$ whoami
Hi Stranger! I am Youssef Aboukir known as onevilx, a Bug Bounty Hunter and Software Engineer at 1337 School (42 Network · Level 10.22) based in Casablanca, Morocco.
My pursuit is centered around a simple offensive doctrine: finding the friction points where abstract system architecture breaks under real-world protocol mechanics. Whether intercepting HTTP pipeline traffic, uncovering parser confusion in microservices, or building custom UNIX servers from scratch in raw C/C++, I dissect technology to master how it functions—and how to make it fail.
I like to break things lol
My Approach
- Web Security Research — Actively hunting for logic flaws, authorization bypasses, and race conditions across multi-cloud architectures.
- Low-Level Engineering — Building custom network protocols, shells, and UNIX daemons from scratch in C/C++ without relying on heavy frameworks.
- CTFs & Wargames — Competing in advanced web exploitation, OSINT, and cryptography challenges.
Bug Bounty Experience
Actively hunting across Intigriti (100% Valid Ratio · View Profile) and Bugcrowd (66.67% Accuracy · View Profile), focused exclusively on high-impact logic failures, Low-Level memory/cryptographic flaws, and multi-cloud vulnerability discovery.
Selected Findings & CTFs
-
Private Cryptocurrency Custodian (Core C++ Cryptographic Engine)
Vulnerability: OOB Heap Read & Fiat-Shamir Binding Flaw in MtA ZKP (P3 Severity · Broken Cryptography)
Uncovered an Out-of-Bounds heap buffer overflow (CWE-125) and a Fiat-Shamir transcript binding flaw within a Zero-Knowledge Proof pipeline by debugging cryptographic key commitment serialization in raw C++ using AddressSanitizer (ASAN). -
B2B DevSecOps Platform (Internal Supply Chain Tooling)
Vulnerability: HTTP Proxy Malware Scanning Bypass (Medium Severity · CVSS 5.9)
Uncovered a critical design logic hole where package verification and malware scanning routines were completely skipped when traffic was routed through non-TLS HTTP proxies, exposing build chains to malicious payloads. -
European Micro-Mobility Enterprise (Internal Enterprise Backends)
Vulnerability: Unauthenticated PII Exposure & OTP Rate-Limit Exploitation (Medium Severity · CVSS 5.3)
Discovered unauthenticated backend endpoints exposing sensitive employee information coupled with internal authentication mechanism rate-limiting bypasses. -
Leading Global SaaS Provider (Internal Service Integration Module)
Vulnerability: Server-Side Request Forgery (SSRF) & Credential Exfiltration via Insecure Redirects
Identified improper 301/302 HTTP redirection handling where secret authorization headers and POST bodies are preserved across cross-origin boundaries, enabling internal network SSRF against cloud metadata services and backend microservices. -
Intigriti July 2026 Challenge Winner
Vulnerability: TOCTOU Authorization Bypass via JSON Duplicate Key Parsing Inconsistencies
Bypassed cryptographic namespace authorization controls in a multi-microservice infrastructure by exploiting divergent JSON duplicate-key parsing behaviors between validation daemons and storage engines. -
Intigriti LeakyJar CTF Challenge
Vulnerability: Cross-Site Request Forgery (CSRF) via Relaxed SameSite Boundary
Exploited an insecureSameSite=Noneauthentication state on a document-sharing endpoint to forge requests and exfiltrate administrative secret vaults. -
Cyber Odyssey 2025 National Finalist (Akasec × 1337)
Competed in Morocco’s premier 24-hour cybersecurity championship among 500+ security operators, tackling complex web exploitation, forensic anomaly analysis, and custom cryptographic puzzles.
Technical Arsenal
Offensive Security & Pentesting
- Web Applications & API: Burp Suite Professional, OWASP Top 10 Triage, IDOR / Broken Access Control, Server-Side Template Injection (SSTI), CSRF, API Authentication Exploitation.
- Protocol & Network Recon: Nmap, Wireshark Packet Inspection, Traffic Interception, Custom Python Exploitation Scripting, Automated Reconnaissance Pipelines, Advanced OSINT.
Systems Engineering & Languages
- Core Languages: POSIX C, Modern C++, Python 3, Bash / Shell Scripting, JavaScript / Node.js.
- Low-Level Concepts: Non-Blocking Socket Programming, Inter-Process Communication (IPC), POSIX Signal Handling, Fork/Exec Process Management, Memory Safety & Leak Debugging (Valgrind/GDB).
Infrastructure & DevOps Security
- Containerization: Docker, Docker Compose Multi-Container Orchestration, Isolated Volume Mounts, Secret Hardening.
- Network & Server Administration: Nginx Reverse Proxies, Linux/Unix Hardening, UFW Firewall Policies, Strict SSH Access Enforcement, MariaDB / Relational Databases.
Notable Systems Builds (1337 / 42 Network)
-
ft_irc — Custom High-Performance IRC Server
Engineered an fully compliant Internet Relay Chat server in C++98 from the ground up. Utilizes non-blocking I/O polling (poll()), custom authentication protocols, dynamic channel multiplexing, and robust edge-case socket disconnect handling without external networking libraries. -
Minishell — POSIX-Compliant UNIX Command Shell
Built a native interactive Unix shell in C. Features tokenization and lexical parsing for custom pipelines (|), input/output redirections (>,<,>>,<<here-docs), built-in POSIX utilities, environment variable expansion, and precise signal handling (Ctrl-C,Ctrl-\). -
Inception — Hardened Multi-Container Infrastructure
Designed a highly resilient containerized Linux deployment utilizing custom Dockerfiles. Orchestrates isolated networking between Nginx TLS reverse proxies, automated WordPress daemon management, and secured MariaDB data persistence. -
Cub3D — 3D Raycasting Engine in Raw C
Developed a retro Wolfenstein-inspired 3D graphical renderer in raw C using linear algebra and Digital Differential Analysis (DDA) raycasting mathematics, incorporating custom texture mapping and smooth collision detection.
Operator Timeline
- 1337 School (42 Network) · 2024 — Present
Software Engineering & Cybersecurity Specialization · Level 10.22 Achieved · Khouribga, Morocco. - Intelcia Group · 2023 — 2024
Customer Operations Specialist · Casablanca, Morocco. - Faculty of Sciences Ain Chock · 2022 — 2023
Biology, Geology, & Chemistry (BGC) · Casablanca, Morocco.
Let’s Connect
I am constantly seeking challenging security engineering roles, bug bounty collaborations, and offensive research opportunities. If you are building resilient architectures or breaking down high-value targets, let’s talk.
- Email: onevilx@intigriti.me
- LinkedIn: linkedin.com/in/onevilx
- GitHub: github.com/onevilx
onevilx