$ whoami
Hi Stranger! I am Youssef Aboukir known as onevilx, a Bug Bounty Hunter and Software Engineer at 1337 School (42 Network · Level 10.22) based in Casablanca, Morocco.
My pursuit is centered around a simple offensive doctrine: finding the friction points where abstract system architecture breaks under real-world protocol mechanics. Whether intercepting HTTP pipeline traffic, uncovering parser confusion in microservices, or building custom UNIX servers from scratch in raw C/C++, I dissect technology to master how it functions - and how to make it fail.
I like to break things lol
My Approach
- Web Security Research — Actively hunting for logic flaws, authorization bypasses, and race conditions across multi-cloud architectures.
- Low-Level Engineering — Building custom network protocols, shells, and UNIX daemons from scratch in C/C++ without relying on heavy frameworks.
- CTFs & Wargames — Competing in advanced web exploitation challenges.
Bug Bounty Experience
Actively hunting across Intigriti (100% Valid Ratio · View Profile) and Bugcrowd (85.71% Accuracy · View Profile), focused exclusively on high-impact logic failures and multi-cloud vulnerability discovery.
Selected Findings & CTFs
-
Private B2B SaaS Platform (In-App AI Assistant API)
Vulnerability: Credentialed CORSlocalhostReflection → Cross-Origin Chat Exfiltration (CWE-942 · Reported High 8.2, Accepted Low)
Found an API reflecting alocalhostorigin alongsideAccess-Control-Allow-Credentials: true, fronted by a requiredApp-Idheader that was never validated — letting a loopback-origin page read a victim’s private AI-assistant conversation history, integration status, and tenant identifiers cross-origin. (Read writeup →) -
@vue/server-renderer(Vue core) — SSR XSS · GHSA-g2v6-rqmx-r4w6
Vulnerability: Attribute-Name Blacklist Missing\r→ Zero-Interaction Event Handler in SSR Output (~13.9M downloads/week · High · CVSS 7.2 · CWE-79 · Fixed v3.5.42)
Found thatssrRenderDynamicAttr()escaped attribute values but not attribute names — a carriage return absent from the name blacklist lets a singlev-bindobject key be reparsed by real browsers as three separate HTML attributes, including an event handler that fires on page load with no user interaction, turning server-rendered data into cross-user XSS on every visitor. Reported → confirmed and patched same-day → released in3.5.42, credited. (Read writeup →) -
nuxt-auth-utils— OAuth Login-CSRF · GHSA-xc49-mgwh-9pjv
Vulnerability: MissingstateValidation in 35/48 OAuth Providers (Moderate · CWE-352 · Fixed v0.5.30)
Discovered that 35 of 48 identity provider handlers — including Google, Discord, Microsoft, and Spotify — performed no OAuthstatevalidation, enabling login-CSRF / forced account linking. Confirmed via an executable differential PoC; patched by the maintainer same-day with a per-provider invariant test to prevent regression. (Read writeup →) -
@hono/oauth-providers— Weak Randomness · GHSA-6833-cxmv-fqjf
Vulnerability: OAuthstate& PKCEcode_verifierGenerated withMath.random()(Moderate · CWE-338 · Fixed v0.8.7)
Found that all OAuth state tokens and the X/Twitter PKCE code verifier were generated using V8’s xorshift128+ PRNG. Built a deterministic-reconstruction PoC showing tokens are a pure function of 3Math.random()draws — provably no more unpredictable than the recoverable PRNG state. (Read writeup →) -
ip-range-check— SSRF Denylist Bypass · GHSA-87xc-4hwr-pxf6
Vulnerability: Abbreviated IPv4 Notation Bypasses SSRF Guard (~390k downloads/week · Moderate · CWE-918 · Fixed v0.2.1)
Identified that127.1,127.0.1,0177.1, and127.0x1bypass the library’s private-IP denylist while still resolving to127.0.0.1at the OS level — a validator/connector disagreement caused by a stale bundledipaddr.js@1.9.1. Connect-verified with a live loopback server PoC. (Read writeup →) -
Intigriti July 2026 Challenge Winner
Vulnerability: TOCTOU Authorization Bypass via JSON Duplicate Key Parsing Inconsistencies
Bypassed cryptographic namespace authorization controls in a multi-microservice infrastructure by exploiting divergent JSON duplicate-key parsing behaviors between validation daemons and storage engines. -
Intigriti LeakyJar CTF Challenge
Vulnerability: Cross-Site Request Forgery (CSRF) via Relaxed SameSite Boundary
Exploited an insecureSameSite=Noneauthentication state on a document-sharing endpoint to forge requests and exfiltrate administrative secret vaults. -
Cyber Odyssey 2025 National Finalist (Akasec × 1337)
Competed in Morocco’s premier 24-hour cybersecurity championship among 500+ security operators, tackling complex web exploitation, forensic anomaly analysis, and custom cryptographic puzzles.
Technical Arsenal
Offensive Security & Pentesting
- Web Applications & API: Burp Suite Professional, OWASP Top 10 Triage, IDOR / Broken Access Control, Server-Side Template Injection (SSTI), CSRF, API Authentication Exploitation.
- Protocol & Network Recon: Nmap, Wireshark Packet Inspection, Traffic Interception, Custom Python Exploitation Scripting, Automated Reconnaissance Pipelines.
Systems Engineering & Languages
- Core Languages: POSIX C, Modern C++, Python 3, Bash / Shell Scripting, JavaScript / Node.js.
- Low-Level Concepts: Non-Blocking Socket Programming, Inter-Process Communication (IPC), POSIX Signal Handling, Fork/Exec Process Management, Memory Safety & Leak Debugging (Valgrind/GDB).
Infrastructure & DevOps Security
- Containerization: Docker, Docker Compose Multi-Container Orchestration, Isolated Volume Mounts, Secret Hardening.
- Network & Server Administration: Nginx Reverse Proxies, Linux/Unix Hardening, UFW Firewall Policies, Strict SSH Access Enforcement, MariaDB / Relational Databases.
Notable Systems Builds (1337 / 42 Network)
-
ft_irc — Custom High-Performance IRC Server
Engineered an fully compliant Internet Relay Chat server in C++98 from the ground up. Utilizes non-blocking I/O polling (poll()), custom authentication protocols, dynamic channel multiplexing, and robust edge-case socket disconnect handling without external networking libraries. -
Minishell — POSIX-Compliant UNIX Command Shell
Built a native interactive Unix shell in C. Features tokenization and lexical parsing for custom pipelines (|), input/output redirections (>,<,>>,<<here-docs), built-in POSIX utilities, environment variable expansion, and precise signal handling (Ctrl-C,Ctrl-\). -
Inception — Hardened Multi-Container Infrastructure
Designed a highly resilient containerized Linux deployment utilizing custom Dockerfiles. Orchestrates isolated networking between Nginx TLS reverse proxies, automated WordPress daemon management, and secured MariaDB data persistence. -
Cub3D — 3D Raycasting Engine in Raw C
Developed a retro Wolfenstein-inspired 3D graphical renderer in raw C using linear algebra and Digital Differential Analysis (DDA) raycasting mathematics, incorporating custom texture mapping and smooth collision detection.
Operator Timeline
- 1337 School (42 Network) · 2024 — Present
Software Engineering & Cybersecurity Specialization · Level 10.22 Achieved · Khouribga, Morocco. - Intelcia Group · 2023 — 2024
Customer Operations Specialist · Casablanca, Morocco. - Faculty of Sciences Ain Chock · 2022 — 2023
Biology, Geology, & Chemistry (BGC) · Casablanca, Morocco.
Let’s Connect
I am constantly seeking challenging security engineering roles, bug bounty collaborations, and offensive research opportunities. If you are building resilient architectures or breaking down high-value targets, let’s talk.
- Email: onevilx@intigriti.me
- LinkedIn: linkedin.com/in/onevilx
- GitHub: github.com/onevilx
onevilx