Mokrane ABDELMALEK

Mokrane ABDELMALEK

Penetration Testing Intern @Randorisec

Biography

Computer Systems Engineer and Master’s student in Networks, currently working as a Penetration Testing Intern. I have hands-on experience in web security, penetration testing, and code review. I participate in bug bounty programs and CTF competitions with @noreply team. Passionate about cybersecurity and always eager to take on new challenges and opportunities.

Interests
  • Penetration Testing
  • Vulnerability Research
  • Web Application & API Security
  • Cloud Computing / DevOps
Education
  • Master Degree in Computer Science, 2025

    Sorbonne Université - Sciences et Ingénierie, Paris

  • Computer Science Engineering Degree, 2024

    Ecole Supérieure nationale d'Informatique, ESI in Algiers, Algeria

  • Master Degree in Computer Science, 2024

    Ecole Supérieure nationale d'Informatique, ESI in Algiers, Algeria

Discovered Vulnerabilities

Projects

*
Dynamic IP Getter

Dynamic IP Getter

Bash script to get the dynamic public IP address pushed on a private Github repo each time it changes.

esiCDN

esiCDN

esiCDN - a CDN architecture for Algerian universities

Java arithmetic interpreter

Java arithmetic interpreter

Mini interpreter of arethmetic operations written in JAVA

FastAPI Project Template

FastAPI Project Template

RESTful Back-end project template with FastAPI + PostgreSQL + JWT + Docker + Nginx

Mark Checker

Mark Checker

Automation script using Python and Selenium, in order to login on talents.esi.dz and check for last released marks.

QR generator

QR generator

A simple QR code generator application developed with Flask.

Car Tracking App

Car Tracking App

A ReactJS app using MapBox and Firebase to show position in maps

SQL Injection

SQL Injection

a time based PostGreSQL injection using Dichotomic search, in order to dump the database.

Experience

 
 
 
 
 
Randorisec
Penetration Testing Intern
February 2025 – August 2025
  • • Improvement and creation of static analysis rules for CodeQL and Semgrep, to expand vulnerability coverage and reduce false positives.
  • Practical application on open‑source projects (Samsung MagicInfo, WordPress plugins, RagFlow), leading to the discovery of zero‑day vulner‑ abilities and CVE assignments (e.g.: CVE‑2025‑5487).
  • Contribution to penetration testing engagements for various clients, complementing the research work.
 
 
 
 
 
Hackerone - YesWeHack - Huntr
Bug bounty hunter
June 2023 – Present
  • Discovered and reported numerous vulnerabilities, including critical ones, to known companies such as Visa and VFS Global.
  • Got rewarded for my findings and have been assigned many CVEs, which let me gain a lot of experience with real world products.
 
 
 
 
 
Datawaves
DevOps Engineer
January 2023 – May 2023 London, UK

Responsibilities include:

  • Analysing
  • Modelling
  • Deploying
  • Automating
  • Maintaining
 
 
 
 
 
Upwork
Freelancer
March 2022 – Present
  • Carried out many technical tasks related to Security, Web Development, and IT automation.
  • Had contact with real clients and solved real-world issues.
 
 
 
 
 
GDG Algiers
Development Department Manager
August 2021 – July 2022 Algiers, Algeria
  • Managed a team of a lot of developers, and created a lot of dev projects and events websites.
  • Organized a lot of events and workshops.
 
 
 
 
 
GDG Algiers
Development Department Manager
August 2021 – July 2022 Algiers, Algeria
  • Managed a team of a lot of developers, and created a lot of dev projects and events websites.
  • Organized a lot of events and workshops.
 
 
 
 
 
CodeLabs Academy
Content Creator
August 2021 – January 2022 London, UK
  • Prepared content for the cyber security bootcamp and learned how to redact technical content.
 
 
 
 
 
Red Fox Labs
Junior Penteration Tester
October 2021 – February 2022 Dublin, Ireland
  • Performed penetration testing on commercial websites, whether it was a black, gray, or white box.
  • Interacted with actual products, experiment with their features, and apply the security principles learned.
 
 
 
 
 
Shellmates Club
Active Member
October 2019 – Present Algiers, Algeria
  • Organized many CaptureTheFlag competetions and workshops.
  • Creating Web exploitation and Cryptography challenges for the CTFs.

Conducted Workshops

Client-side Web Security Workshop
Oussama and I, held a workshop in Bsides Algiers Finals 2021, about client-side web security, we talked about the most common vulnerabilities in the client-side, and how to exploit them, and how to prevent them.
Introduction to CTFs
Akram Boutouchent and I, held a workshop in Sahra with GDG Algiers, about the basics of CTFs, we talked about the most common categories, and how to start solving challenges.

Skills

Technical
Web security
Cryptography
Automation
Reverse engineering
Cloud Security
Docker, Kubernetes
Soft
Crtical thinking
Time management
Problem solving
Team work & collaboration

Contact

Feel free to get in touch if you have any questions or suggestions.