Skip to content
Z3tra

Hi There!

I am Web Security Researcher

Building secure applications, researching web vulnerabilities and continuously learning through practice.

Z3tra — portrait

Who am i?

I'm Z3tra, a Web Security Researcher

I got into security about two years ago — not to become a hacker, but because I wanted to understand how applications actually work underneath. Over time I narrowed down to web application security, which is where the logic lives. I also build my own projects, so I see applications from the developer's side as well as the researcher's.

Started in security:
2023
Focus:
Web application security
Currently:
Preparing the OSCP
Looking for:
An apprenticeship, Sept 2026
From:
France

What I do

My Services

Assessment tooling is used in labs, CTFs and authorised engagements. Nowhere else.

Web Application Security

Assessing web applications against the classes that actually show up — broken access control, injection, authentication flaws — starting from how the application works, not from a scanner.

Secure Development

Building with Next.js, TypeScript and PostgreSQL, with the security decisions made at design time: scoped queries, validated input, and secrets that never reach the client.

Vulnerability Research

Reading source with intent, reproducing findings from a clean state, and turning them into a minimal proof of concept a developer can act on.

Infrastructure & Isolation

Containerised environments that assume compromise: dropped capabilities, no outbound network, hard resource limits and a short life. Built for Hackuten, used in my lab.

Automation & Tooling

Python and shell tooling for the parts of enumeration and reporting I run every time — consistent output, reproducible results, less room to forget a step.

Technical Reporting

Findings written for the person who has to ship the fix: impact, reproduction, evidence and remediation, in the terms of their codebase.

Selected work

Three projects, three very different problems

A platform built to be attacked, a messenger built to distrust its own server, and a safety app where being offline is the failure I have to design for.

Live

Hackuten

A CTF platform for learning cybersecurity

Hackuten is a capture-the-flag platform covering several areas of cybersecurity — web, reverse engineering, cryptography, forensics and more. It exists to make the first steps into the field less discouraging: challenges that teach something specific, in an order that makes sense, with infrastructure that does not get in the way.

  • Next.js
  • TypeScript
  • TailwindCSS
  • PostgreSQL
  • Docker
In development

Orbyte

An end-to-end encrypted messenger

Orbyte is an encrypted messaging application in the spirit of Session: private conversations that do not require a phone number to start, and a server that is designed to know as little as possible. It is in active development — the parts that are built are built carefully, and the parts that are not are honestly labelled as such.

  • TypeScript
  • React
  • Next.js
  • Node.js
  • PostgreSQL
In development

Batelys

Lone worker safety, one button at a time

Batelys protects people who work alone. You check in when you arrive, then press a button now and then to confirm you are fine. Miss a check-in — because you fell, collapsed, or simply cannot reach your phone — and an alert leaves on its own, with your position, escalating through your chain until someone responds.

  • TypeScript
  • Next.js
  • React
  • Node.js
  • PostgreSQL

Writing

Notes, write-ups and research

What I learned, written while it was still fresh — including the paths that went nowhere, which is usually the useful part.

Research4 min

Encrypting content is easy. Hiding who talks to whom is not.

Notes from designing Orbyte: why metadata is often more sensitive than message content, and the spectrum of defences between 'we encrypt messages' and actual metadata resistance.

  • Research
  • Web Security
  • Cryptography
Article3 min

Understand the application before you test it

Scanners find what they were told to look for. The bugs that matter live in the gap between what an application believes about itself and what it actually enforces.

  • Web Security
  • OWASP
  • Methodology
Research4 min

When being offline is the emergency: designing a reliable dead man's switch

Notes from Batelys on building a lone-worker alert system, where availability is a safety property and a missed check-in has to be as loud as a pressed button.

  • Research
  • Linux
  • Architecture

Right now

Where I am at

Kept current, because a portfolio that describes last year is worse than no portfolio.

Latest experience

Cybersecurity Intern

Oteria · 2025

Second placement, focused on web application security: reviewing applications, reproducing findings and turning them into reports someone could act on.

Preparing OSCPPreparing OSWE

Stack

Languages

  • TypeScript
  • Python
  • JavaScript
  • SQL
  • HTML
  • CSS

Frameworks

  • Next.js
  • React
  • TailwindCSS

Technologies

  • Git
  • GitHub
  • Docker
  • REST API
  • Linux
  • PostgreSQL

Security tooling

  • Burp Suite
  • Caido
  • OWASP ZAP
  • ffuf
  • Gobuster
  • Nmap
  • SQLMap
  • Hashcat

Systems

  • CachyOS
  • Windows
  • macOS

Looking for an apprenticeship in application security, starting September 2026.

If you are hiring, or you just found something on this site worth arguing about, I would like to hear from you.