Skip to content
View Rehan137's full-sized avatar

    Block or report Rehan137

    Block user

    Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

    You must be logged in to block users.

    Content in all repositories owned by your account will be closed.
    Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
    Report abuse

    Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

    Report abuse
    rehan137/README.md










    ╔══════════════════════════════════════════════════════════════════════════════════╗
    ║ ☠ WARNING — CLASSIFIED OPERATOR FILE — AUTHORIZED PERSONNEL ONLY ☠ ║
    ╠══════════════════════════════════════════════════════════════════════════════════╣
    ║ ║
    ║ ██████╗ ███████╗██╗ ██╗ █████╗ ███╗ ██╗ ███╗ ███╗ ║
    ║ ██╔══██╗██╔════╝██║ ██║██╔══██╗████╗ ██║ ████╗ ████║ ║
    ║ ██████╔╝█████╗ ███████║███████║██╔██╗ ██║ ██╔████╔██║ ║
    ║ ██╔══██╗██╔══╝ ██╔══██║██╔══██║██║╚██╗██║ ██║╚██╔╝██║ ║
    ║ ██║ ██║███████╗██║ ██║██║ ██║██║ ╚████║ ██║ ╚═╝ ██║ ║
    ║ ╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ║
    ║ ║
    ╠══════════════════════════════════════════════════════════════════════════════════╣
    ║ [ 0.001337 ] kernel :: offensive_security .............. LOADED [ OK ] ║
    ║ [ 0.013370 ] module :: zero_day_engine .................. ARMED [ OK ] ║
    ║ [ 0.133700 ] auth :: REHAN_MALEK :: identity_ok ....... PASS [ OK ] ║
    ║ [ 1.337000 ] net :: cyrad_radius_module .............. ONLINE [ OK ] ║
    ║ [ 1.337001 ] ics :: kotori_scada_exploit .............. ARMED [ OK ] ║
    ║ [ 1.337002 ] hw :: flipper_zero_rf_nfc_rfid ......... LOADED [ OK ] ║
    ║ [ 1.337003 ] ops :: mission_control ▓▓▓▓▓▓▓▓▓▓▓▓ 100% ONLINE ║
    ╠══════════════════════════════════════════════════════════════════════════════════╣
    ║ ● ALL SYSTEMS NOMINAL — HUNTING MODE ACTIVE — TARGET LOCKED ║
    ╚══════════════════════════════════════════════════════════════════════════════════╝
    

    ☠️ THREAT ACTOR MANIFEST

    {
    "file_id" : "THREAT_ACTOR :: 0x7331",
    "operator" : "Rehan Malek",
    "alias" : "R3H4N",
    "origin" : "Ahmedabad, India",
    "education" : "M.Sc Cybersecurity — NIST Ahmedabad",
    "clearance" : "RED TEAM // UNRESTRICTED",
    "primary_ops" : [
    "ICS/SCADA Exploitation",
    "Authentication System Hacking",
    "RF / NFC / RFID Hardware Attacks",
    "Bug Bounty & CVE Research",
    "RADIUS / AAA Penetration Testing"
    ],
    "zero_days" : 1,
    "cve_status" : "1 PENDING — Kotori ICS/SCADA",
    "disclosure" : "CVD — Fully Ethical",
    "mission" : "Hunt → Break → Disclose → Repeat",
    "hire_status" : "OPEN — immediate availability",
    "threat_level" : "██████████ CRITICAL",
    "sys_status" : "● ONLINE — HUNTING MODE"
    }




    🔴 EXPLOIT REGISTRY — CVE DATABASE

    ⚠️All vulnerabilities disclosed under Coordinated Vulnerability Disclosure (CVD). All research is authorized and ethical.

    🔴 STATUSCVE IDTARGETCVSSCLASSCREDIT
    ⏳ PENDINGCVE-XXXX-XXXXXKotori ICS/SCADA🔴 CRITICALUnauthenticated Telemetry Poisoning✅ Confirmed
    ╔════════════════════════════════════════════════════════════════════════════════╗
    ║ ⚠ EXPLOIT CHAIN REPORT — OPERATION KOTORI — EYES ONLY ⚠ ║
    ╠════════════════════════════════════════════════════════════════════════════════╣
    ║ ║
    ║ SYSTEM : Kotori ICS/SCADA Framework (Open-Source OT Monitoring) ║
    ║ ENDPOINT : Unauthenticated HTTP Route — Zero Auth Required ║
    ║ TECHNIQUE : Telemetry Data Injection → Sensor Value Falsification ║
    ║ IMPACT : Critical Infrastructure Disruption / False Sensor Readings ║
    ║ REACH : All internet-exposed Kotori instances pre-patch ║
    ║ METHOD : Coordinated Vulnerability Disclosure (CVD) — Ethical ║
    ║ STATUS : ✅ Contributor Credit Confirmed by Maintainer ║
    ║ CVE : Pending NVD Assignment ║
    ║ ║
    ║ CHAIN: Unauth HTTP ──► Inject Telemetry ──► Falsify Sensors ║
    ║ ──► Trigger False Alarms ──► Disrupt Critical Infrastructure ║
    ║ ║
    ╚════════════════════════════════════════════════════════════════════════════════╝
    

    🎯 ATTACK SURFACE MAPPING

     ┌─────────────────────────────┐
    │ ╔═══════════════════════╗ │
    │ ║ ◉ TARGET ACQUIRED ║ │
    │ ║ REHAN MALEK ║ │
    │ ║ OPERATOR :: R3H4N ║ │
    │ ╚═══════════╤═══════════╝ │
    └──────────────┼───────────────┘
    ┌──────────────┬──────────┴──────┬──────────────┐
    ▼ ▼ ▼ ▼
    ┌────────────┐ ┌─────────────┐ ┌──────────────┐ ┌──────────────┐
    │ 🌐 WEB APP │ │ 📡 HARDWARE │ │ 🏭 ICS / OT │ │ 🔐 NET/AUTH │
    │────────────│ │─────────────│ │──────────────│ │──────────────│
    │ OWASP Top10│ │ Flipper Zero│ │ Modbus/DNP3 │ │ RADIUS / AAA │
    │ SQLi / RCE │ │ RF Replay │ │ Telemetry Inj│ │ MITM / Deauth│
    │ Auth Bypass│ │ NFC Cloning │ │ PLC Exploit │ │ Session Hijack│
    │ SSRF / XXE │ │ RFID Spoof │ │ Kotori SCADA │ │ Cred Harvest │
    │ LFI / IDOR │ │ BadUSB / HID│ │ OT Recon │ │ Wi-Fi Attacks│
    └────────────┘ └─────────────┘ └──────────────┘ └──────────────┘
    
    KILL CHAIN:
    ┌────────┐ ┌───────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌────────┐
    │ RECON │─►│ WEAPONIZE │─►│ DELIVER │─►│ EXPLOIT │─►│ PERSIST │─►│ EXFIL │
    │ OSINT │ │ Zero-Day │ │ Social │ │ Auth Byp.│ │ Backdoor │ │ C2 Ops │
    │ Nmap │ │ HW Implant│ │ Phishing │ │ SCADA/OT │ │ RADIUS │ │ Loot │
    │ Shodan │ │ Exploits │ │ Delivery │ │ ICS/PLC │ │ Persist │ │ Drain │
    └────────┘ └───────────┘ └──────────┘ └──────────┘ └──────────┘ └────────┘
    

    🛠️ OFFENSIVE TOOLKIT

    ─── ANIMATED SKILL ICONS ───



    ─── EXPLOITATION FRAMEWORKS ───

    Burp SuiteMetasploitNmapWiresharkFlipper Zero

    ─── PLATFORMS ───

    Kali LinuxParrot OSDigitalOceanWindows


    📁 OPERATION FILES — Click to Decrypt

    🔴 OPERATION : DROID BYPASS | Android Security | Root Lock Screen Circumvention
    ╔═══════════════════════════════════════════════════════════════════╗
    ║ OP_ID : DROID-BYPASS-001 CLASSIF : RESEARCH ONLY ║
    ╠═══════════════════════════════════════════════════════════════════╣
    ║ TARGET : Rooted Android Devices — All Versions ║
    ║ VECTOR : Root Shell → Privilege Escalation ║
    ║ METHOD : Scripted Lock Screen Bypass (Full PoC + Docs) ║
    ║ IMPACT : Full Device Access Without PIN / Bio / Pattern ║
    ║ STATUS : Demonstrated — Security Model Invalidated ║
    ╚═══════════════════════════════════════════════════════════════════╝
    

    Root access completely invalidates Android's lockscreen security model. Script demonstrates full device takeover with zero authentication. Includes PoC & technical writeup.


    🔴 OPERATION : CYRAD DEPLOY | Network Auth / AAA | Enterprise RADIUS System
    ╔═══════════════════════════════════════════════════════════════════╗
    ║ OP_ID : CYRAD-002 CLASSIF : CLIENT PROJECT ║
    ╠═══════════════════════════════════════════════════════════════════╣
    ║ BUILD : Designed & architected from zero ║
    ║ FEAT 1 : Per-user data quota enforcement (real-time) ║
    ║ FEAT 2 : Live session monitoring + AAA full stack ║
    ║ FEAT 3 : Admin dashboard + dynamic access policy engine ║
    ║ CLIENT : Cyndia Cyberspace LLP ║
    ║ RESULT : ✅ Letter of Recommendation Awarded ║
    ╚═══════════════════════════════════════════════════════════════════╝
    

    Enterprise-grade AAA platform built from scratch — Authentication, Authorization & Accounting with per-user quota enforcement and live session management.


    🔴 OPERATION : UNMASK | OSINT / Recon | Origin IP Discovery Behind CDN
    ╔═══════════════════════════════════════════════════════════════════╗
    ║ OP_ID : UNMASK-003 CLASSIF : PEN TEST TOOLS ║
    ╠═══════════════════════════════════════════════════════════════════╣
    ║ TARGET : CDN-shielded Web Applications ║
    ║ TECH : True-origin IP discovery — Cloudflare bypass ║
    ║ METHOD : Multi-vector passive recon + DNS enumeration ║
    ║ IMPACT : Direct origin attack — bypasses WAF / CDN layer ║
    ║ PHASE : Reconnaissance — pre-exploitation ║
    ╚═══════════════════════════════════════════════════════════════════╝
    

    Automates uncovering the real origin server behind CDN/Cloudflare. Used to neutralize WAF protections and target the exposed origin directly during pen tests.


    🔴 OPERATION : HARDWARE KRAKEN | Hardware / Red Team | Flipper Zero 5-in-1 PCB
    ╔═══════════════════════════════════════════════════════════════════╗
    ║ OP_ID : HW-KRAKEN-004 CLASSIF : RED TEAM HW ║
    ╠═══════════════════════════════════════════════════════════════════╣
    ║ HW : Custom Flipper Zero 5-in-1 PCB Extension Board ║
    ║ CAP 1 : RF Replay + Sub-GHz frequency attack surface ║
    ║ CAP 2 : NFC emulation + full RFID cloning / spoofing ║
    ║ CAP 3 : Physical bypass modules + BadUSB HID injection ║
    ║ USE : Red team physical security assessments ║
    ║ STATUS : Designed, built, assembled & field-tested ✅ ║
    ╚═══════════════════════════════════════════════════════════════════╝
    

    Custom PCB expanding Flipper Zero's attack surface for red team ops — RF, NFC, RFID, and physical bypass all on one hardware platform.


    💼 FIELD ASSIGNMENTS

    ╔══════════════════════════════════════════════════════════════════════════════╗
    ║ ASSIGNMENT-001 │ KUBOTOR — Bug Bounty Hunter (Intern) ║
    ║ TIMELINE │ Sep 2025 → Jan 2026 ║
    ╠══════════════════════════════════════════════════════════════════════════════╣
    ║ ► Structured penetration tests executed across multiple live targets ║
    ║ ► Vulnerability chains assembled into critical-impact proof-of-concepts ║
    ║ ► Responsible disclosure pipeline — full exploit documentation delivered ║
    ╚══════════════════════════════════════════════════════════════════════════════╝
    ╔══════════════════════════════════════════════════════════════════════════════╗
    ║ ASSIGNMENT-002 │ CYNDIA CYBERSPACE LLP — Security Analyst (Intern) ║
    ║ TIMELINE │ May 2025 → Jul 2025 ║
    ╠══════════════════════════════════════════════════════════════════════════════╣
    ║ ► Architected CYRAD — enterprise RADIUS authentication system from zero ║
    ║ ► Per-user quota enforcement + real-time live session monitoring (AAA) ║
    ║ ► 🏅 Awarded Letter of Recommendation for exceptional delivery ║
    ╚══════════════════════════════════════════════════════════════════════════════╝
    

    📊 DIGITAL FOOTPRINT






    💡 CAPABILITY INDEX

    ⚡ DOMAIN🛠️ STACK🔴 THREAT RATING
    🌐 Web App PentestingBurp Suite · OWASP Top-10 · SQLi████████████ ADVANCED
    🏭 ICS / SCADA SecurityKotori · Modbus · OT Networks██████████░░ ADVANCED
    🔐 Network & AuthRADIUS · AAA · MITM · Wi-Fi████████████ ADVANCED
    📡 Hardware HackingFlipper Zero · RF · NFC · RFID█████████░░░ PROFICIENT
    🔎 OSINT & ReconShodan · Nmap · DNS · Passive████████████ ADVANCED
    🐍 Exploit ScriptingPython · Bash · Automation█████████░░░ PROFICIENT
    💾 Digital ForensicsEvidence · Analysis · Imaging███████░░░░░ INTERMEDIATE
    🚩 CTF OperationsWeb · Pwn · Crypto · Misc████████░░░░ PROFICIENT

    🎓 CREDENTIALS VAULT

    🔐 CERTIFICATION🏛️ ISSUER🎯 DOMAIN🔰
    Cyber Security & PrivacyNPTELOffensive & Defensive SecOps
    Computer Networks & Internet ProtocolNPTELNetwork Architecture
    SQL Injection AttackEC-COUNCILWeb Application Exploitation
    PHP & MySQLIIT BombayBackend & Database Development
    H4CKP13T 0X01International CTFCapture The Flag Competition
    PHANTOM FLABCTF EventCapture The Flag Competition

    📡 EXFIL CHANNEL — SECURE COMMS

    ╔════════════════════════════════════════════════════════════════════╗
    ║ ⚡ AVAILABLE FOR THE FOLLOWING ENGAGEMENTS ⚡ ║
    ╠════════════════════════════════════════════════════════════════════╣
    ║ ✅ Freelance Penetration Testing & Vulnerability Assessments ║
    ║ ✅ Bug Bounty Collaborations & Joint Research Programs ║
    ║ ✅ Full-Time Offensive Security / Red Team Roles ║
    ║ ✅ Security Research Internships ║
    ║ ✅ CVE Research, Coordination & Responsible Disclosure ║
    ║ ✅ Hardware Hacking & Physical Security Red Team Operations ║
    ╚════════════════════════════════════════════════════════════════════╝
    

    Popular repositories Loading

    1. buggymart-project buggymart-projectPublic

      BuggyMart is a simple e-commerce website built with PHP and MySQL. It is designed to be an easy-to-understand platform for learning about common web application vulnerabilities.

      PHP

    2. rehan137 rehan137Public

      HTML 1

    3. windows95_portfolio windows95_portfolioPublic

      Forked from renish47/windows95_portfolio

      My web portfolio whose design is inspired based on popular Windows-95 operating system's look.

      JavaScript

    4. origin-finder origin-finderPublic

      Advanced 30-method origin IP discovery tool with CDN bypass and mathematical validation - Written in pure C with no external dependencies

      C

    5. ai-productivity-hub ai-productivity-hubPublic

      TypeScript