Skip to content

peterd3cs3c/cyber-path

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

4 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

 β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—   β–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•—  β–ˆβ–ˆβ•—
β–ˆβ–ˆβ•”β•β•β•β•β•β•šβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β•šβ•β•β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘
β–ˆβ–ˆβ•‘      β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘
β–ˆβ–ˆβ•‘       β•šβ–ˆβ–ˆβ•”β•  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•  β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•”β•β•β•β• β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘
β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘     β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘
 β•šβ•β•β•β•β•β•   β•šβ•β•   β•šβ•β•β•β•β•β• β•šβ•β•β•β•β•β•β•β•šβ•β•  β•šβ•β•    β•šβ•β•     β•šβ•β•  β•šβ•β•   β•šβ•β•   β•šβ•β•  β•šβ•β•
Typing SVG

Bug Bounty Web/API Cloud CTF

Website GitHub LinkedIn Blog Email

πŸ“ Spain (Remote) Β· Responsible disclosure Β· Clear PoCs & remediation guidance


πŸ—ΊοΈ Repo Map

cyber-path/
β”œβ”€β”€ πŸ“‚ ctf/                    # Capture The Flag writeups & solutions
β”‚   β”œβ”€β”€ πŸ“‚ web/                # Web exploitation challenges
β”‚   β”œβ”€β”€ πŸ“‚ pwn/                # Binary exploitation
β”‚   β”œβ”€β”€ πŸ“‚ crypto/             # Cryptography
β”‚   β”œβ”€β”€ πŸ“‚ reverse/            # Reverse engineering
β”‚   β”œβ”€β”€ πŸ“‚ forensics/          # Digital forensics
β”‚   └── πŸ“‚ misc/               # Miscellaneous challenges
β”‚
β”œβ”€β”€ πŸ“‚ bug-bounty/             # Bug bounty findings & methodology
β”‚   β”œβ”€β”€ πŸ“‚ reports/            # Anonymized report templates
β”‚   └── πŸ“‚ methodology/        # Recon & exploitation workflows
β”‚
β”œβ”€β”€ πŸ“‚ labs/                   # Hands-on lab environments
β”‚   β”œβ”€β”€ πŸ“‚ hackthebox/         # HackTheBox machines
β”‚   β”œβ”€β”€ πŸ“‚ tryhackme/          # TryHackMe rooms
β”‚   └── πŸ“‚ portswigger/        # PortSwigger Web Security Academy
β”‚
β”œβ”€β”€ πŸ“‚ cloud-security/         # Cloud security research & tooling
β”‚   └── πŸ“‚ wiz-challenges/     # Wiz security challenges
β”‚
β”œβ”€β”€ πŸ“‚ certs/                  # Certification study notes & labs
β”‚
β”œβ”€β”€ πŸ“‚ scripts/                # Custom tools & automation
β”‚
└── πŸ“‚ docs/                   # Methodology guides & cheatsheets
    └── index.html              # 🌐 Portfolio (GitHub Pages)

πŸ“Š Stats

Metric Value
CTF Roots 105
HackTheBox Hacker
TryHackMe [0x9] MAGE
Focus Web / API / Cloud
Languages EN / ES

🏴 CTF Writeups

Challenge Category Platform Difficulty Status
Coming soon β€” β€” β€” πŸ”œ

πŸ› Bug Bounty

Focus areas: IDOR / BOLA / BFLA Β· Auth & Session Β· SSRF-to-Cloud Β· API Security (REST/GraphQL)

# Target Severity Type Status
Coming soon β€” β€” β€” πŸ”œ

Notable Findings (sanitized)

Finding Description Tags
IDOR β†’ privilege escalation Object-level access control issue enabling cross-tenant access idor api
Auth logic bypass Inconsistent checks between UI and API endpoints auth api
SSRF risk in import feature Potential internal network access; cloud metadata hardening recommended ssrf cloud

πŸ”¬ Labs & Machines

Machine / Room Platform Difficulty Writeup
Coming soon β€” β€” πŸ”œ

☁️ Cloud Security

Challenge Platform Topic Status
Coming soon β€” β€” πŸ”œ

πŸŽ“ Certifications

Cert Status Tags Link
CCNA βœ… Completed Network Β· Routing Β· SDN Credly
AWS Solutions Architect βœ… Completed Cloud Β· Architecture Credly
Terraform Associate βœ… Completed IaC Β· Cloud Credly
CompTIA Security+ 701 πŸ”„ In Progress Cybersecurity Β· Defensive Β· GRC Credly
HTB CPTS πŸ”„ In Progress Offensive Β· Web Β· AD β€”
HTB CBBH πŸ”„ In Progress Offensive Β· Web Β· API β€”
CRTO πŸ”„ In Progress Offensive Β· Red Team β€”
OSCP ⏳ Not started Offensive β€”

Training

Path Status Tags
PortSwigger Web Security Academy πŸ”„ Ongoing Web
HTB Academy (CPTS, CBBH, ProLabs) πŸ”„ Ongoing Offensive
Cloud labs (AWS) πŸ”„ Ongoing Cloud

πŸ”— Platforms

HackerOne Bugcrowd Intigriti HackTheBox TryHackMe


πŸ› οΈ Toolbox

Kali Burp Suite Nmap Metasploit Wireshark Python Docker GitLab CI Ghidra AWS Terraform


πŸ“ How I Document

Each writeup follows a consistent format:

## Challenge Name
### Recon β†’ Foothold β†’ Privesc β†’ Root

- 🎯 Objective
- πŸ” Enumeration & Discovery
- πŸ’£ Exploitation
- 🏁 Flag / Proof
- πŸ“š Lessons Learned

πŸ—“οΈ Roadmap

When Goal Detail
Now Finish CPTS + consistent bug bounty routine Daily reps: labs + target practice; write one note per week
3–6 months Increase valid reports + focus specialization Deepen access control expertise (BOLA/BFLA) across APIs
Next Increase high/critical vulnerabilities found Show proof: reports, certs, writeups, and professional workflow

πŸ“Š GitHub Activity

GitHub streak


If you find this repo useful, drop a ⭐ β€” it fuels the grind.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors