Skip to content
Yassir Mouyiwa

Offensive security · Morocco

Yassir Mouyiwa.

I break systems to understand how to defend them. Lab writeups, tooling projects, field notes.

Specialities

SQL Injection

UNION / blind boolean / time-based chains, WAF bypasses, extraction and pivot.

XSS

Reflected / stored / DOM, CSP bypass.

Web exploitation

IDOR, SSRF.

Linux privesc

SUID/GTFOBins, misconfigured sudo, cron, capabilities, targeted kernel exploits.

Systèmes embarqués

Firmware analysis, UART/JTAG.

Latest writeups

See all →

Want to talk?

Reach out for an internship, a collaboration, or just to discuss a challenge you're stuck on. I reply fast.