Penetration testing, bug bounty, and vulnerability research.
I am Amr Al Hallak, a freelance cybersecurity professional focused on finding real-world security issues in web applications and online systems. My work centers on penetration testing, bug bounty hunting, and responsible vulnerability discovery across public and private programs.
I help organizations identify weaknesses before attackers do, with practical testing and clear reporting around issues such as XSS, SQL injection, local file inclusion, and other impactful vulnerabilities.
What I do
I work with companies and platforms that value proactive security testing. My main focus is bug bounty, but I also support broader cybersecurity work related to application security and vulnerability assessment.
- Penetration testing for web applications and exposed assets
- Bug bounty research across leading disclosure platforms
- Vulnerability discovery and responsible reporting
- Testing for issues including XSS, SQL injection, and file inclusion
Selected CVEs
I have identified multiple vulnerabilities that were assigned CVE identifiers.
Main platforms
These are the main platforms where I work and participate in security programs.