🧠 About Me

I'm trabbit (Γ‰mile Durand), a 17-year-old cybersecurity researcher and ethical hacker. I uncover real-world web vulnerabilities, build security tools, and promote awareness through demos and videos. I specialize in creative XSS techniques, recon automation, and OSINT investigations.

πŸ”Ž Vulnerability Discoveries

πŸ“¦ Strikingly iframe Injection

Abused the preview iframe of strikingly.com to embed phishing content in a trusted domain context.

πŸ” YouTube Redirect Bypass

Tricked users into visiting untrusted links while bypassing YouTube’s redirect warnings using clever encoding.

πŸ“œ Oracle JWT Leak

Archived Oracle URLs exposed over 500 expired JWTs containing internal user data, including emails and IDs.

πŸŒ€ ODR (Obscured Domain Redirect)

Technique using userinfo@host syntax to mask malicious URLs β€” tested across modern Chromium browsers.

πŸ› οΈ Custom Tools

πŸ“· sshot

Terminal tool to bulk-screenshot websites from a URL list using an API β€” useful for recon snapshots.

πŸ•΅οΈ BHunty

Bash tool that runs Subfinder, collects Wayback URLs, and scans for sensitive keywords like password and wp-admin.

πŸ“‘ Loctrac

JS + Bash based tool for device tracking, bundled with a military UI and a web front-end version.

πŸ“Š Pentagone-Toolkit

A modular pentesting Bash suite for recon, scanning, and reporting β€” inspired by real-world workflows.

πŸ§‘β€πŸ’» Scripting Skills

These are the scripting languages I use regularly, along with how comfortable I feel using them:

Bash
95%
JavaScript
85%
Python
70%
HTML/CSS
90%
PHP
40%
SQL
65%

🚨 Predator Investigation

Used OSINT and investigative methods to identify a child predator employed in a Florida school. Worked with authorities to report and remove him from his position. Case was documented for educational awareness purposes only.