$ whoami

Hi Stranger! I am Youssef Aboukir known as onevilx, a Bug Bounty Hunter and Software Engineer at 1337 School (42 Network · Level 10.22) based in Casablanca, Morocco.

My pursuit is centered around a simple offensive doctrine: finding the friction points where abstract system architecture breaks under real-world protocol mechanics. Whether intercepting HTTP pipeline traffic, uncovering parser confusion in microservices, or building custom UNIX servers from scratch in raw C/C++, I dissect technology to master how it functions - and how to make it fail.

I like to break things lol


My Approach

  • Web Security Research — Actively hunting for logic flaws, authorization bypasses, and race conditions across multi-cloud architectures.
  • Low-Level Engineering — Building custom network protocols, shells, and UNIX daemons from scratch in C/C++ without relying on heavy frameworks.
  • CTFs & Wargames — Competing in advanced web exploitation challenges.

Bug Bounty Experience

Actively hunting across Intigriti (100% Valid Ratio · View Profile) and Bugcrowd (85.71% Accuracy · View Profile), focused exclusively on high-impact logic failures and multi-cloud vulnerability discovery.

Selected Findings & CTFs

  • Private B2B SaaS Platform (In-App AI Assistant API)
    Vulnerability: Credentialed CORS localhost Reflection → Cross-Origin Chat Exfiltration (CWE-942 · Reported High 8.2, Accepted Low)
    Found an API reflecting a localhost origin alongside Access-Control-Allow-Credentials: true, fronted by a required App-Id header that was never validated — letting a loopback-origin page read a victim’s private AI-assistant conversation history, integration status, and tenant identifiers cross-origin. (Read writeup →)

  • @vue/server-renderer (Vue core) — SSR XSS · GHSA-g2v6-rqmx-r4w6
    Vulnerability: Attribute-Name Blacklist Missing \r → Zero-Interaction Event Handler in SSR Output (~13.9M downloads/week · High · CVSS 7.2 · CWE-79 · Fixed v3.5.42)
    Found that ssrRenderDynamicAttr() escaped attribute values but not attribute names — a carriage return absent from the name blacklist lets a single v-bind object key be reparsed by real browsers as three separate HTML attributes, including an event handler that fires on page load with no user interaction, turning server-rendered data into cross-user XSS on every visitor. Reported → confirmed and patched same-day → released in 3.5.42, credited. (Read writeup →)

  • nuxt-auth-utils — OAuth Login-CSRF · GHSA-xc49-mgwh-9pjv
    Vulnerability: Missing state Validation in 35/48 OAuth Providers (Moderate · CWE-352 · Fixed v0.5.30)
    Discovered that 35 of 48 identity provider handlers — including Google, Discord, Microsoft, and Spotify — performed no OAuth state validation, enabling login-CSRF / forced account linking. Confirmed via an executable differential PoC; patched by the maintainer same-day with a per-provider invariant test to prevent regression. (Read writeup →)

  • @hono/oauth-providers — Weak Randomness · GHSA-6833-cxmv-fqjf
    Vulnerability: OAuth state & PKCE code_verifier Generated with Math.random() (Moderate · CWE-338 · Fixed v0.8.7)
    Found that all OAuth state tokens and the X/Twitter PKCE code verifier were generated using V8’s xorshift128+ PRNG. Built a deterministic-reconstruction PoC showing tokens are a pure function of 3 Math.random() draws — provably no more unpredictable than the recoverable PRNG state. (Read writeup →)

  • ip-range-check — SSRF Denylist Bypass · GHSA-87xc-4hwr-pxf6
    Vulnerability: Abbreviated IPv4 Notation Bypasses SSRF Guard (~390k downloads/week · Moderate · CWE-918 · Fixed v0.2.1)
    Identified that 127.1, 127.0.1, 0177.1, and 127.0x1 bypass the library’s private-IP denylist while still resolving to 127.0.0.1 at the OS level — a validator/connector disagreement caused by a stale bundled ipaddr.js@1.9.1. Connect-verified with a live loopback server PoC. (Read writeup →)

  • Intigriti July 2026 Challenge Winner
    Vulnerability: TOCTOU Authorization Bypass via JSON Duplicate Key Parsing Inconsistencies
    Bypassed cryptographic namespace authorization controls in a multi-microservice infrastructure by exploiting divergent JSON duplicate-key parsing behaviors between validation daemons and storage engines.

  • Intigriti LeakyJar CTF Challenge
    Vulnerability: Cross-Site Request Forgery (CSRF) via Relaxed SameSite Boundary
    Exploited an insecure SameSite=None authentication state on a document-sharing endpoint to forge requests and exfiltrate administrative secret vaults.

  • Cyber Odyssey 2025 National Finalist (Akasec × 1337)
    Competed in Morocco’s premier 24-hour cybersecurity championship among 500+ security operators, tackling complex web exploitation, forensic anomaly analysis, and custom cryptographic puzzles.


Technical Arsenal

Offensive Security & Pentesting

  • Web Applications & API: Burp Suite Professional, OWASP Top 10 Triage, IDOR / Broken Access Control, Server-Side Template Injection (SSTI), CSRF, API Authentication Exploitation.
  • Protocol & Network Recon: Nmap, Wireshark Packet Inspection, Traffic Interception, Custom Python Exploitation Scripting, Automated Reconnaissance Pipelines.

Systems Engineering & Languages

  • Core Languages: POSIX C, Modern C++, Python 3, Bash / Shell Scripting, JavaScript / Node.js.
  • Low-Level Concepts: Non-Blocking Socket Programming, Inter-Process Communication (IPC), POSIX Signal Handling, Fork/Exec Process Management, Memory Safety & Leak Debugging (Valgrind/GDB).

Infrastructure & DevOps Security

  • Containerization: Docker, Docker Compose Multi-Container Orchestration, Isolated Volume Mounts, Secret Hardening.
  • Network & Server Administration: Nginx Reverse Proxies, Linux/Unix Hardening, UFW Firewall Policies, Strict SSH Access Enforcement, MariaDB / Relational Databases.

Notable Systems Builds (1337 / 42 Network)

  • ft_irc — Custom High-Performance IRC Server
    Engineered an fully compliant Internet Relay Chat server in C++98 from the ground up. Utilizes non-blocking I/O polling (poll()), custom authentication protocols, dynamic channel multiplexing, and robust edge-case socket disconnect handling without external networking libraries.

  • Minishell — POSIX-Compliant UNIX Command Shell
    Built a native interactive Unix shell in C. Features tokenization and lexical parsing for custom pipelines (|), input/output redirections (>, <, >>, << here-docs), built-in POSIX utilities, environment variable expansion, and precise signal handling (Ctrl-C, Ctrl-\).

  • Inception — Hardened Multi-Container Infrastructure
    Designed a highly resilient containerized Linux deployment utilizing custom Dockerfiles. Orchestrates isolated networking between Nginx TLS reverse proxies, automated WordPress daemon management, and secured MariaDB data persistence.

  • Cub3D — 3D Raycasting Engine in Raw C
    Developed a retro Wolfenstein-inspired 3D graphical renderer in raw C using linear algebra and Digital Differential Analysis (DDA) raycasting mathematics, incorporating custom texture mapping and smooth collision detection.


Operator Timeline

  • 1337 School (42 Network) · 2024 — Present
    Software Engineering & Cybersecurity Specialization · Level 10.22 Achieved · Khouribga, Morocco.
  • Intelcia Group · 2023 — 2024
    Customer Operations Specialist · Casablanca, Morocco.
  • Faculty of Sciences Ain Chock · 2022 — 2023
    Biology, Geology, & Chemistry (BGC) · Casablanca, Morocco.

Let’s Connect

I am constantly seeking challenging security engineering roles, bug bounty collaborations, and offensive research opportunities. If you are building resilient architectures or breaking down high-value targets, let’s talk.