Skip to content
View touhidshaikh's full-sized avatar
💭
I may be slow to respond.
💭
I may be slow to respond.

Organizations

@Initd-sh

Block or report touhidshaikh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
touhidshaikh/README.md

Typing SVG


🕶️ About Me

I'm a Security Researcher based in India 🇮🇳.
I hunt bugs, break systems, and build tools that help others do the same 🔥

  • 🎯 10+ CVEs published (XSS, RCE, SQLi, Auth Bypass, etc.)
  • 🛠️ Contributor to Exploit-DB, Metasploit, and CIS Benchmarks
  • 🎤 Speaker at CrestCon (London) & ThreatCon (Kathmandu)
  • 🧠 Shellcode author and CTF machine creator for HTB & VulnHub

🧙‍♂️ Hacker Highlights

> echo "Touhid Shaikh"
┌──(root💀touhid)-[~/research]
└─$ whoami
Security Researcher | Exploit Developer | Open Source Contributor

┌──(root💀touhid)-[~/CVEs]
└─$ cat highlights.txt

✅ OSCP | OSCE | CRT | CPSA | ISC² CC
🚨 CVE-2024-43381 – Stored XSS in reNgine
🎯 RCE on Netgear, TP-Link, OnePlus Web Services
🎓 MBA (ITASM) | BSc IT
🌍 Conferences: CrestCon (UK), ThreatCon (Nepal)

📕 Latest Blog Posts


🧰 Tech Stack & Tools I Use

Python PHP Docker Metasploit Burp Suite Git Kali Linux


🏆 CVEs & Research Contributions

  • 🔒 CVE-2024-43381 – Stored XSS in reNgine
  • 💥 CVE-2021-29069 – Command Injection in Netgear Router
  • 🛡️ CVE-2018-11714 – Auth Bypass in TP-Link Routers
  • 🖥️ 10+ total CVEs — see full list on Exploit-DB

🐛 Bug Bounty Hall of Fame

Proud to be acknowledged by:

  • 🍏 Apple – Security Misconfiguration
  • 🌐 Synology – Remote Code Execution, SSRF and Security Misconfiguration
  • 📶 Netgear – Remote Code Execution and XSS and Security Misconfiguration
  • 🔐 OnePlus – Remote Code Execution
  • 🎯 Arlo, Registrar.gov, HackTheBox, PlaySMS, and more.

📚 Featured Work


🧠 Custom Labs Created


🔗 Connect with Me


🙌 Mentions

Thanks to everyone who has referenced or credited my work in their repositories!


📟 GitHub Stats & Hacker Vibes

Pinned Loading

  1. AES_Decryptor AES_Decryptor Public

    This tool help you to decryption of AES Encrypted file in very easy way.

    Python 8 2

  2. CVE CVE Public

    Explain Some CVE, Which i Discovered

    1 1

  3. shellcode shellcode Public

    C 11 1

  4. 0x00-0x00/ShellPop 0x00-0x00/ShellPop Public

    Pop shells like a master.

    Python 1.5k 236

  5. nidem/kerberoast nidem/kerberoast Public

    Python 1.5k 315

  6. PentestPad/subzy PentestPad/subzy Public

    Subdomain takeover vulnerability checker

    Go 1.3k 185