Portfolio of ZGr3Y \aka Paolo Maria Scarlata

My project and works

View on GitHub

Welcome to my Portfolio ๐Ÿ‘‹

Hi, Iโ€™m ZGr3Y! Here I showcase my projects and coding experiments, with a focus on Web Security.


๐Ÿš€ Web Security Projects

CTF Vulnerability Lab (Bachelorโ€™s Thesis)

An offensive security training platform built with Docker and Node.js. I developed three isolated services simulating real-world vulnerabilities (IDOR with bypassable WAF, JWT Injection, and Weak Cryptography) to allow students to practice exploitation techniques in a controlled environment.

View Code

Broken Access Control & Mitigations

A research project focused on the #1 vulnerability in the OWASP Top 10. The application demonstrates practical cases of IDOR and insecure JWT implementations, while providing a parallel โ€œHardenedโ€ version of the code featuring rigorous validation, secure session management, and AES-256 encryption.

View Code


Find me on GitHub