Skip to content
View C4sh3R's full-sized avatar
☠️
Pwning all day long
☠️
Pwning all day long

Highlights

  • Pro

Block or report C4sh3R

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
C4sh3R/README.md

👾 c4sh3r

Offensive Security Researcher · Red Teamer · Binary/RE · Kernel & Exploit Dev · Smart-Contract Auditor · Bug Bounty Hunter

From kernel UAFs to DeFi exploits — I break it, then I prove it.

profile views followers


🧠 About

I'm an offensive security researcher operating across the entire stack — from the metal to the mempool. I don't specialize in a single surface: one week it's a use-after-free in a Linux kernel subsystem, the next it's an IDOR chain in a fintech API or a share-inflation bug in a DeFi vault. I treat every target the same way: understand it deeply, find where trust breaks, then write the exploit that proves it.

No theoretical findings. No hand-waving. If I report it, there's a working Proof-of-Concept behind it.


🎯 What I do

Domain What it looks like
🏴‍☠️ Red Team & Offensive Ops Full kill chain: recon → initial access → privilege escalation → RCE → root → post-exploitation & defacing
🔬 Binary Analysis & Reverse Engineering Native daemons, firmware images, desktop & mobile binaries, embedded keys, protocol RE
🧨 Kernel & Exploit Development Memory corruption (UAF, OOB), local privilege escalation, n-day weaponization & original research
🌐 Web / API / Mobile / Infra Pentesting Auth bypass, IDOR, SSRF, NoSQL injection, session attacks, server & infrastructure compromise
⛓️ Smart-Contract Auditing Solidity / EVM — ERC-4626 vaults, LayerZero/OFT bridges, oracles, staking & withdrawal queues
🐛 Bug Bounty Hunting End-to-end: recon, asset discovery, vulnerability research and a reproducible exploit

🧰 Arsenal

Languages

Reverse engineering & exploitation

Web / chain / infra


🏆 Where you'll find me

Public bug bounty programs, private red-team engagements, audit contests and CTFs — spanning web, mobile, IoT, firmware, kernel and on-chain. DeFi, bridges, exchanges, fintech… and the occasional kernel rabbit hole.


📊 GitHub


“If it holds value or runs code, it has an attack surface.”

Pinned Loading

  1. CTF_HTB CTF_HTB Public

    Repository for the challenges

    HTML 1