Ubaid Ur Rehman
AI-Native Security Researcher & Full-Stack Developer
Nazimabad, Karachi, Pakistanarifubaid0345@gmail.comgithub.com/darkmaster0345gitlab.com/theredhacker0345Professional Summary
Security researcher and full-stack developer building open-source Android, web, and CLI tools. Experience includes static analysis, API security research, privacy-focused software, and AI-assisted engineering workflows, with public contributions to GitLab and Inkscape.
Core Skills
- Security Research
- Security Research, Static Analysis, API Security, OWASP, Bug Bounty, Web Pentesting, Responsible Disclosure, F-Droid Security Audits, Kali Linux / Burp Suite
- Languages
- Python, Kotlin, TypeScript, Node.js, Rust
- Frameworks & Tools
- Next.js, React + Vite, Supabase, Cloudflare Workers + Pages, Capacitor
- Development Workflow & Tooling
- CLI Tools, AI-Assisted Engineering, QwenWork AI
- DevOps
- Git + GitHub Actions, Bash, n8n
Selected Projects
KarobarX
Trust-first social-commerce platform for Pakistan, built with React, Supabase, Cloudflare Pages, and Capacitor. It focuses on safer transactions, fast product discovery, and student needs.
Technologies: Startup, Marketplace, React, Supabase, Cloudflare, TypeScript
- Trust layer: masked chat, delivery-verification flow, and reputation signals
- Short-form Reel discovery feed with Cloudflare R2 media storage
- Student ecosystem: Study Graph, ISBN-based Book Exchange, and Student Alerts
- Security posture: RLS, Turnstile, HttpOnly admin cookies, TOTP 2FA, audit logs, and a stricter admin CSP
Pak Books
Free digital library for Pakistani students, built for 360 Muslim Experts. It brings textbooks, notes, past papers, and learning resources into a bilingual web experience with Telegram-based discovery; public usage metrics are not yet published.
Technologies: Education, Digital Library, Next.js, Cloudflare, TypeScript, Telegram Bot, Kaggle
- Next.js 16 + Cloudflare Pages + D1 + Workers KV + Internet Archive S3
- Telegram Bot with inline mode, fuzzy search, and a delete-my-data flow
- Kaggle operations with scheduled mirror and maintenance jobs
- Bilingual English/Urdu interface with RTL support, dark/light theme, PWA, and accessibility settings
shadowaudit
Open source CLI security tool that detects unauthenticated and undocumented API routes via static analysis. Supports Express, FastAPI, Django, Flask, NestJS, Rails, and Spring Boot. Maps findings to OWASP API Top 10 with risk scoring.
Technologies: Security, Node.js, Static Analysis, OWASP, CLI
- Static analysis engine with multi-framework scanner support
- OWASP API Top 10 risk mapping with severity scoring
- Published on npm with active community usage
- GitHub Action integration for CI/CD pipelines
- Live dashboard at shadowaudit-dashboard.vercel.app
Noor Connect
Comprehensive, beautiful, and privacy-focused Islamic companion application published on F-Droid.
Technologies: Islamic, Privacy, TypeScript, F-Droid
- Privacy-first Islamic companion app with no tracking
- Published on F-Droid with 395+ downloads
- TypeScript-based cross-platform architecture
Privacy-first, Islamic-values-aligned, FOSS GPL-v3 on-device content-filtering Android app.
Technologies: Android, Kotlin, Privacy, Content Filter, GPL-v3
- On-device content filtering with Islamic values alignment
- GPL-v3 licensed, fully open source
- Kotlin + Jetpack Compose, Capacitor for Android
Neuron-Encrypt
Transparent, open-source file encryption application featuring cryptographic security software.
Technologies: Encryption, Rust, Security, Cryptography, Privacy
- AES-256-GCM-SIV encryption with forward secrecy
- Rust implementation with zero dependencies
- Cross-platform: Linux, macOS, Windows
Simulation of a primitive AI agent with zero world knowledge.
Technologies: AI, Python, Reinforcement Learning, Simulation
- PPO + GRU based agent architecture
- Zero-shot learning simulation
- Python + PyTorch implementation
HAYAT-AI
Offline-first mobile medical assistant for high-conflict and crisis zones like Gaza and Kashmir. Provides physician-validated emergency protocols without internet.
Technologies: Android, Kotlin, Medical, Offline, Crisis Response
- Offline-first medical assistant with no internet dependency
- Physician-validated emergency protocols for trauma, surgery, and first aid
- Designed for crisis zones with high-conflict environments
Onionroute-Lite
Lightweight Orbot alternative for low-end Android. Tor VPN, SOCKS5/HTTP proxy, obfs4 and snowflake bridges, kill switch.
Technologies: Android, Kotlin, Tor, VPN, Privacy, F-Droid
- Lightweight Tor VPN alternative optimized for low-end Android devices
- SOCKS5/HTTP proxy support with obfs4 and snowflake bridges
- F-Droid compliant, GPL-3.0 licensed
Pocket Relay
Self-hosted Android agent host with private Telegram control and embedded runtime.
Technologies: Android, Kotlin, Telegram, Self-hosted, Agent
- Self-hosted agent runtime for Android with private Telegram control
- Embedded runtime with no cloud dependency
- GPL-3.0 licensed with active development
Nofap Fursan
Elite sovereign Command Centre for masculine discipline. Decentralized via Nostr with end-to-end NIP-44 encryption, featuring active Mindset Interventions and Biological Signal tracking.
Technologies: Android, Kotlin, Nostr, Privacy, Discipline
- Nostr decentralized architecture with NIP-44 end-to-end encryption
- Mindset Interventions and Biological Signal tracking
- No servers, no tracking — fully sovereign design
Photon-Dns
Android local-VPN DNS resolver manager with bounded DNS forwarding and resolver latency monitoring.
Technologies: Android, Kotlin, DNS, Privacy, DoH, DoT
- DNS-over-UDP, strict DNS-over-HTTPS, and strict DNS-over-TLS resolver support
- Per-resolver latency checks and automatic switching with cooldown and hysteresis
- Kotlin + Jetpack Compose with bounded packet handling and protected upstream sockets
synthetic-spirit
High-performance Android DNS sinkhole with a large malicious, tracking, and adult-content domain database.
Technologies: Android, Kotlin, DNS, Privacy, Adblock
- 200,000+ domain blocklist covering malware, tracking, and adult content
- Jetpack Compose UI with Material Design 3
- Local-only processing with zero telemetry
Open Source Contributions
GitLab — gitlab-shell
Fixed JWT refresh bug before rate-limit retries — preventing authentication failures under retry pressure.
Merge Request !1534 · Open
Inkscape — Inkscape 1.5
Fixed the Wide Screen preference-state regression so the action restores correctly after interface-mode changes and restart.
Merge Request !8122 · Merged
GitLab — GitLab Docs
Fixed test environment fallback mounts configuration — restored English-only doc resolution for localized sites (Japanese, French, Korean) by removing duplicate module.mounts override and adding --environment test to review-app CI. Closes #708.
Merge Request !2558 · Open
OpenMW — OpenMW
Documented a launcher-first mod-installation path so users can manage data directories without manually editing openmw.cfg.
Merge Request !5547 · Open
Selected Security Research
EC-Council (CodeRed)
Hall of Fame 2026 + Certificate of Appreciation
9 vulnerabilities (3 Critical)
Discovered 9 vulnerabilities including 3 critical findings across EC-Council web assets. Acknowledged in 12 minutes.
PriceOye
Acknowledged
5 vulnerabilities (3 Critical PII leaks)
Identified 5 vulnerabilities including 3 critical PII exposure issues. Remediation confirmed within 72 hours.
Waqar Electronics
Acknowledged
6 vulnerabilities (XSS-to-ATO chain)
Found 6 vulnerabilities including a stored XSS-to-account-takeover chain via insecure session cookies.
Certifications
CyberOps Associate — Networking Basics — Saylani Welfare International Trust
2026-06
Introduction to Cybersecurity — Saylani Welfare International Trust
2026-04
Network Technician Career Path — Saylani Cisco Networking Academy
2026-03
ChatGPT for Everyone — Learn Prompting
2026-01
Education
DAE Electronics (In Progress) — Technical College of Karachi
2024 — Present
Awards and Recognition
EC-Council Hall of Fame 2026 — EC-Council
2026-05
Recognized for 9 vulnerabilities (3 Critical) across EC-Council web assets. Certificate of Appreciation from President Sanjay Bavisi.
GitLab Core Contributor — GitLab
2024
MR !1534 — JWT refresh retry handling contribution in gitlab-shell.
Inkscape Contributor — Inkscape
2025
MR !8122 — wide-screen preference-state regression fix.
Languages
English (Professional) · Urdu (Native) · Arabic (Conversational (Quranic))