Kathir profile picture

Hello, I'm

Kathir

Cybersecurity

my linked profile my github profile
arrow icon

Get To Know More

About Me

Profile Picture
education logo

Education

Master of Science in Cybersecurity

University at Buffalo

Expected Graduation: Dec 2025

Bachelor of Technology in Computer Science and Business Systems

Sri Krishna College of Engineering and Technology

Graduated: 2024

I’m passionate about learning cybersecurity to keep digital systems safe. I focus on finding and fixing security weaknesses to protect data and assets. Through hands-on projects and advanced courses, I’m building strong skills in using cybersecurity tools and techniques. My goal is to stay ahead of new threats and help create secure digital environments.

arrow icon

Projects

CUPS Vulnerability Exploitation

Exploited CUPS vulnerability (CVE-2024-47176) on port 631 using cups-browsed and foomatic-rip to achieve remote code execution. Captured sensitive print job data in /var/spool/cups for root password retrieval, demonstrating privilege escalation.

Active Directory Enumeration and Exploitation

Performed AD enumeration on a Windows domain controller, using Kerberoasting and SMB enumeration to retrieve domain names, SIDs, and sensitive files. Cracked a service account Kerberos ticket with Hashcat (mode 13100), achieving domain control with secretsdump.

E-Learning Platform Penetration Testing

Conducted security testing on an e-learning platform, identifying vulnerabilities through subdomain enumeration, directory brute-forcing, and credential cracking. Gained root access by exploiting a root-owned cron job and deploying a reverse shell payload.

In-Depth Vulnerability Assessment and Exploitation

Performed a full vulnerability assessment on a target machine, identifying open ports and services using Nmap. Discovered and exploited a DNS server vulnerability on BIND (port 53) and a web-based CMS on Nginx (port 80) through Metasploit. Achieved privilege escalation by leveraging a misconfigured SUID binary, ultimately gaining root access and control over the target system.

Jenkins Vulnerability Exploitation on Windows

Assessed a Windows 10 machine running Jenkins, gaining initial access via Jenkins misconfigurations. Escalated privileges by exploiting a misconfigured service path, deploying a reverse shell payload in WiseBootAssistant to achieve administrator access.

Website Security Analysis

Developed an e-commerce website using PHP, MySQL, and Docker, focusing on identifying and mitigating security vulnerabilities such as SQL injection and XSS. Used Docker to manage development environments, ensuring consistent deployment across systems, and performed detailed security assessments to secure database interactions and user input validation.

Developer Showcase Platform

Built a collaborative platform for developers to share projects, using Django, HTML, CSS, JavaScript, and PostgreSQL. Incorporated secure, role-based authentication for user privacy, real-time updates with Supabase, and scalable image storage with Backblaze.

Portfolio Website

Created a personal portfolio website using HTML, CSS, and JavaScript, deployed on AWS S3. Managed the domain with Route 53, used ACM for SSL/TLS security, and CloudFront for global content delivery, achieving secure and high-performance access.


My intern

Experience

Web Developer

I possess 5 months of experience as a web developer, specializing in technologies such as Node.js, Python Django, and Postgres SQL, enabling me to contribute effectively to projects requiring expertise in scalable server-side development and robust database management.

AWS Cloud Architect

I bring 6 months of experience as an AWS Cloud Architect, where I honed my skills in cloud infrastructure functions and gained a deep understanding of network security protocols.


arrow icon

Explore my

Skills

Experience Icon

Nmap

Experience Icon

Metasploit

Experience Icon

Wireshark

Experience Icon

Splunk

Experience Icon

Burp Suite

Experience Icon

FFUF

Experience Icon

Hydra

Experience Icon

Hashcat

Experience Icon

Responder

Experience Icon

Impacket Tools

Experience Icon

CrackMapExec

Experience Icon

John the Ripper

Experience Icon

SQLmap

Experience Icon

DirBuster

Experience Icon

Gobuster

Experience Icon

Aircrack-ng

Experience Icon

Snort

Experience Icon

Elastic Stack (ELK)

arrow icon

Get in Touch

Contact me