HackTheBox: Exploiting SUID Binaries for Privilege Escalation
Walkthrough of a medium-difficulty HTB machine involving web enumeration, initial foothold via LFI, and privilege escalation through misconfigured SUID binaries.
I craft scalable web applications and explore the depths of cybersecurity — passionate about clean code and finding vulnerabilities.
Full-Stack Dev
React · Node.js · PostgreSQL · Docker
Ethical Hacker
OWASP · Burp Suite · Metasploit
CTF Player
HackTheBox · TryHackMe · Research

Full-Stack Developer & Security Researcher
CS student building fast, secure web apps with React, Node.js, FastAPI, and PostgreSQL.
CEH certified with hands-on penetration testing experience. I bring a security mindset to everything I build.
Building and maintaining full-stack web applications within a GitHub organization. Focused on security-centric architecture, clean component design, and delivering high-performance products collaboratively.
Studying core CS fundamentals with a focus on algorithms, data structures, and network security. Actively applying academic knowledge through a growing portfolio of security tools and web platforms.
Contributing to open-source projects across debugging tools, security utilities, and developer tooling. Focused on code quality, documentation, and building tools that solve real problems.
Self-reflection and habit tracking platform. Built with React and FastAPI, featuring a PostgreSQL backend and a clean, minimal UI focused on daily journaling and progress tracking.
Real-time network traffic visualizer with an interactive dashboard. Uses Scapy for packet capture and WebSockets to stream live data to the React frontend.
Scalable social media application with a focus on performance and clean component architecture. Supports real-time interactions and a responsive feed.
EC-Council · 2024
freeCodeCamp · 2023
Amazon Web Services · 2024
University · 2025 – Present
Walkthrough of a medium-difficulty HTB machine involving web enumeration, initial foothold via LFI, and privilege escalation through misconfigured SUID binaries.
A hands-on breakdown of the OWASP Top 10 vulnerabilities with real exploitation examples and code-level mitigations for each.
How to build production-ready FastAPI applications with proper JWT authentication, rate limiting, and input sanitization to prevent common vulnerabilities.
Step-by-step walkthrough of a network-focused CTF challenge involving port scanning, service enumeration, and exploitation with Metasploit.
Have a project in mind or want to collaborate? Send me a message and I'll get back to you.
Location
Dhaka, Bangladesh