Skip to content
View 0xmrsecurity's full-sized avatar
πŸ’­
oops, you can see this profile.
πŸ’­
oops, you can see this profile.

Block or report 0xmrsecurity

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xmrsecurity/README.md
Typing SVG

GitHub LinkedIn Blog Email HTB THM

Views


πŸ‘Ύ About Me

class Suraj:
    name     = "Suraj Gupta"
    alias    = "0xmr"
    role     = "Pentester & Cloud Security Engineer"
    domains  = ["Web", "Active Directory", "AWS", "AI/LLM"]
    language = ["Python", "Bash"]
    
    def mission(self):
        return "Find it before the bad guys do."
  • πŸ”­ Currently pentesting Web, AD, AWS & AI/LLM
  • 🌱 Deep-diving AWS Security, AI/LLM attacks, Web Advanced
  • πŸ› Disclosed IDOR vulns, exposed S3 buckets, Grok/Kimi findings
  • πŸ“– Personal cheatsheet & notes β†’ 0xmr.qzz.io
  • 🀝 Open to collaborate β†’ github.com/0xmrsecurity


πŸ† Real-World Findings

# Vulnerability Target Impact
πŸ”“ IDOR Γ— 2 Live Production Systems Unauthorized data access exposed
πŸͺ£ Exposed S3 Bucket Live Production Sensitive data publicly accessible
πŸ’‰ Command Injection Grok AI (via Chatbot) Remote command execution vector
πŸ“€ System Prompt Extraction Kimi AI (Chinese LLM) Full system prompt leaked

πŸ› οΈ Tech Arsenal

Languages

Python Bash

Pentesting Tools

Burp Suite BloodHound Nessus Nuclei Sliver C2 Impacket Custom Scripts

Cloud & OS

AWS Kali Linux Linux Docker


πŸš€ Featured Projects

Netspray

Netspray:- NetSpray is a wrapper script designed to save time when performing password or hash spraying across multiple protocols. It leverages the power of NetExec to automate the process efficiently.

live_Project_link

Usage: NetSpray <protocols|all> <targets|subnet> -u <username> [-p <password> | -H <hash>] [OPTIONS]

Scrad

Scrad:- This tool finds hidden endpoints across the entire website using js.

live_Project_link

Usage Ready to use from brower, just click on scrad bookmark and it will open a new page with in a 2 seconds.

Public POC Repo

Public POC (Proof of Concepts):- list of public Exploit in python and bash languages.

live_Project_link

Pentesting Notes site

Pentesting Notes

0xmr.qzz.io


πŸ“œ Certifications & Training

"Certifications are expensive. Skills are not. Here's the proof of work."

🏫 Cybrary β€” Offensive Penetration Testing
πŸ›°οΈ ISRO β€” Geo-data Sharing & Cyber Security
☁️ SimplyCyber β€” Intro to AWS Pentesting
🏒 SimplyCyber β€” Hacking Active Directory

βš”οΈ TryHackMe β€” Offensive Pentesting Path
🌐 TryHackMe β€” Web Exploitation Path
πŸ”΄ TryHackMe β€” Red Teaming Path


πŸ“ˆ Currently Leveling Up

☁️  AWS Security     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ       Deep dive: IAM escalation, Lambda abuse, EC2 , S3 etc.
πŸ€–  AI/LLM Security  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ       Prompt injection, model extraction, System Prompt Extract and Jail Break.  
🌐  Web Advanced     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ          OAuth/OTP, SSRF chains, LFI, Command Injection.

πŸ“Š GitHub Stats


Activity Graph


"The quieter you become, the more you are able to hear."

Snake animation

Pinned Loading

  1. HTB-lab-POC HTB-lab-POC Public

    This repo contains the hackthebox lab script ,try it out ....

    Shell 9

  2. Offensive-Security-Tool Offensive-Security-Tool Public

    make it possible

    Shell 10

  3. OSCP OSCP Public

    try the awesome script , you always thanks to me ...

    Shell 11