<!doctype html><html lang=en-us><head><meta name=generator content="Hugo 0.161.1"><meta http-equiv=X-Clacks-Overhead content="GNU Terry Pratchett"><meta charset=utf-8><meta name=viewport content="width=device-width,initial-scale=1"><title>netw0rk | Cybersecurity & Software Engineering | netw0rk.io</title><meta name=title content="netw0rk | Cybersecurity & Software Engineering"><meta name=description content="Cybersecurity Professional and Software Engineer specializing in penetration testing, secure software development, and vulnerability research. Available for contract and consulting engagements."><meta name=keywords content><meta property="og:url" content="https://netw0rk.io/"><meta property="og:site_name" content="netw0rk.io"><meta property="og:title" content="netw0rk | Cybersecurity & Software Engineering"><meta property="og:description" content="Cybersecurity Professional and Software Engineer specializing in penetration testing, secure software development, and vulnerability research. Available for contract and consulting engagements."><meta property="og:locale" content="en_us"><meta property="og:type" content="website"><meta name=twitter:card content="summary"><meta name=twitter:title content="netw0rk | Cybersecurity & Software Engineering"><meta name=twitter:description content="Cybersecurity Professional and Software Engineer specializing in penetration testing, secure software development, and vulnerability research. Available for contract and consulting engagements."><meta itemprop=name content="netw0rk | Cybersecurity & Software Engineering"><meta itemprop=description content="Cybersecurity Professional and Software Engineer specializing in penetration testing, secure software development, and vulnerability research. Available for contract and consulting engagements."><meta itemprop=datePublished content="2026-04-12T00:00:00+00:00"><meta itemprop=dateModified content="2026-04-12T00:00:00+00:00"><meta itemprop=wordCount content="180"><meta name=referrer content="no-referrer-when-downgrade"><link rel=alternate type=application/rss+xml href=https://netw0rk.io/index.xml title=netw0rk.io><style>:root{--width:720px;--font-main:Verdana, sans-serif;--font-secondary:Verdana, sans-serif;--font-scale:1em;--background-color:#fff;--heading-color:#222;--text-color:#444;--link-color:#3273dc;--visited-color:#8b6fcb;--blockquote-color:#222}@media(prefers-color-scheme:dark){:root{--background-color:#01242e;--heading-color:#eee;--text-color:#ddd;--link-color:#8cc2dd;--visited-color:#8b6fcb;--blockquote-color:#ccc}}body{font-family:var(--font-secondary);font-size:var(--font-scale);margin:auto;padding:20px;max-width:var(--width);text-align:left;background-color:var(--background-color);word-wrap:break-word;overflow-wrap:break-word;line-height:1.5;color:var(--text-color)}h1,h2,h3,h4,h5,h6{font-family:var(--font-main);color:var(--heading-color)}a{color:var(--link-color);cursor:pointer;text-decoration:none}a:hover{text-decoration:underline}nav a{margin-right:8px}strong,b{color:var(--heading-color)}button{margin:0;cursor:pointer}time{font-family:monospace;font-style:normal;font-size:15px}main{line-height:1.6}table{width:100%}hr{border:0;border-top:1px dashed}img{max-width:100%}code{font-family:monospace;padding:2px;border-radius:3px}blockquote{border-left:1px solid #999;color:var(--blockquote-color);padding-left:20px;font-style:italic}footer{padding:25px 0;text-align:center}.title:hover{text-decoration:none}.title h1{font-size:1.5em}.inline{width:auto!important}.highlight,.code{border-radius:3px;margin-block-start:1em;margin-block-end:1em;overflow-x:auto}.highlight pre,.code pre{min-width:100%;width:max-content}ul.blog-posts{list-style-type:none;padding:unset}ul.blog-posts li{display:flex}ul.blog-posts li span{flex:0 0 130px}ul.blog-posts li a:visited{color:var(--visited-color)}</style></head><body><header><a href=/ class=title><h2>netw0rk.io</h2></a><nav><a href=/blog/>Blog</a></nav></header><main><h2 id=about-me>About Me</h2><p>I am Sufijen Bani, a Cybersecurity Professional and Software Engineer based in Berlin. I work on offensive security, secure software development, and the operational side of running production systems.</p><p>What I do:</p><ul><li>Penetration testing and red teaming against web apps, APIs, and internal infrastructure</li><li>Vulnerability research and exploit development (see CVEs below)</li><li>Threat modeling and security review across the SDLC: design, code, CI/CD, deployment</li><li>Defend against threats regarding AI and the new attack paths</li><li>Building backend services and tooling in Go, Typescript, PHP, and Python</li><li>Setting up secure infrastructure: Linux, containers, hardened CI/CD pipelines</li><li>Leading security and engineering teams, including reporting to C-level</li></ul><p>I am available for consulting and contract work. Get in touch if you need a penetration test, a second pair of eyes on architecture or code, or hands-on help shipping secure software.</p><h2 id=common-vulnerabilities-and-exposures-cve>Common Vulnerabilities and Exposures (CVE)</h2><ul><li>2014-10-27 <a href=/blog/phpmemcachedadmin-rce-cve-2014-8731/>CVE-2014-8731: PHPMemcachedAdmin Remote Code Execution</a></li><li>2020-05-14 <a href=https://spring.io/security/cve-2020-5427>CVE-2020-5427: Spring Cloud Config Server Path Traversal</a></li><li>2020-05-14 <a href=https://spring.io/security/cve-2020-5428>CVE-2020-5428: Spring Cloud Config Server Path Traversal</a></li><li>2022-04-06 <a href=https://git.sbani.net/sbani/CVE-2022-29221-PoC>CVE-2022-29221-PoC: Apache HTTP Server mod_lua Use-After-Free</a></li></ul><h2 id=code>Code</h2><p>You can find my public code at <a href=https://git.sbani.net/sbani>git.sbani.net/sbani</a>.</p></main><footer></footer></body></html>