About Me
Hello, I'm Adham Khairy (0xSponge), a Penetration Tester and Bug Bounty Hunter specializing in web application and Active Directory exploitation, with hands-on Android and working iOS testing.
I combine deep manual testing with custom recon and verification automation to uncover high-impact flaws that automated scanning misses. Currently pursuing my Bachelor's degree in Computer Science at Helwan University.
Experience
- Reported 50+ valid security vulnerabilities across 20+ companies through responsible disclosure programs, contributing directly to improving production security.
- Performed manual testing, endpoint mapping, and authorization abuse to identify high-impact issues beyond automated scanning.
- Completed 840+ TryHackMe rooms, 120+ HackTheBox challenges, 40+ HackTheBox machines, and 175+ PortSwigger Web Security Academy labs covering Web, Active Directory, and privilege escalation.
- Participated in 15+ online and offline CTF competitions, solving web, network, and miscellaneous challenges under time pressure.
- Completed intensive hands-on training in Web, Network, and Active Directory penetration testing, with introductory exposure to Android security.
- Concluded with a full Active Directory engagement and presented findings to peers and instructors, improving reporting and teamwork skills.
Certifications
Education
Bachelor of Computer Science
Helwan University โ Cairo, Egypt (Oct. 2024 โ Present)
Expected Graduation: June 2028
Relevant Coursework
Philosophy
I believe understanding how to break systems is fundamental to building secure ones. My approach is methodical, ethical, and focused on continuous learning โ through hands-on practice, bug bounty hunting, and CTF competitions I constantly push my boundaries to stay ahead of emerging threats.
By sharing knowledge and contributing to the security community, I aim to help create a safer digital environment. Every vulnerability discovered and responsibly disclosed makes the internet a little bit safer.