Meeran Hassan

Meeran Hassan

Penetration Tester / Security Engineer

Sri Lanka

Penetration tester specializing in web application security. Passionate about post-quantum cryptography and CTF competitions.

about

skills

Security

Penetration TestingVAPTCode ReviewSIEMBug Bounty

Languages

GoPythonRustTypeScriptLuaBash

Cloud & IaC

AzureTerraformDockerSentinel

Frameworks

SvelteKitNext.jsExpress

education

MSc Network & Information Security

Kingston University · 2025

BSc (Hons) IT - Cyber Security

SLIIT · 2021 - 2024

experience

Security Engineer & Penetration Tester

Surge Global

May 2023 - Present

  • > Performed VAPT on in-house and client web applications
  • > Found 10-20 critical vulnerabilities per application on average
  • > Conducted security code reviews on client codebases
  • > Built Microsoft Sentinel SIEM solution with Terraform IaC
  • > R&D on prompt injection prevention methods

bug bounty

NASA Letter of Recognition

Received for responsibly disclosing a critical vulnerability

NASA Hall of Fame

Listed on the NASA VDP researcher acknowledgments

Keycloak Hall of Fame

Ranked #3 on the program leaderboard

CVEs pending

#3

Zivver Hall of Fame

Ranked #6 on the program leaderboard

#6
SAML Authentication Bypass - Admin Takeover

Forged unsigned SAML assertions to gain full admin access on a government application

Critical

Redirect URI Validation Bypass

Bypassed OAuth redirect URI validation via path traversal to steal authorization codes

High
RCE to Full Cloud Compromise

Exploited unpatched Ghostscript to achieve root RCE, escalating to AWS credential theft

High

...and several other findings across various programs.

projects

A knowledge repository with easy-to-understand explanations of complex concepts

SveltemdsvexTypeScript

Post-quantum steganography tool using ML-KEM-768 and AES-256-GCM

SvelteTypeScriptWebCrypto

Single Sign-On system based on quantum cryptography

PythonDockerPQC
recycleMe
21 stars

CLI tool to detect and humanize AI-generated text

Go

Rust API for benchmarking post-quantum JWT signature schemes

RustPQC

Client-side password manager with AES encryption

JavaScriptWebCrypto
view all repositories

achievements

capture the flag

SLIIT ISACA CTF

Solo vs 15 four-member teams

1st Place

CICRA 10th Summit CTF

Duo vs 40+ teams

2nd Place

Enigma CTF

19 participants

2nd Place

Manthra CTF

30+ participants

2nd Place

Medusa CTF

2nd Place

Consistently placed in the top 3 across all CTF competitions.

contact

Interested in working together or have a security concern? Feel free to reach out.

© 2025 Meeran Hassan