majdeddine.com

About

I am Majdeddine BEN HADJ BRAHIM, a penetration tester and security researcher based in Munich, Germany. Colleagues call me Maje.

I currently work in offensive security at Rohde & Schwarz. My main areas of interest are web security, Active Directory and Azure AD (Entra ID) attacks, and IoT security. Before moving to Germany I trained as an engineer in Tunisia, completing a Bachelor in computer systems engineering at ISSAT Mateur (Carthage University) and a national engineering degree at TEK-UP University, both recognized in Germany with an official ZAB Statement of Comparability.

Research

I focus on vulnerability research and responsible disclosure, which has led to three published CVEs so far:

  • CVE-2024-6494, stored XSS in the WordPress File Upload plugin
  • CVE-2024-6477, sensitive data disclosure in the UsersWP plugin
  • CVE-2024-6243, stored XSS in the HTML Forms plugin

Beyond that, I independently discovered and reported a 3D Secure verification bypass affecting Google payment products through the Google Vulnerability Reward Program. It was triaged as a duplicate of an internal finding and fixed later.

Write-ups live on the research page, and the testing methodology I actually follow on engagements is documented in my checklists.

Certifications

Offensive

  • CRTP - Certified Red Team Professional
  • eWPTX - Web Application Penetration Tester eXtreme
  • eWPT - Web Application Penetration Tester
  • eMAPT - Mobile Application Penetration Tester
  • eCPPT - Certified Professional Penetration Tester
  • CEH - Certified Ethical Hacker
  • eJPT - Junior Penetration Tester
  • PT1 - Penetration Tester Level 1
  • CC - Certified in Cybersecurity (ISC2)

Infrastructure

  • RHCE - Red Hat Certified Engineer
  • RHCSA - Red Hat Certified System Administrator

Development

  • PCAP - Certified Associate in Python Programming

Resume

You can download my resume as a PDF.

Contact

The fastest way to reach me is contact@majdeddine.com. I am also on GitHub, X and LinkedIn.