Skip to content
Yassir Mouyiwa

Yassir Mouyiwa

@yassirmouyiwa

ROLE
offensive-security · student
GEO
33.5731° N   7.5898° W · Maroc
STATUS
system online

About

I break things to understand them.

My name is Yassir Mouyiwa. I'm based in Morocco, a cybersecurity and embedded systems student. My playground: offensive security — web pentesting, privilege escalation, exploitation, firmware analysis.

This site collects my lab writeups (Hack The Box, TryHackMe, PortSwigger), a handful of tooling projects, and the state of my certifications. All handwritten, in Markdown, versioned. Reports are in French — the rest of the site is bilingual.

Specialities

SQL Injection

UNION / blind boolean / time-based chains, WAF bypasses, extraction and pivot.

XSS

Reflected / stored / DOM, CSP bypass.

Web exploitation

IDOR, SSRF.

Linux privesc

SUID/GTFOBins, misconfigured sudo, cron, capabilities, targeted kernel exploits.

Systèmes embarqués

Firmware analysis, UART/JTAG.

Journey

  1. 2026

    HTB CPTS — in progress

    HTB Certified Penetration Testing Specialist track: network pentesting, AD, pivoting, reporting.

  2. June 2026

    HTB CWES — track complete, exam pending

    Certified Web Exploitation Specialist: advanced SQLi, XSS/CSP bypass, SSRF, IDOR. Pathway complete, exam being prepared.

Where to find me