About
I am Majdeddine BEN HADJ BRAHIM, a penetration tester and security researcher based in Munich, Germany. Colleagues call me Maje.
I currently work in offensive security at Rohde & Schwarz. My main areas of interest are web security, Active Directory and Azure AD (Entra ID) attacks, and IoT security. Before moving to Germany I trained as an engineer in Tunisia, completing a Bachelor in computer systems engineering at ISSAT Mateur (Carthage University) and a national engineering degree at TEK-UP University, both recognized in Germany with an official ZAB Statement of Comparability.
Research
I focus on vulnerability research and responsible disclosure, which has led to three published CVEs so far:
- CVE-2024-6494, stored XSS in the WordPress File Upload plugin
- CVE-2024-6477, sensitive data disclosure in the UsersWP plugin
- CVE-2024-6243, stored XSS in the HTML Forms plugin
Beyond that, I independently discovered and reported a 3D Secure verification bypass affecting Google payment products through the Google Vulnerability Reward Program. It was triaged as a duplicate of an internal finding and fixed later.
Write-ups live on the research page, and the testing methodology I actually follow on engagements is documented in my checklists.
Certifications
Offensive
- CRTP - Certified Red Team Professional
- eWPTX - Web Application Penetration Tester eXtreme
- eWPT - Web Application Penetration Tester
- eMAPT - Mobile Application Penetration Tester
- eCPPT - Certified Professional Penetration Tester
- CEH - Certified Ethical Hacker
- eJPT - Junior Penetration Tester
- PT1 - Penetration Tester Level 1
- CC - Certified in Cybersecurity (ISC2)
Infrastructure
- RHCE - Red Hat Certified Engineer
- RHCSA - Red Hat Certified System Administrator
Development
- PCAP - Certified Associate in Python Programming
Resume
You can download my resume as a PDF.
Contact
The fastest way to reach me is contact@majdeddine.com. I am also on GitHub, X and LinkedIn.