Skip to content
View h4ckologic's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report h4ckologic

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
h4ckologic/README.md
h4ckologic β€” Security Researcher | CVE Hunter | Abu Dhabi

Profile Views Twitter HackerOne Bugcrowd Blog


h4ckologic terminal profile

πŸ‘Ύ About Me

Security researcher passionate about uncovering and addressing critical vulnerabilities in complex technology implementations. I specialize in mobile security (Android/iOS/VoLTE), vulnerability research, fuzzing, and bug bounty hunting. Based in Abu Dhabi, I have discovered critical CVEs affecting millions of users and regularly present research at security conferences.

🎯 Current Focus

  • πŸ“± Mobile Security Research (Android & iOS)
  • πŸ” Zero-day vulnerability hunting
  • πŸ› Bug bounty on HackerOne & Bugcrowd
  • πŸ”¬ Custom fuzzer development
  • πŸ“’ Security conference speaking

⚑ Quick Stats

  • πŸ† Multiple CVEs discovered & disclosed
  • πŸ“± iOS VoLTE vulnerability researcher (CVE-2021-31001)
  • πŸ•·οΈ PhantomJS arbitrary file read (CVE-2019-17221)
  • πŸ› οΈ Open source security tooling author
  • 🎀 Security conference speaker

πŸ΄β€β˜ οΈ CVE & Research Highlights

CVE Severity Target Impact
CVE-2021-31001 πŸ”΄ Critical iOS VoLTE Stack Remote exploitation via crafted VoLTE packets
CVE-2019-17221 🟠 High PhantomJS Arbitrary file read via crafted web content

πŸ”— Full security research β†’ Disclosed Online Profile Β· Conference Talks


πŸ› οΈ Technical Arsenal

πŸ“± Mobile Security

Android iOS Frida Objection MobSF Jadx APKTool Burp Suite OWASP MASTG

πŸ”¬ Vulnerability Research & Fuzzing

AFL++ LibFuzzer Radare2 GDB Ghidra IDA Pro pwntools AIDL Fuzzer

🌐 Web Application Security

Burp Suite SQLMap Nuclei OWASP ZAP ffuf Nikto

πŸ”­ Recon & OSINT

Amass Subfinder Shodan Censys go--SCAN httpx

πŸ’» Programming & Scripting

Python Go Bash Kotlin Java C Swift

☁️ Cloud & DevSecOps

Docker Kubernetes AWS CI/CD Security SAST DAST Semgrep


πŸš€ Featured Security Research & Tools


Lang Stars Forks

PhantomJS Arbitrary File Read Exploit & PoC for CVE-2019-17221 β€” arbitrary file read via crafted web content in PhantomJS headless browser.

πŸ€– AIDL_Fuzzer

Lang Stars Forks

Android AIDL Interface Fuzzer Custom Python fuzzer targeting Android AIDL IPC interfaces. Used in research leading to CVE-2021-31001.

πŸ”­ go-SCAN

Lang Stars Forks

Recon Automation Suite Bash-orchestrated recon pipeline using Go-based tools (nuclei, subfinder, httpx). Fast attack surface mapping.

Lang Stars Forks

On-Device AIDL Interface Fuzzer Kotlin-based on-device fuzzer for Android AIDL interfaces. Runtime IPC surface discovery & fuzzing.

πŸ›‘οΈ mobiletools

Lang Stars Forks

Mobile Security Assessment Toolkit Collection of automation scripts for mobile security assessments β€” Android & iOS testing workflows.

🎀 Talks

Type Stars Forks

Conference Research Slides Collection of security conference presentation slides covering mobile security, CVE research, and fuzzing.


🎀 Conference Talks & Research Presentations


Presented at HITB, Black Hat MEA, RomHack, Hack.lu, Hacktivity, BSides, Ekoparty, and more.


Year Conference Talk Slides
IDSS'26 Deep Dive into Building Next-Gen Local AI Security Reviewers πŸ“„
Black Hat MEA 2025 FalconEYE β€” Local LLM Powered Code Review πŸ“„
Hack.lu 2025 Breaking into Android IPC Mechanisms through AIDL Fuzzing πŸ“„
HITB Bangkok AI-Assisted Code Review πŸ“„
BSides Ahmedabad 0x05 Breaking into Android IPC Mechanisms through Advanced AIDL Fuzzing πŸ“„
RomHack Β· HITB HKT Β· BSides AMD Hacking into iOS's VoLTE Implementation (CVE-2021-31001) πŸ“„ πŸ“„ πŸ“„
NoNameCon Β· Ekoparty Β· Hacktivity Demystifying the Server Side πŸ“„
Null Dubai SSRF β€” Make the Cloud Rain πŸ“„

View All Talks


πŸ“Š GitHub Analytics


GitHub Streak

🌱 Contribution Activity

h4ckologic's Activity Graph


🎯 Professional Expertise

security_researcher:
  name: h4ckologic
  specializations:
    - "πŸ“± Mobile Application Security (Android & iOS)"
    - "πŸ“‘ VoLTE / Telecom Protocol Security"
    - "πŸ”¬ Binary Fuzzing & Vulnerability Discovery"
    - "πŸ•΅οΈ Bug Bounty Hunting (HackerOne / Bugcrowd)"
    - "🧬 AIDL / IPC Interface Fuzzing (Android)"
    - "πŸ” Secure SDLC & Threat Modeling"
    - "☁️ Cloud & Container Security (K8s / Docker)"
    - "🌐 Web Application Security (OWASP Top 10)"
    - "πŸ”Ž Recon & Attack Surface Mapping"
    - "πŸ“œ CVE Research & Responsible Disclosure"
    - "🎀 Security Conference Speaking"
    - "πŸ›‘οΈ DevSecOps & CI/CD Pipeline Security"
    - "πŸ”© SAST / DAST / IAST Implementation"
  methodology: "Offense-informed Defense β€” break it to secure it"
  disclosure_policy: "Responsible Disclosure via CVD Programs"

🌐 Connect & Find Me


Twitter LinkedIn HackerOne Bugcrowd Blog GitHub



root@h4ckologic:~# echo "Security is not a product, but a continuous process." && logout
Security is not a product, but a continuous process.
Connection to h4ckologic closed.

Pinned Loading

  1. Talks Talks Public

    Quick and handy collection of my conference Slides

    1

  2. CVE-2019-17221 CVE-2019-17221 Public

    PhantomJS uses internal module: webpage, to open, close, render, and perform multiple actions on webpages, which suffers from an arbitrary file read vulnerability. The vulnerability exists in the p…

    8 3

  3. go-SCAN go-SCAN Public

    A simple bash script to perform recon using go-based tools.

    Shell 2 1

  4. AIDL_Fuzzer AIDL_Fuzzer Public

    A short AIDL fuzzer written in Python

    Python 3