Ubaid_Rehman
ONLINE
Nazimabad, Karachi, Pakistan

Ubaid ur Rehman

@darkmaster0345 · 18-year-old self-taught developer & vulnerability researcher

Source code security and privacy-focused software builder. I find vulnerabilities through passive analysis, JS bundle review, HAR analysis, and console-based verification with responsible disclosure.

GitHubDownload CVEC-Council Hall of Fame 2026
KotlinTypeScriptPythonRust (Learning)Bash/ShellBrowser DevToolsGitAndroid StudioKali LinuxMetasploit (Learning)ClaudeGeminiKotlinTypeScriptPythonRust (Learning)Bash/ShellBrowser DevToolsGitAndroid StudioKali LinuxMetasploit (Learning)ClaudeGemini
ABOUT

Source Code Security + Privacy Engineering

I'm a DAE Electronics student at Technical College of Karachi (in progress), focused on vulnerability research and privacy-first software development.

My security workflow is transparent: passive analysis → JavaScript bundle review → HAR file analysis → browser console verification → responsible disclosure. I prioritize reproducible findings over automated scanner reports.

I openly use AI assistants (Claude and Gemini) to speed up code analysis and attack-surface mapping, while keeping reports evidence-driven and technically verified.

Passive Analysis

Non-intrusive observation of application behavior and data flows

JS Bundle Review

Source code analysis of client-side JavaScript for leaked secrets and logic flaws

Responsible Disclosure

Evidence-driven reports with verified, reproducible findings

0+Vulnerabilities Found
0Companies Disclosed
0Hall of Fame
FORGE

Software Forge

Open-source tools built with Kotlin, Python, and TypeScript. Built software, not vaporware.

·
·
SECURITY LAB

Verified Security Research

20+ vulnerabilities across 3 engagements · 7+ Critical findings · 1 Hall of Fame listing

EC-Council (CodeRed)

9 vulns · 3 Critical

9 vulnerabilities found (3 Critical). Acknowledged in 12 minutes. Hall of Fame 2026 + Certificate of Appreciation.

Acknowledged and recognized

PriceOye

5 vulns · 3 Critical PII

5 vulnerabilities found, including 3 Critical PII leaks. Remediation confirmed within 72 hours.

Acknowledged, not compensated

Waqar Electronics

6 vulns · XSS-to-ATO

6 vulnerabilities found including one Stored-XSS-to-ATO chain via insecure session cookies.

Acknowledged, not compensated

F-Droid App Security Audits

F-Droid Contributor

Verifying FOSS apps for tracker-free, privacy-respecting compliance

0
🔍Apps Audited
0
Merged
0
🛡️Policy Violations
AppMRStatus
Snowflake
!35787
Merged
YouPipe
!34597
Merged
Acutis Firewall
!33629
Merged
Fauxx
!36607
Merged
Yelling
!35886
Merged
ONVIF Camera
!32355
Merged
Kochi Transit Go
!39731
Merged
Conduit
!39885
Merged
Redly
!36246
Pending
F-Droid Audit Shell v1.0.4 - Type "help" for commands.
$

Audit Activity

MonWedFri
JanFebMarAprMayJun
$ git clonehttps://gitlab.com/theredhacker0345--depth=freedom
ACTIVITY TIMELINE

Journey So Far

2024 Q1

PriceOye

First bug bounty report submitted; 5 vulnerabilities identified, including critical PII leaks.

2024 Q1

EC-Council initial report

Initial responsible disclosure submitted to EC-Council.

2024 Q2

HaramVeil + NoFap Hydra + Waqar Electronics

Built privacy-focused projects and disclosed Waqar Electronics ATO chain.

2024 Q3

FOSS contributions

Continued open-source development on privacy/security-oriented repositories.

2025 Q1

F-Droid Snowflake verification

Forward-compatibility verification for Snowflake Volunteer on Android 16 approved by F-Droid maintainer.

2026 Q2Highlight

EC-Council Hall of Fame

Hall of Fame 2026 listing with Certificate of Appreciation for 9 vulnerabilities (3 Critical).

CREDENTIALS

Certifications & Achievements

Verified credentials from Saylani Cisco Networking Academy & EC-Council.

Saylani Cisco Networking Academy via Saylani Welfare International Trust|6 Certificates3 Badges11 Modules
CERTIFICATE

DC - M3 - CyberOps Associate ( Networking Basics )

Jun 1, 2026
SAYLANI WELFARE INTERNATIONAL TRUST

Start learning the basics of computer networking and discover how networks operate.

CyberOps Associate
View Certificate
CERTIFICATESecurity Research

EC-Council Hall of Fame 2026

Certificate of Appreciation — Responsible Disclosure

May 1, 2026
EC-Council

Recognized by EC-Council President Sanjay Bavisi for identifying vulnerabilities in EC-Council web assets (9 vulnerabilities, 3 Critical)

View CertificateView Hall of Fame
CERTIFICATE

Introduction to Cybersecurity

Apr 6, 2026
SAYLANI WELFARE INTERNATIONAL TRUST
CyberOps Associate
View Certificate
CERTIFICATE100%

Introduction to Dark Web, Anonymity, and Cryptocurrency

Apr 1, 2026
EC-Council
EC-Council Skill Enhancement
View Certificate
CERTIFICATE

Network Technician Career Path

Mar 15, 2026
Network Technician Career Path
View Certificate
CERTIFICATE

Digital Safety and Security Awareness

Jan 26, 2026
Digital Safety and Security Awareness
View Certificate
BADGE

DC - M3 - CyberOps Associate ( Networking Basics )

CyberOps Associate
Jun 1, 2026

Start learning the basics of computer networking and discover how networks operate.

BADGE

Network Technician Career Path

Network Technician Career Path
Mar 15, 2026

Comprehensive career path badge earned upon completing the full Network Technician curriculum covering networking fundamentals, security, and administration through Saylani Cisco Networking Academy.

BADGE

Digital Safety and Security Awareness

Digital Safety and Security Awareness
Jan 26, 2026

Badge earned for demonstrating comprehensive awareness of digital safety practices, online privacy protection, and cybersecurity hygiene through the Saylani Cisco Networking Academy program.

ALL VERIFIABLE ON SAYLANI CISCO NETWORKING ACADEMY & EC-COUNCIL

TECH STACK

Skills & Tools

(Honest Snapshot)

Languages
Python0%
Kotlin / Android0%
TypeScript0%
Rust (learning)0%
Tools
Bash / Shell0%
Git0%
Frameworks
React / Next.js0%
Security
Kali Linux0%
Metasploit (self-taught)0%
LIVE FEED

GitHub Activity

Terminal-style view of the latest commits, PRs, and events across the darkmaster0345 repositories.

~/activity-feed
CACHED
$gh feed darkmaster0345 --limit 20
Fetching activity feed...
DIGITAL FREEDOM

Snowflake Proxy

Help censored users browse the free internet — right from your browser

STANDBY

Proxy inactive — click Enable to start helping censored users access the free internet

IP PROTECTED
ZERO LOGS
LIFETIME HELPED: 0
TOTAL UPTIME: 0s

WebRTC Relay

Your browser becomes a bridge. Censored users route traffic through your WebRTC connection to access the open internet.

Your Privacy First

Your IP is never exposed to the websites censored users visit. You're just a transport layer — no data stored, no logs kept.

By Tor Project

Snowflake is built by the Tor Project. It's used by thousands daily to bypass censorship in restricted regions worldwide.

Learn more
GLOBAL NETWORK

Snowflake Network

You're not alone — thousands of proxies are helping censored users worldwide

YOUR DIGITAL SHADOW

Fingerprint Art

Every browser leaves a unique mark — here's yours, turned into art

SCANNING
seed: 0x...

Uniqueness Score

0%unique

Your browser is 0% unique among visitors

More private — blends in with the crowd

Threat Level: LOW

Higher uniqueness means your browser fingerprint is more distinctive, making it easier for trackers to identify you without cookies.

What drives your art

This art was generated from data your browser leaked passively

No cookies, no storage, no server calls needed. This is the same technique advertisers use to track you across the web. Every element in the art above corresponds to a piece of information your browser volunteered without you knowing.

  • Use a privacy-focused browser like Firefox or Tor Browser
  • Install uBlock Origin or Privacy Badger extensions
  • Disable JavaScript when possible (breaks many sites)
  • Use browser settings to block third-party trackers
  • Consider using a VPN to mask your IP address
raw_data.json
Collecting fingerprint data…
01001000 01100101
AES-256-CBC
SHA256:9f86d...
x7F3A2B1C
0x4A2F E8B1
PROVE YOUR SKILLS

Capture The Flag

3 hidden challenges across this portfolio — solve them all to earn the Verified Hacker badge

Session: 00:00:00
Ctrl+` Terminal
System Status0/30%
ENCRYPTED
ENCRYPTED
ENCRYPTED
CLASSIFIED
MISSION01
Challenge #1

Base64 Beacon

EASY47 solvedLOCKED

A signal is being broadcast from the terminal. Intercept it and decode the message.

Enter flag text (case-insensitive)
CLASSIFIED
MISSION02
Challenge #2

Source Inspector

MEDIUM128 solvedLOCKED

Something is hidden in the source code of this page. Inspect the HTML to find the secret.

Enter flag text (case-insensitive)
CLASSIFIED
MISSION03
Challenge #3

ROT13 Transmission

HARD23 solvedLOCKED

An encrypted transmission was intercepted: FRPHVGL. Decode it using a classic cipher.

Enter flag text (case-insensitive)
Tip: Use the terminal command 'ctf' to check your progress
CRYPTOGRAPHY LAB

Encryption Playground

Encode, decode, and explore classic ciphers

0 / 5,000
Output will appear here...
Input entropy:0.00 bits/sym
Output entropy:0.00 bits/sym
Algorithm:Base64
100% Local
Base64

Encodes binary data into ASCII text using a 64-character alphabet. Commonly used...

CYBERSECURITY TOOLKIT

Password Analyzer

Test your password strength and learn what makes passwords secure

Enter Password
Your password never leaves your browser — all analysis is local
Entropy Visualization
0/ 128 bits
0326496128
AES-128
AES-256 →
a-z+4.7 bits/char
A-Z+4.7 bits/char
0-9+3.3 bits/char
!@#+5.0 bits/char
Encryption Comparison
AES-128128 bits
AES-256256 bits
Your Password0 bits
Password Generator
33:Z)tzSScmh9`Kt
Very Strong87/100105.1 bits
Length16
864
Include Characters
DEFENSE POSTURE

Security Scanner

Real-time analysis of this website's security headers

Scroll into view to initiate security scan…

SECURE CHANNEL

LET'S WORK
TOGETHER

Security engagement, collaboration, or just want to talk shop. All communications treated with strict confidentiality.

Let's Build Something

Android apps · Websites · Security audits

Need a secure Android app, a blazing-fast website, or a thorough security audit? Let's discuss your project.

Typical response < 24h · Available now

GitHub

@darkmaster0345

LinkedIn

/in/ubaid-ur-rehman-979623401/

Responsible Disclosure

All findings reported through proper channels. Available for bug bounty and private security consulting.