Penetration Tester at DuoLabz (2024-08 – Present)
Led end-to-end penetration testing engagements, identifying and exploiting critical vulnerabilities across web applications and network infrastructure
- Discovered ASP.NET Core configuration file (appsettings.json) exposure vulnerability - file was publicly accessible without authentication, containing database connection strings, JWT signing keys, API credentials, and SMTP passwords
- Identified and exploited Path Traversal vulnerabilities, allowing unauthorized access to files and directories outside the intended application root directory
- Found DOM-based and Reflected XSS (Cross-Site Scripting) vulnerabilities enabling malicious script injection in client-side code and HTML responses
- Discovered Clickjacking and security misconfiguration issues including missing X-Frame-Options headers, weak authentication mechanisms, and improper access controls
- Identified critical authentication flaws in login page implementation including weak password policies, lack of rate limiting, session fixation vulnerabilities, and insufficient login attempt controls
- Analyzed and exposed missing security headers (Content-Security-Policy, X-Content-Type-Options, X-XSS-Protection, HSTS) and CSP misconfigurations that were too permissive
- Translated technical findings into risk-prioritized remediation strategies, delivered comprehensive penetration test reports with clear exploitation proof-of-concepts, and contributed to attack surface reduction through continuous security assessments
Jr. Penetration Tester at Powersoft19 (2023-01 – 2024-06)
Conducted structured web and network penetration tests on multiple client systems, identifying and validating exploitable vulnerabilities
- Performed initial reconnaissance and system enumeration using Nmap, port scanning, and service version detection to map attack surfaces
- Executed SQL injection attacks using SQLmap and manual payloads to test database security and demonstrate data extraction capabilities
- Identified and exploited weaknesses in authentication, authorization, encryption, and data handling mechanisms across applications
- Performed privilege escalation testing on Linux and Windows systems using Metasploit and manual exploitation techniques
- Executed XSS (Stored/Reflected), CSRF, and Path Traversal vulnerability testing using Burp Suite and manual fuzzing to demonstrate real-world impact
Cyber Security Internship at PNY (2022-08 – 2022-12)
Developed foundational expertise in ethical hacking and penetration testing methodologies through hands-on training and practical exercises
- Learned and practiced system scanning using Nmap to discover active hosts, open ports, and identify running services in target environments
- Gained hands-on experience identifying and exploiting common web vulnerabilities (XSS, CSRF, SQL injection, path traversal, authentication flaws)
- Learned Burp Suite fundamentals including proxy interception, request modification, and vulnerability scanning with hands-on laboratory exercises
- Gained exposure to Metasploit Framework basics including payload generation, exploitation techniques, and post-exploitation activities
- Strengthened knowledge of network protocols, system security, attack vectors, and privilege escalation methodologies through practical penetration testing scenarios