about

Ahmed Ibrahim — vulnerability researcher. I hunt 0/1/N-days across web, native, and supply chain, build open tools for the work, and write up everything with proof.

The handle is chattr; the lab is skeletonsec. The rule of the house: everything here ships with evidence or it doesn’t ship.

The Lab

A small homelab, built to be rebuilt. Nothing exotic — the point is that any result on this site comes off infrastructure I can tear down and stand back up from notes, so a reproducer stays reproducible.

  • one x86 box, a hypervisor, an isolated VLAN for targets
  • victim VMs: intentionally vulnerable apps, end-of-life distros, mobile emulators for the mobile lane
  • one fuzzing VM: coverage-guided fuzzers, sanitizer builds
  • this site: markdown in a repo, built static, deployed from git

Trophy Wall

CVEs, vendor acknowledgments, hall-of-fames, CTF placements, bounties — reverse-chron, each with a link to proof, when they exist.

First entries in the pipe.

Dev Tools

toolwhat it doeslanguagestarslink
authprobeauthenticated-session record/refresh/export for DASTGorepo
skelet0nstaged research conductor, tamper-evident evidence ledgerGorepo

Star counts get wired in at build time; until then, honesty beats a stale number. Details on the projects page.

The Business

I take a small number of paid engagements: pentests, source-code audits, custom security tooling, and technical writing — all held to the same evidence standard as everything else on this site. Scope and contact are on services.

Timeline

Reverse-chron, and honest about what is still in progress.

  • 2026-08 — skeletonsec.com goes public; the lab gets a front door.
  • 2026 — authprobe shipped; first public tool.
  • 2026 — skelet0n phase 0 — in progress (engine and ledger real, swarm and RAG are Phase 2).
  • 2026 — first original-research disclosures — in progress; they land on research with timeline tables when done.

Earlier chapters stay offline until there is something evidence-worthy to say about them.

Trust

  • email — chattr [at] linux [dot] com
  • PGP — key will live at /pgp.txt; placeholder until the key is published. Encrypt anything sensitive.
  • security.txt/.well-known/security.txt for the machine-readable version.

To report a vulnerability in one of my tools, email chattr [at] linux [dot] com with PGP; acknowledgment within 72h.