Skip to content
View Christbowel's full-sized avatar
πŸ’­
Try Hard πŸ”₯πŸ’»
πŸ’­
Try Hard πŸ”₯πŸ’»

Block or report Christbowel

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
christbowel/README.md

πŸ‘‹ Hey, I'm christbowel

GitHub
TryHackMe
RootMe
0xdeadbeef


πŸš€ Who am I?

I’m a 19-year-old CS student at TU Darmstadt with a strong focus on IT-Security.
Passionate about breaking & building, I dive into vulnerability research, exploit development and red/blue team tooling.
Between CVEs, custom tools, and CTFs, I love pushing the boundaries of what’s possible in cybersecurity.


🏴 CVE

  • CVE-2024-29643 – Croogo v3.0.2
    Exploitable Host Header Injection via feed.rss component.
    β†’ Allows malicious HTTP Host headers, which can lead to arbitrary PHP code execution and full compromise of the target system.
    β†’ Demonstrates how CMS plugins/extensions can be leveraged as initial access vectors for attackers.

πŸ› οΈ CVE Contributions

  • CVE-2023-25136 – OpenSSH 9.1

    • Wrote a Python mass scanner + exploit script to detect & leverage the vuln.
    • Widely adopted in the community as a go-to exploitation framework.
  • CVE-2024-25600 – WordPress Bricks Builder

    • Authenticated RCE affecting WordPress sites.
    • Created a Nuclei template (2 versions), quickly merged as the official ProjectDiscovery template.
    • Accelerated detection & remediation in Bug Bounty & pentest engagements.

βš’οΈ Tools & Projects

  • πŸ”₯ Infiltrator

    • Infiltrator is a stealthy input surveillance tool written in Go.
    • Captures keystrokes, clipboard data, system info, and exfiltrates via a secure Telegram bot.
  • πŸ”‘ CipherBuster

    • A tool designed for breaking weak ciphers & cryptographic flaws.
    • Useful in CTFs & real pentest scenarios when facing custom/legacy encryption.
  • πŸ›‘οΈ RedTeamer

    • Offensive toolkit for adversary simulation.
    • Includes payload generators, privilege escalation helpers, and persistence techniques.
  • πŸ”΅ BlueTeamer

    • Companion project to RedTeamer, focusing on defensive analysis.
    • Log analysis, anomaly detection, and automated detection rule generation.

πŸ… Hall of Fame

  • πŸ† State of California (USA) β†’ Found & exploited SQLi β†’ RCE leading to full server compromise.
  • πŸ† Bureau of Indian Affairs (BIA) β†’ Reported multiple vulnerabilities impacting critical systems.
  • πŸ† Mars Vulnerability Program β†’ Found & exploited IDOR β†’ Client Information Disclosure and Client Side Validation Bypass
  • πŸ† RMIT UNiversity (AUSTRALIA)

πŸ’» Skills

Languages:
Python Β· C Β· Go Β· JavaScript Β· PHP Β· Bash Β· SQL

Technologies & Tools:
Linux Β· Docker Β· Nmap Β· BurpSuite Β· Metasploit Β· Kali Tools Β· Nuclei Β· Git Β· Ghidra

Domains:
Penetration Testing Β· Exploit Development Β· Cryptanalysis Β· Bug Bounty Β· Reverse Engineering Β· Web Security Β· CTFs


πŸ“Š GitHub Stats

GitHub Stats
Top Langs


πŸ”— Connect


Popular repositories Loading

  1. CVE-2023-25136 CVE-2023-25136 Public

    OpenSSH 9.1 vulnerability mass scan and exploit

    Python 106 21

  2. Red-Teamer Red-Teamer Public

    Red Teaming tools and techniques

    56 12

  3. CVE-2024-25600_Nuclei-Template CVE-2024-25600_Nuclei-Template Public

    Nuclei template and information about the POC for CVE-2024-25600

    31 7

  4. Blue-Teamer Blue-Teamer Public

    Blue teamer tools and techniques

    8 4

  5. CipherBuster CipherBuster Public

    Outil d'analyse et d'exploitation des vulnΓ©rabilitΓ©s des implΓ©mentations RSA, avec techniques d'attaque automatisΓ©es et avancΓ©es

    Python 5 4

  6. SSRFmap SSRFmap Public

    Python 3