Skip to content
View tanzz1337's full-sized avatar
๐ŸŒด
On vacation
๐ŸŒด
On vacation

Block or report tanzz1337

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
tanzz1337/README.md

๐Ÿ‘‹ Hi, I'm Sultan Raja Marlindo

Typing SVG

LinkedIn Twitter HackTheBox TryHackMe

๐ŸŽฏ About Me

Passionate cybersecurity professional specializing in penetration testing and vulnerability assessment. Active CTF player and security researcher dedicated to making the digital world safer.

$ whoami
> Penetration Tester | CTF Player | Security Researcher
> "Breaking things to make them stronger"
  • ๐Ÿ” Specializing in Web Application & Network Penetration Testing
  • ๐Ÿšฉ Active CTF player on HackTheBox, TryHackMe, and CTFtime
  • ๐Ÿ› Bug bounty hunter finding vulnerabilities to help secure applications
  • ๐ŸŽ“ Constantly learning and sharing cybersecurity knowledge
  • ๐Ÿ’ป IT enthusiast exploring the latest security tools and techniques

Berpengalaman pada pengujian aplikasi web: authentication, authorization, session management, input validation, file upload, dan API security. Berminat pada bug hunting (responsible disclosure), threat modeling, dan penguatan pipeline CI/CD terhadap secret leakage. Prefer bekerja di lingkungan yang aman/terisolasi (Docker/VM) dan selalu mengikuti etika pen-test.

๐Ÿ› ๏ธ Keahlian Utama

  • Web App Testing: OWASP Top 10, XSS, SQLi, CSRF, IDOR, SSRF, RCE (analisis & mitigasi)
  • Authentication & Authz: session fixation, JWT, password flows, SSO assessment
  • API Security: API endpoints audit, rate limiting, token misuse, IDOR pada API
  • Recon & Scanning: passive/active recon, subdomain enumeration, dirb, fuzzing
  • Forensics & Remediation: log analysis, incident triage, secret rotation
  • Coding/Automation: scripting untuk PoC & scanner (Python / Bash), CI pipelines

๐Ÿงฐ Tools Favorit

  • Burp Suite (Professional / Community workflows)
  • OWASP ZAP, Nmap, Nikto
  • sqlmap, ffuf, dirbuster, wfuzz
  • Gitleaks, TruffleHog, git-secrets
  • Docker, Ghidra (untuk reverse engineering sederhana), Wireshark
  • Python (requests, BeautifulSoup), Node.js (simple tooling)

๐Ÿ› ๏ธ Technical Arsenal

Penetration Testing & Red Team

Kali Linux Burp Suite Metasploit Wireshark Nmap

Programming & Scripting

Python Bash JavaScript PHP PowerShell

Security Domains

  • ๐ŸŒ Web Application Security (OWASP Top 10)
  • ๐Ÿ”’ Network Security & Infrastructure Testing
  • ๐ŸŽญ Social Engineering & OSINT
  • ๐Ÿ”“ Cryptography & Password Cracking
  • ๐Ÿ“ฑ Mobile Application Security
  • โ˜๏ธ Cloud Security (AWS, Azure)

๐Ÿ’ก Currently Learning

  • ๐Ÿ” Advanced exploitation techniques
  • โ˜๏ธ Cloud security and container security
  • ๐Ÿค– AI/ML security and adversarial attacks
  • ๐Ÿ“ฑ iOS/Android application security

Profile Views

"The only truly secure system is one that is powered off, cast in a block of concrete and sealed in a lead-lined room with armed guards." - Gene Spafford

๐Ÿ“Š GitHub Stats

GitHub Stats

Top Langs

GitHub Streak

Pinned Loading

  1. tanzz1337.github.io tanzz1337.github.io Public template

    Personal Portofolio Profil - Desain Carbon modern dengan tampilan elegan dan cyber tech

    HTML 1

  2. website-tidak-baik.github.io website-tidak-baik.github.io Public

    Contoh Pengelolaan Sebuah Website Dengan Cara Yang Tidak Baik

    HTML 1

  3. ApacheAudit ApacheAudit Public

    Tools sederhana yang bertujuan untuk melakukan audit dengan cepat dan mengidentifkasi missconfiguration pada web server apache

    Python 1 1

  4. LogScanner LogScanner Public

    Simple tools for analysis .log from apache / nginx web server

    HTML 1 1

  5. WPSec-Audit WPSec-Audit Public

    WP Sec Audit merupakan tools yang dibuat untuk memudahkan audit keamanan pada website berbasis CMS wordpress,efisien dan mudah digunakan untuk kalanagan sysAdmin,Administrator bahkan seorang Pentester

    Python 1