Skip to content
View farSec's full-sized avatar

Block or report farSec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
farSec/README.md

Bahran Bahrani | Junior Web Application Security Tester

I am a cybersecurity student and junior web application security tester focused on manual web application testing, OWASP Top 10, authentication and access control issues, API security, and professional vulnerability reporting.

I recently passed the HTB CWES/CBBH exam and I am building my portfolio around practical web security assessments, structured writeups, and clean technical reporting.

Focus Areas

  • Web Application Security Testing
  • OWASP Top 10
  • Authentication & Session Management
  • Access Control / IDOR
  • XSS, SQLi, File Upload Issues
  • API Security Testing
  • Vulnerability Reporting & Remediation Guidance

Featured Work

  • HTB Writeups: structured retired-machine writeups focused on methodology, exploitation, privilege escalation, and lessons learned.
  • Sample Pentest Reports: professional-style vulnerability reports with impact, reproduction steps, evidence, and remediation.
  • Security Tools: small Python tools built to support learning and practical testing.

Current Goal

I am looking for junior web application security testing opportunities, freelance security review work, and subcontractor support roles with security teams or agencies.

Contact

Pinned Loading

  1. sample-pentest-reports sample-pentest-reports Public

    Professional-style web application security findings and pentest report samples.

  2. web-security-portfolio web-security-portfolio Public

    A practical web application security portfolio focused on OWASP Top 10, API testing, access control, methodology, and reporting.

  3. HTB-WriteUps HTB-WriteUps Public

    Structured Hack The Box writeups focused on methodology, enumeration, exploitation, privilege escalation, and lessons learned.