Skip to content
View 0xmrsecurity's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report 0xmrsecurity

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xmrsecurity/README.md
Typing SVG

GitHubLinkedInBlogEmailHTBTHM

Views


👾 About Me

classSuraj:
name="Suraj Gupta"alias="0xmr"role="Pentester & Cloud Security Engineer"domains= ["Web", "Active Directory", "AWS", "AI/LLM"]
language= ["Python", "Bash"]
defmission(self):
return"Find it before the bad guys do."
  • 🔭 Currently pentesting Web, AD, AWS & AI/LLM
  • 🌱 Deep-diving AWS Security, AI/LLM attacks, Web Advanced
  • 🐛 Disclosed IDOR vulns, exposed S3 buckets, Grok/Kimi findings
  • 📖 Personal cheatsheet & notes → 0xmr.qzz.io
  • 🤝 Open to collaborate → github.com/0xmrsecurity


🏆 Real-World Findings

#VulnerabilityTargetImpact
🔓IDOR × 2Live Production SystemsUnauthorized data access exposed
🪣Exposed S3 BucketLive ProductionSensitive data publicly accessible
💉Command InjectionGrok AI (via Chatbot)Remote command execution vector
📤System Prompt ExtractionKimi AI (Chinese LLM)Full system prompt leaked

🛠️ Tech Arsenal

Languages

PythonBash

Pentesting Tools

Burp SuiteBloodHoundNessusNucleiSliver C2ImpacketCustom Scripts

Cloud & OS

AWSKali LinuxLinuxDocker


🚀 Featured Projects

Netspray

Netspray:- NetSpray is a wrapper script designed to save time when performing password or hash spraying across multiple protocols. It leverages the power of NetExec to automate the process efficiently.

live_Project_link

Usage: NetSpray <protocols|all><targets|subnet> -u <username> [-p <password>| -H <hash>] [OPTIONS]

Scrad

Scrad:- This tool finds hidden endpoints across the entire website using js.

live_Project_link

Usage Ready to use from brower, just click on scrad bookmark and it will open a new page with in a 2 seconds.

Public POC Repo

Public POC (Proof of Concepts):- list of public Exploit in python and bash languages.

live_Project_link

Pentesting Notes site

Pentesting Notes

0xmr.qzz.io


📜 Certifications & Training

"Certifications are expensive. Skills are not. Here's the proof of work."

🏫 Cybrary — Offensive Penetration Testing
🛰️ ISRO — Geo-data Sharing & Cyber Security
☁️ SimplyCyber — Intro to AWS Pentesting
🏢 SimplyCyber — Hacking Active Directory

⚔️ TryHackMe — Offensive Pentesting Path
🌐 TryHackMe — Web Exploitation Path
🔴 TryHackMe — Red Teaming Path


📈 Currently Leveling Up

☁️ AWS Security ███████████ Deep dive: IAM escalation, Lambda abuse, EC2 , S3 etc.
🤖 AI/LLM Security ███████████ Prompt injection, model extraction, System Prompt Extract and Jail Break. 🌐 Web Advanced ████████ OAuth/OTP, SSRF chains, LFI, Command Injection.

📊 GitHub Stats


Activity Graph


"The quieter you become, the more you are able to hear."

Snake animation

Pinned Loading

  1. OSCPOSCPPublic

    try the awesome script , you always thanks to me ...

    Shell 11

  2. ad2enumad2enumPublic

    This Repo contains the Active Directory Enumeration scripts.

    Shell 1

  3. 0xmrsecurity.github.io0xmrsecurity.github.ioPublic

    Pentesting Notes

    Shell 11

  4. Public_PocPublic_PocPublic

    I write the python and bash Proof of Concept for the better understanding of attacks.

    Python 10 1