JMJasveer MaanCyber Security Enthusiast
~/site/whoamioperator profile

$ whoami

Offensive security

Jasveer Maan

I break down real-world security problems through hands-on testing, research, and practical write-ups.

Never stop learning, because life never stops teaching.

About

Driven by practical security research.

Cyber security is best understood by doing, not just reading. I learn by experimenting with real-world attack paths and lab environments to understand how systems fail and how they can be secured.

I enjoy breaking things only after understanding how they work. That curiosity drives my approach to penetration testing, red teaming, and knowledge sharing.

Diploma

SEGi University – Diploma in Computer Studies

Degree

  • Asia Pacific University (A.P.U) – BSc (Hons) in Information Technology with specialism in Information System Security
  • Staffordshire University – BSc (Hons) in Information Technology with specialism in Information System Security

Skills

Core Skills

Red TeamingPenetration Testing (Web/Mobile/Network)Cloud SecurityAPI SecurityNetwork SecurityMainframe Application Security (z/OS)Vulnerability Assessment & ManagementScripting (Bash, Python, PowerShell)Security ResearchSecurity Architecture ReviewAI Red Teaming

Certifications

Credentials

Altered Security – Certified Red Team Expert (CRTE)Altered Security – Certified Red Team Professional (CRTP)AWS - Certified Cloud PractitionerCREST – Practitioner Security AnalystCREST – Registered Penetration TesterCyberWarFare Labs – Certified AWS Cloud Red TeamCyberWarFare Labs – Google Cloud Red Team SpecialistEC Council – Certified Ethical Hacker V9 (CEH)EC Council – Computer Hacking Forensic Investigator V8 (CHFI)Hack The Box (HTB) – OffshoreOffensive Security – Offensive Security Certified Expert (OSCE)Offensive Security – Offensive Security Certified Professional (OSCP)Offensive Security – Offensive Security Web Expert (OSWE)Offensive Security – Offensive Security Wireless Professional (OSWP)Pentester Academy – Certified Az Red Team Professional (CARTP)SecOps Group - Certified AI/ML Pentester (C-AI/MLPen)Zero Point Security – Red Team Operator

Write-ups

Research notes, labs, and walkthroughs.

locked

HTB - Bedside

Hack The Box write-up with exploitation notes and lessons learned.

locked

HTB - SmartHire

Hack The Box write-up with exploitation notes and lessons learned.

locked

HTB - Helix

Hack The Box notes focused on practical attack path thinking.

Exploiting React Server Components RCE (React2Shell – CVE-2025-55182)

Request-level exploitation notes for React Server Components RCE testing.

Fixing “Illegal Server Name” Error in Burp Suite Caused by Underscores in Domain Names

Troubleshooting notes for Burp Suite DNS handling and match-replace behavior.

LLM Assisted Source Code Review Using FalconEye

Using LLM-assisted workflows to accelerate source code review and vulnerability discovery.

Using Burp Suite Professional Without Installing It on a Client VDI (via SSH & EC2)

A practical SSH and EC2 workflow for proxying client VDI traffic into Burp Suite Pro.

Child-to-Parent Domain Escalation: Lessons Learned from Kerberos ETYPE Pitfalls

Active Directory escalation notes from Kerberos ticketing and hash-dump edge cases.

Exfiltrating Data via DNS in a Restricted Environment

DNS exfiltration testing in restricted network conditions.

Using Proxychains With Mythic C2 to Pivot From Kali → C2 → Assume Breach → Internal Network

Pivoting through Mythic C2 and proxychains in an assume-breach style lab.

Exploring SpicyAD for Active Directory Security Testing

Hands-on AD security testing with SpicyAD, Kerberoasting, delegation, and enumeration.

AI-driven AD enumeration

Notes on using AI assistance while enumerating Active Directory environments.

How I Used Tailscale to Access My Homelab from Anywhere

Remote access notes for homelab connectivity using Tailscale.

Android Banking Malware Analysis

Static and behavioral notes from Android banking malware analysis.

Intentional Exposure: Exploiting Android Exported Activities for Root Detection Bypass

Android exported activity testing and root detection bypass observations.

CVE / Research

Public vulnerability research history.

A structured home for CVE notes, affected products, vulnerability classes, and references.

ClipBucket

CVE-2018-7664, CVE-2018-7665, CVE-2018-7666

OS Command Injection, Arbitrary File Upload, SQL Injection

I, Librarian PDF Manager

CVE-2017-1000234, CVE-2017-1000235, CVE-2017-1000236, CVE-2017-1000237

OS Command Injection, SSRF, Directory Enumeration, Reflected XSS

InvoicePlane

CVE-2017-1000238, CVE-2017-1000239

Arbitrary File Upload, Stored XSS

MyBB Forum

CVE-2017-7566

Server-Side Request Forgery

MyBiz MyProcureNet

CVE-2018-11090, CVE-2018-11091

Arbitrary File Upload, Reflected Cross-Site Scripting

OpenEMR

CVE-2018-1000019, CVE-2018-1000020

OS Command Injection, Reflected Cross-Site Scripting

phpBB

CVE-2017-1000419

Server-Side Request Forgery

Contact

Reach out for security services or research collaboration.

Available for focused security assessments, research collaboration, and advisory work.