- SQL injection — customer database exposedCRITICAL
- Broken access control on admin panelHIGH
- Payment callback forgery possibleHIGH
- Verbose error leakage on 3 endpointsMEDIUM
All visitors are logged.
Offensive security with a defensive conscience. I'm hired to think like the adversary — probing web applications, networks and human-facing systems for the weaknesses others miss. Then I help you close them. Properly, permanently, and with evidence.
Hostel meal billing runs on trust and mental math — and it fails the way every unverified system fails: quietly. Special-day exceptions nobody wrote down, arguments at month-end, and tracking apps that store money as floating point — so the bill itself can be wrong by a paisa, and no one would ever know.
I treated a meal bill the way a security engineer treats a hash — something that must be exact and verifiable by construction. Meal Ledger never touches floats: money lives as integer paisa, meals as integer half-units, and every hostel rule is encoded in a locked, tested rulebook. Isolation isn't a UI promise either — each resident's ledger sits under their own UID, enforced server-side by Firestore Security Rules. Even the ৳52 → ৳55 rate change ships with tests that walk every month boundary — and fail the build if a stale rate is ever hardcoded back.
A zero-dependency PWA in production: offline-capable, installable, real-time synced, with CSV/JSON exports and a rules-guarded admin workspace. 20 automated tests guard the arithmetic, and the entire app weighs ~250 KB — less than one stock photo. The ledger is now mathematically incapable of being wrong.
▶ core · 15 passing ✔ rate schedule preserves ৳52 history → ৳55 from Sep 2026 ✔ every supported month follows the exact rate boundary ✔ calendar handles normal and leap years ✔ breakfast is always one half-unit (0.5 meal) ✔ Friday lunch ×2 · Tuesday dinner ×2 · Sunday dinner ×1.5 ▶ rate-integrity · 5 passing ✔ core rate constants are internally exact ✔ no stale hard-coded ৳52 multiplier in app.js Tests 20 · Failures 0 · Math exact ✓
Every security career starts with a question. Mine was simple — how do things break? Hi, I'm Foysal Mahmud, a Cyber Security Specialist and Ethical Hacker with 3+ years of hands-on field work. I study at Notre Dame College, Dhaka, and I've chosen to do the unusual: pursue professional offensive security seriously, in parallel with my studies — not as a hobby, but as a craft.
My work spans penetration testing, ethical hacking, OSINT investigations and full-cycle security consulting — for individuals, startups and organizations. I've built and broken enough systems to know exactly where teams usually look away: misconfigurations, trust assumptions, forgotten endpoints and the human layer. Those blind spots are where I operate.
I run every engagement the same way: reconnaissance → exploitation → evidence → remediation. No fear-mongering reports, no jargon walls. You get findings in plain language, proof for every claim, and a prioritized path to fix them. Security is a discipline, not a product — I'm here to be your long-term partner in it.
P.S. — yes, I really do all of this between classes. Sleep is a scheduled vulnerability.
A simulated real-time view of the internet's background noise — port scans, brute-force attempts and intrusion probes hitting monitored infrastructure worldwide. This is the visibility every engagement of mine starts with.
Five disciplines, one mindset: assume nothing, verify everything, and leave the system harder than you found it.
Authorized, simulated attacks against your systems — executed exactly like a real adversary would. I probe your infrastructure for the weaknesses an attacker would find first, then hand you a risk-rated report with proof-of-concept evidence and a remediation roadmap — before someone with worse intentions finds the same doors.
Start an Engagement
Deep-dive security assessments where automation meets craft. Scanners find the obvious; I hunt the logic flaws, chained misconfigurations and business-logic abuses that tools can't reason about. Web apps, APIs, networks and mobile — every finding delivered with PoC evidence and business-impact analysis.
Start an Engagement
Strategy before tooling. Threat modeling, risk assessment, incident-response planning and security culture — tailored to your risk landscape and budget, not a generic checklist. Whether you're a startup shipping your first product or an organization hardening what already exists, I help build a posture that lasts.
Start an Engagement
I don't just find vulnerabilities — I know how they get written. Landing pages, platforms and web applications built secure by design: validated inputs, hardened headers, sane auth, clean architecture. The rare developer who has read your codebase from the attacker's side first.
Start an Engagement
What does the internet already know about you? Open-source intelligence gathering and digital-footprint analysis that shows exactly what an attacker learns before they ever knock on your firewall — exposed records, leaked credentials, metadata trails — and how to shrink that footprint.
Start an Engagement
No mystery, no black box. Every engagement follows the same four-phase protocol — you know what's happening at every step, and you get full documentation when it's done.
A sample of real engagements — anonymized and redacted to protect client confidentiality. Hover the redactions to decrypt. Full references available on request.
Security is the craft — but the field is wider than the terminal. Representing Notre Dame College in robotics outreach at AIUB, guest-speaking on national ed-tech live streams, and building the digital backbone for institutional science events.
Invited as a Special Guest Merit Student from Notre Dame College for Shikho's flagship live launch — speaking on the SSC→HSC transition, how AI belongs in a smart study system, and practical roadmaps for incoming HSC batches.
With OSA & the AIUB Robotic Crew (ARC), bringing 66 Notre Dame College Science Club students into the lab: 3D CAD modeling, live drone demos, a Robo Soccer championship — and trophies and medals that traveled back to NDC with the team.
Active developer and technician for the Notre Dame College IT Team and NDSC — designing and running the official platforms behind the Annual Science Festival and campus tech initiatives. The invisible systems behind visible events.
Curated frames from the field: project platforms, security labs, campus robotics, and the moments in between.
Foysal did an outstanding job on our web application security audit. He found critical vulnerabilities our internal team had completely missed — including an SQL injection that could have exposed our entire user database. The report alone was worth the engagement.
Professional, fast, and extremely knowledgeable. Foysal stress-tested our e-commerce platform before launch and found 3 critical and 7 medium-risk issues. The penetration test report was detailed, clear, and very actionable — our devs fixed everything in one sprint.
Working with Foysal was great from start to finish. He explained every finding in plain language, provided PoC screenshots, and gave a clear remediation roadmap. Will definitely work again.
Hired Foysal for an OSINT investigation and network security review. He delivered a well-organized report within the timeline. Communication was excellent and the quality of work exceeded expectations.
Whether it's a full penetration test, a second opinion on your security posture, or a question you'd rather ask privately — reach out. First consultation is free, and everything you share stays confidential.
You have successfully accessed the private area. This page is only visible to verified clients. Here you can find exclusive resources, advanced cybersecurity tips, and direct contact protocols.