about
Ahmed Ibrahim — vulnerability researcher. I hunt 0/1/N-days across web, native, and supply chain, build open tools for the work, and write up everything with proof.
The handle is chattr; the lab is skeletonsec. The rule of the house:
everything here ships with evidence or it doesn’t ship.
The Lab
A small homelab, built to be rebuilt. Nothing exotic — the point is that any result on this site comes off infrastructure I can tear down and stand back up from notes, so a reproducer stays reproducible.
- one x86 box, a hypervisor, an isolated VLAN for targets
- victim VMs: intentionally vulnerable apps, end-of-life distros, mobile emulators for the mobile lane
- one fuzzing VM: coverage-guided fuzzers, sanitizer builds
- this site: markdown in a repo, built static, deployed from git
Trophy Wall
CVEs, vendor acknowledgments, hall-of-fames, CTF placements, bounties — reverse-chron, each with a link to proof, when they exist.
First entries in the pipe.
Dev Tools
| tool | what it does | language | stars | link |
|---|---|---|---|---|
| authprobe | authenticated-session record/refresh/export for DAST | Go | — | repo |
| skelet0n | staged research conductor, tamper-evident evidence ledger | Go | — | repo |
Star counts get wired in at build time; until then, honesty beats a stale number. Details on the projects page.
The Business
I take a small number of paid engagements: pentests, source-code audits, custom security tooling, and technical writing — all held to the same evidence standard as everything else on this site. Scope and contact are on services.
Timeline
Reverse-chron, and honest about what is still in progress.
- 2026-08 — skeletonsec.com goes public; the lab gets a front door.
- 2026 — authprobe shipped; first public tool.
- 2026 — skelet0n phase 0 — in progress (engine and ledger real, swarm and RAG are Phase 2).
- 2026 — first original-research disclosures — in progress; they land on research with timeline tables when done.
Earlier chapters stay offline until there is something evidence-worthy to say about them.
Trust
- email — chattr [at] linux [dot] com
- PGP — key will live at /pgp.txt; placeholder until the key is published. Encrypt anything sensitive.
- security.txt — /.well-known/security.txt for the machine-readable version.
To report a vulnerability in one of my tools, email chattr [at] linux [dot] com with PGP; acknowledgment within 72h.