$ ls ./projects/

Projects & engagements

A selection of offensive security work, including client engagements and open-source exploits published for disclosed CVEs.

// engagements

~/infinitytix.md

InfinityTix

Independently designed and built a full-stack event ticketing platform covering the complete user journey, including Google Oauth, OTP verification, SSLCommerz based automated payments, digital wallet ticket delivery, event organization and management, and ticket scanning for entry validation.

TypeScriptPostgreSQLSupaBase
~/anti_ctfd.md

Anti-CTFd

Engineered a containerized CTF (Capture The Flag) environment using Python and Docker, designed to eliminate flag sharing between competing teams by dynamically generating and injecting unique per-team flags into isolated challenge instances, ensuring fair scoring and preventing collusion during live competitions.

PythonDockerWeb
~/ctfd_namesync.md

CTFd NameSync

Developed a custom CTFd plugin in Python that bridges the CTFd platform with Discord, automating participant identity verification, syncing Discord nicknames with corresponding CTFd usernames in real time, and automatically assigning server roles based on registration and team status, streamlining competition management for organizers.

PythonBackendBot

// published CVE exploits

More research and write-ups on blog.0xrobiul.me covering Bug Bounty, CSRF, RCE, Broken Link Hijacking and CTF walkthroughs.