Profile), focused exclusively on high-impact logic failures, Low-Level memory/cryptographic flaws, and multi-cloud vulnerability discovery.

Selected Findings & CTFs

  • Private Cryptocurrency Custodian (Core C++ Cryptographic Engine)
    Vulnerability: OOB Heap Read & Fiat-Shamir Binding Flaw in MtA ZKP (P3 Severity · Broken Cryptography)
    Uncovered an Out-of-Bounds heap buffer overflow (CWE-125) and a Fiat-Shamir transcript binding flaw within a Zero-Knowledge Proof pipeline by debugging cryptographic key commitment serialization in raw C++ using AddressSanitizer (ASAN).

  • B2B DevSecOps Platform (Internal Supply Chain Tooling)
    Vulnerability: HTTP Proxy Malware Scanning Bypass (Medium Severity · CVSS 5.9)
    Uncovered a critical design logic hole where package verification and malware scanning routines were completely skipped when traffic was routed through non-TLS HTTP proxies, exposing build chains to malicious payloads.

  • European Micro-Mobility Enterprise (Internal Enterprise Backends)
    Vulnerability: Unauthenticated PII Exposure & OTP Rate-Limit Exploitation (Medium Severity · CVSS 5.3)
    Discovered unauthenticated backend endpoints exposing sensitive employee information coupled with internal authentication mechanism rate-limiting bypasses.

  • Leading Global SaaS Provider (Internal Service Integration Module)
    Vulnerability: Server-Side Request Forgery (SSRF) & Credential Exfiltration via Insecure Redirects
    Identified improper 301/302 HTTP redirection handling where secret authorization headers and POST bodies are preserved across cross-origin boundaries, enabling internal network SSRF against cloud metadata services and backend microservices.

  • Intigriti July 2026 Challenge Winner
    Vulnerability: TOCTOU Authorization Bypass via JSON Duplicate Key Parsing Inconsistencies
    Bypassed cryptographic namespace authorization controls in a multi-microservice infrastructure by exploiting divergent JSON duplicate-key parsing behaviors between validation daemons and storage engines.

  • Intigriti LeakyJar CTF Challenge
    Vulnerability: Cross-Site Request Forgery (CSRF) via Relaxed SameSite Boundary
    Exploited an insecure SameSite=None authentication state on a document-sharing endpoint to forge requests and exfiltrate administrative secret vaults.

  • Cyber Odyssey 2025 National Finalist (Akasec × 1337)
    Competed in Morocco’s premier 24-hour cybersecurity championship among 500+ security operators, tackling complex web exploitation, forensic anomaly analysis, and custom cryptographic puzzles.


Technical Arsenal

Offensive Security & Pentesting

  • Web Applications & API: Burp Suite Professional, OWASP Top 10 Triage, IDOR / Broken Access Control, Server-Side Template Injection (SSTI), CSRF, API Authentication Exploitation.
  • Protocol & Network Recon: Nmap, Wireshark Packet Inspection, Traffic Interception, Custom Python Exploitation Scripting, Automated Reconnaissance Pipelines, Advanced OSINT.

Systems Engineering & Languages

  • Core Languages: POSIX C, Modern C++, Python 3, Bash / Shell Scripting, JavaScript / Node.js.
  • Low-Level Concepts: Non-Blocking Socket Programming, Inter-Process Communication (IPC), POSIX Signal Handling, Fork/Exec Process Management, Memory Safety & Leak Debugging (Valgrind/GDB).

Infrastructure & DevOps Security

  • Containerization: Docker, Docker Compose Multi-Container Orchestration, Isolated Volume Mounts, Secret Hardening.
  • Network & Server Administration: Nginx Reverse Proxies, Linux/Unix Hardening, UFW Firewall Policies, Strict SSH Access Enforcement, MariaDB / Relational Databases.

Notable Systems Builds (1337 / 42 Network)

  • ft_irc — Custom High-Performance IRC Server
    Engineered an fully compliant Internet Relay Chat server in C++98 from the ground up. Utilizes non-blocking I/O polling (poll()), custom authentication protocols, dynamic channel multiplexing, and robust edge-case socket disconnect handling without external networking libraries.

  • Minishell — POSIX-Compliant UNIX Command Shell
    Built a native interactive Unix shell in C. Features tokenization and lexical parsing for custom pipelines (|), input/output redirections (>, <, >>, << here-docs), built-in POSIX utilities, environment variable expansion, and precise signal handling (Ctrl-C, Ctrl-\).

  • Inception — Hardened Multi-Container Infrastructure
    Designed a highly resilient containerized Linux deployment utilizing custom Dockerfiles. Orchestrates isolated networking between Nginx TLS reverse proxies, automated WordPress daemon management, and secured MariaDB data persistence.

  • Cub3D — 3D Raycasting Engine in Raw C
    Developed a retro Wolfenstein-inspired 3D graphical renderer in raw C using linear algebra and Digital Differential Analysis (DDA) raycasting mathematics, incorporating custom texture mapping and smooth collision detection.


Operator Timeline

  • 1337 School (42 Network) · 2024 — Present
    Software Engineering & Cybersecurity Specialization · Level 10.22 Achieved · Khouribga, Morocco.
  • Intelcia Group · 2023 — 2024
    Customer Operations Specialist · Casablanca, Morocco.
  • Faculty of Sciences Ain Chock · 2022 — 2023
    Biology, Geology, & Chemistry (BGC) · Casablanca, Morocco.

Let’s Connect

I am constantly seeking challenging security engineering roles, bug bounty collaborations, and offensive research opportunities. If you are building resilient architectures or breaking down high-value targets, let’s talk.