turkmany.dev
SECURITY PROFILE / 2026 EDITION

Mahmoud Turkmany.

Penetration tester and bug bounty hunter. with 3+ years finding what security teams miss — and delivering the remediation path, not just the finding.

document control
Role
Offensive Security Engineer
Focus
Web, System, Network
Status
Available for Engagements
01 — Executive Summary

Who's behind the report

I break into web applications — legally — and write the report that helps engineering teams close the gap.

work hands-on across the full offensive workflow: reconnaissance, vulnerability assessment, exploitation, and the part most people skip — clear, reproducible reporting that a developer can actually act on.

My day-to-day runs on Burp Suite Pro, custom Python tooling, and a disciplined methodology aligned to OWASP and CVSS. Off the clock, I hunt on public bug bounty programs and document what I learn.

40+
Vulnerabilities reported
15+
Engagements delivered
6
Certifications held / active
02 — Capabilities

Where I focus

A—01

Web Application Testing

Full-coverage assessment of modern and legacy web apps — from authentication logic to server-side injection points.

SQLiIDORXSS Auth BypassAccess Control
A—02

API Security Testing

Assessment of REST and GraphQL APIs — broken authorization, mass assignment, and the logic flaws that scanners never catch.

RESTGraphQL BOLARate Limiting
A—03

System & Infrastructure

Hardening review and exploitation across Windows and Linux hosts — privilege escalation, misconfigurations, and weak credential hygiene.

WindowsLinux PrivEscActive Directory
A—04

Network Penetration Testing

Internal and external network assessments — from service enumeration and pivoting to identifying the paths an attacker would actually take.

EnumerationNmap PivotingLateral Movement
A—05

Exploitation & Tooling

Manual exploitation backed by custom Python proof-of-concepts. I automate the tedious parts and verify the impactful ones by hand.

Burp Suite ProPython PoC WiresharkRecon
A—06

Reporting & Triage

Findings mapped to CVSS, CWE and OWASP, written so a developer knows exactly what's wrong, why it matters, and how to fix it.

CVSSCWE OWASPRemediation
03 — Selected Findings

Representative work

Critical
SQL Injection → full database read
Unparameterized query on a search endpoint
CWE-89 · web app engagement
High
IDOR exposing other users' records
Missing object-level authorization
CWE-639 · HR platform
High
HTML Injection in user-facing fields
Unsanitized markup rendered in the response
CWE-79 · web app engagement
High
OTP bypass on authentication flow
Verification step bypassed via direct navigation to the post-auth page
CWE-306 · web app engagement
Medium
Stored XSS in profile fields
Unsanitized user input rendered to admins
CWE-79 · web app engagement
04 — Credentials

Certifications & training

Certified Ethical Hacker (CEH) EC-Council
Certified
Certified Professional Penetration Tester (eCPPT) INE . hands-on exam
Certified
Junior Penetration Tester (eJPT) INE . hands-on exam
Certified
CEH (Practical) EC-Council · hands-on exam
Certified
Certified Security Specialist (ECSS) EC-Council
Certified
Certified Cybersecurity Technician (CCT) EC-Council
Certified
05 — Recognition

Hall of fame

Organizations that acknowledged my security reports through their responsible disclosure and bug bounty programs.

06 — Research

Writeups & notes

07 — Contact

Let's find what's broken.

Delivering full-scope penetration testing engagements for organizations, alongside active bug bounty research.