SQL Injection
UNION / blind boolean / time-based chains, WAF bypasses, extraction and pivot.
About
My name is Yassir Mouyiwa. I'm based in Morocco, a cybersecurity and embedded systems student. My playground: offensive security — web pentesting, privilege escalation, exploitation, firmware analysis.
This site collects my lab writeups (Hack The Box, TryHackMe, PortSwigger), a handful of tooling projects, and the state of my certifications. All handwritten, in Markdown, versioned. Reports are in French — the rest of the site is bilingual.
UNION / blind boolean / time-based chains, WAF bypasses, extraction and pivot.
Reflected / stored / DOM, CSP bypass.
IDOR, SSRF.
SUID/GTFOBins, misconfigured sudo, cron, capabilities, targeted kernel exploits.
Firmware analysis, UART/JTAG.
2026
HTB CPTS — in progress
HTB Certified Penetration Testing Specialist track: network pentesting, AD, pivoting, reporting.
June 2026
HTB CWES — track complete, exam pending
Certified Web Exploitation Specialist: advanced SQLi, XSS/CSP bypass, SSRF, IDOR. Pathway complete, exam being prepared.