Skip to content
View basriakkaya's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report basriakkaya

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
basriakkaya/README.md

Basri Akkaya

Ethical Hacker · Security Researcher · Network & Web Pentester · Linux Enthusiast

Cybersecurity is not a hobby, it’s a responsibility.

Website LinkedIn YouTube TryHackMe


whoami

I am a Computer Engineering student at Goce Delčev University – Štip, focused on application security, web penetration testing, network security, responsible disclosure, and security tooling.

Most days, you will find me somewhere between a Linux terminal, Burp Suite, a half-finished security tool, and another suspicious domain waiting to be reported.

I spend a significant part of my time researching vulnerabilities, analyzing web applications, studying network behavior, and building tools that make repetitive security work more efficient. I have also reported thousands of spam, scam, phishing, and malicious websites through the appropriate channels.

A vulnerability I responsibly disclosed to my faculty later became an internship opportunity at the Faculty of Informatics. That experience shaped the way I approach security research:

find the issue
understand the impact
document it clearly
report it responsibly
help improve the system

I am also part of the management team at BugHane Academy, a cybersecurity community focused on practical learning, collaboration, and responsible security research.


security.research

Two CVE identifiers have been assigned to vulnerabilities I discovered and responsibly disclosed.

CVE-2026-52662

Research involving an embedded network device and unauthenticated service exposure.

View the official CVE record

CVE-2026-16323

An Execution After Redirect vulnerability affecting access-control enforcement.

View the official CVE record


recognition

Achievement Details
SANS CTF 4th place
Being Wise CTF 4th place
University Hall of Fame Recognition for responsible security research
Rual Hall of Fame Recognition for vulnerability reporting
Goce Delčev University – Štip Official recognition letter and faculty publication
Rahim Usta Anadolu Lisesi Official recognition letter

References


technical.focus

Area Technologies, Tools, and Practices
Application Security Web application testing, access-control validation, authentication testing, vulnerability verification
Penetration Testing Burp Suite, OWASP ZAP, Nmap, ffuf, sqlmap, WPScan, XSStrike, Dalfox
Network Security TCP/IP, Wireshark, service analysis, network enumeration, firewall concepts, ProxyChains, Netcat
Reconnaissance subfinder, amass, katana, gau, waybackurls, HTTP probing, attack-surface mapping
Security Research Responsible disclosure, CVE coordination, impact analysis, technical reporting
Development Python, Bash, Rust, JavaScript, TypeScript, automation, CLI and desktop tooling
Platforms Kali Linux, Debian, macOS, Windows, WSL, Raspberry Pi
Infrastructure Git, GitHub, Vercel, Docker fundamentals, Nginx, Linux administration

featured.projects

KageGate

A defensive desktop application for authorized access-control and Execution After Redirect validation.

Stack: Tauri 2 · React · TypeScript · Rust · SQLite

Core areas include:

  • URL and scope validation
  • Redirect-safety checks
  • DNS and IP pinning
  • Per-scan authorization
  • Audit logging
  • Pause, resume, and recovery workflows
  • Turkish and English localization

KageTrace

An OSINT-focused phishing analysis and domain monitoring tool designed to investigate suspicious infrastructure.


A security-focused script for analyzing exposed credentials and auditing email and password security.


A productivity-oriented terminal environment built around Zsh and a customized security-research workflow.


Security Recon Tooling

I am actively working on tools for:

  • JavaScript endpoint discovery
  • Subdomain reconnaissance
  • Attack-surface mapping
  • HTTP status and technology monitoring
  • Authorized access-control validation
  • Security reporting automation

Raspberry Pi Security Lab

A Raspberry Pi 5-based lab environment for Linux, networking, security experimentation, automation, and computer-vision projects.


education.experience

Goce Delčev University – Štip

Computer Engineering and Technologies

My academic focus includes computer engineering, networking, operating systems, software development, and cybersecurity.

Faculty of Informatics — Security Internship

After responsibly disclosing a security issue affecting university infrastructure, I was given the opportunity to continue my work through a faculty internship focused on authorized security testing and technical documentation.


community

BugHane Academy

I am part of the management team at BugHane Academy, a cybersecurity community where researchers and learners share knowledge, collaborate, and improve together.


writing

I publish practical notes about cybersecurity, Linux, software development, security research, and the technical problems I encounter while learning.

My goal is not to turn every small problem into a forty-page guide. If something can be explained clearly in a few paragraphs, that is usually the better option.

Read my technical blog


github.activity

Basri Akkaya GitHub statistics

Most used programming languages


connect

For security research, collaboration, community work, or professional communication:

research responsibly · report clearly · keep learning

Pinned Loading

  1. KageTarget KageTarget Public

    Privacy-first Chrome extension for fast, user-initiated web reconnaissance and page inspection.

    TypeScript 10

  2. kagedork kagedork Public

    TypeScript

  3. KageLeak KageLeak Public

    TypeScript

  4. kage-terminal kage-terminal Public

    Shell

  5. google-dorks-bug-bounty google-dorks-bug-bounty Public

    A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting