Skip to content
View Aether-0's full-sized avatar

Highlights

  • Pro

Block or report Aether-0

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Aether-0/README.md
Aether cybersecurity profile banner

San Wana Zaw

Cybersecurity Student · Security Researcher · Tool Builder

Web Security · Red Teaming · Vulnerability Research · Recon Automation


Profile · Repositories · Projects


Profile

Alias       : Aether
Discipline  : Cyber Security
Role        : Security Researcher and Tool Builder
Environment : Linux
Objective   : Professional Penetration Tester and Red Teamer

I am a B.Sc. Computer Science student specializing in Cyber Security. My work focuses on practical security research, penetration testing, reconnaissance automation, and building tools that make authorized testing more efficient.

I value deep technical understanding, reproducible results, clear reporting, and responsible disclosure.


Focus

Security Research

  • Web application security
  • Vulnerability analysis
  • Proof-of-concept development
  • Authentication and authorization testing
  • Responsible vulnerability disclosure
  • Technical security reporting

Offensive Security

  • Penetration testing
  • Red-team methodology
  • Attack-surface analysis
  • Reconnaissance
  • Network security
  • Capture the Flag challenges

Engineering

  • Security automation
  • Command-line tools
  • HTTP testing utilities
  • Linux tooling
  • Workflow integration
  • Technical documentation

Current Development

  • Advanced web exploitation
  • Business-logic testing
  • Access-control vulnerabilities
  • Network exploitation
  • Secure tool development
  • Professional reporting

Featured Work

A lightweight HTTP method-testing utility written in Go for authorized security assessments.

Capabilities

  • Concurrent request processing
  • Custom HTTP method selection
  • Status-code filtering
  • Configurable timeouts and retries
  • Standard-input and file support
  • Silent and verbose output

Go HTTP Concurrency CLI

Educational tooling for studying CVE-2024-12986 in controlled laboratory environments.

Contents

  • Bash-based scanner
  • Python proof of concept
  • Vulnerability documentation
  • Testing guidance
  • Responsible-use notice

Python Bash HTTP Security Research

A Linux utility that simplifies managing a TryHackMe OpenVPN connection.

Capabilities

  • VPN configuration installation
  • Global command shortcut
  • Start and stop controls
  • Configuration replacement
  • Linux-focused workflow

Bash Linux OpenVPN Automation

Vulnerability Research

My research process emphasizes reproducibility, minimal proof of impact, clear documentation, and coordinated disclosure.

Research milestone

CVE-2025-55575

Principles

  • Confirm scope before testing
  • Prove impact without causing harm
  • Access only what is necessary
  • Provide practical remediation

Technical Stack

Programming and Scripting

Python Go Bash Java

Systems and Development

Linux Kali Linux Parrot OS Git

Security Tools

Burp Suite Nmap Metasploit OWASP


Current Direction

aether = {
    "research": [
        "web application vulnerabilities",
        "authentication weaknesses",
        "access-control failures",
        "network security"
    ],
    "engineering": [
        "recon automation",
        "security tooling",
        "Linux utilities",
        "repeatable testing workflows"
    ],
    "principles": [
        "understand before automating",
        "test only with authorization",
        "prove impact without causing harm",
        "document findings clearly"
    ],
    "goal": "Become a professional penetration tester and red teamer"
}

Research Workflow

SCOPE
  Confirm authorization
  Review program rules
  Identify allowed assets
  Define testing limits

RECON
  Discover assets
  Identify technologies
  Map exposed services
  Build the attack surface

TEST
  Authentication
  Authorization
  Input handling
  Business logic
  Session management
  Security configuration

VALIDATE
  Reproduce consistently
  Identify the root cause
  Confirm realistic impact
  Minimize unnecessary access

REPORT
  Provide clear reproduction steps
  Explain the security impact
  Include relevant evidence
  Recommend practical remediation

Responsible Security

All security testing, vulnerability research, and proof-of-concept work presented on this profile is intended only for systems I own, controlled laboratories, Capture the Flag challenges, educational security platforms, bug-bounty programs within their published scope, or systems where explicit authorization has been granted.

I do not support unauthorized access, credential abuse, data theft, service disruption, malware deployment, destructive testing, or activity outside an approved scope.


Collaboration

For project questions, bug reports, improvements, or responsible security collaboration, open an issue in the relevant repository.

Think deeply. Test responsibly. Build continuously.

aether@redshadow:~/security$ status
learning | researching | building

Popular repositories Loading

  1. AETHER-SPAM AETHER-SPAM Public

    Python 343

  2. tryhackmevpn-shortcut tryhackmevpn-shortcut Public

    Shell 342

  3. r3dly-d34dly r3dly-d34dly Public

    Go 342

  4. fr33b00k fr33b00k Public

    Python 341

  5. CVE-2024-12986 CVE-2024-12986 Public

    Shell 341

  6. learn4free learn4free Public

    Python 341