Skip to content
View 0x5chltz's full-sized avatar

Block or report 0x5chltz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0x5chltz/README.md
0x5chltz's GitHub profile

HelloWorld("print")

Security researcher focused on web exploitation and CTF challenges. I spend my time crafting payloads, building exploit PoCs, and digging into web application vulnerabilities.

  • Build offensive tooling: SSTI-Exploit (Flask/Jinja2 SSTI to RCE) and Lepton7-Exploit (LeptonCMS 7.0.0 authenticated RCE)
  • CVE-2025-6019: local privilege-escalation PoC with automated exploit scripts
  • On the defensive side: phishion, a full-stack anti-phishing platform (Flask + React)
  • Into pentest tooling (sqlmap, John the Ripper, PayloadsAllTheThings)
  • Also build side projects: Task-Reminder, Notepad, Personal-Cloud, KiniBusApps

Pinned Loading

  1. KiniBusApps KiniBusApps Public

    Forked from AlfiMaulanaA/KiniBusApps

    Java

  2. Lepton7-Exploit Lepton7-Exploit Public

    Python

  3. phishion phishion Public

    JavaScript

  4. SSTI-Exploit SSTI-Exploit Public