Hi, I'm Youssef Elsheikh
Bug bounty hunter and Android security researcher passionate about automation, tooling, and responsible disclosure.
About Me
I'm Youssef Elsheikh, known online as nem0x00 — a passionate bug bounty hunter, Android & web application security enthusiast, and creator of custom tools for automation and recon.
With recognized vulnerability reports acknowledged by major companies like Google, Unity, and the Estonian government, I focus on real-world impact, application logic flaws, and advanced recon techniques.
My strengths lie in analyzing JavaScript files, automating reconnaissance using Go, and digging deep into Android apps to uncover sensitive data, broken authentication flows, and overlooked misconfigurations.
Currently building BadGPT — a powerful bug bounty framework combining JS scanning, crawling, subdomain enumeration, and secret detection.
When I'm not reversing apps or scripting automation, I'm probably walking while listening to a cybersecurity podcast, brainstorming new fuzzing ideas, or helping fellow researchers.
Recognitions
PlayStation
2025
Acknowledged for reporting a security vulnerability in PlayStation's online services.
Unity
2025
Rewarded for identifying a security flaw in Unity's game engine.
HubSpot
2025
Recognized for discovering a vulnerability in HubSpot's marketing platform.
Linktree
2025
Acknowledged for identifying and reporting a security issue in Linktree's platform.
BiltRewards
2025
Recognized for finding and reporting a vulnerability in the Bilt Rewards platform.
Lime
2025
Acknowledged for discovering a security flaw in Lime's mobile application.
DailyPay_BBP
2025
Rewarded through DailyPay's bug bounty program for reporting critical vulnerabilities.
Estonia Gov
2025
Acknowledged by the Estonian government for reporting a security issue.
Skills & Expertise
💻 Programming & Automation
- Go (Golang)
- Bash scripting
- Java
- Kotlin
- JavaScript
- Git & GitHub Actions
🔐 Offensive Security
Android App Pentesting (Jadx, Frida, Apktool, Drozer, MobSF)
Web App Pentesting:
- XSS (All types)
- CSRF
- SSRF
- SQL Injection
- Command Injection
- CORS Misconfigurations
- JWT attacks
- OAuth Misuse
- SSTI, XXE, IDOR
- Race Conditions
Mobile App Vulnerability Focus:
- Insecure Data Storage
- WebView Misuse
- Insecure Deeplinks
- Token reuse
- Hardcoded secrets
- Root detection bypass
🛠 Tools & Frameworks
- Burp Suite (Pro)
- Ghidra
- Wireshark
- Nmap, SQLMap, ffuf
- Subfinder, Amass
- Custom-built tools
Featured Projects
Open-source tools built to enhance security research and bug bounty workflows.

BadGPT
AI-powered security testing tool that leverages GPT models to enhance bug bounty workflows, automate vulnerability discovery, and generate intelligent test cases.

Frida Android Scanner
Comprehensive Android security scanner built with Frida for dynamic analysis, runtime manipulation, and vulnerability detection in mobile applications.
Security Research & Writeups
Sharing knowledge through detailed vulnerability research and tool development insights.

From a Simple Client-Side Mistake to Full Read/Write Access of an Internal Support System
Discover how exposed client-side token generation with a hardcoded secret key led to complete compromise of an internal support system. A detailed analysis of a critical cryptographic flaw...
Read More
Frozen Fingers & Hot Bugs: How a Small Dork Turned Into Full Support Panel Access
A winter night of curiosity led to discovering unauthenticated access to a support panel with XSS vulnerabilities. See how dorks and fuzzing revealed critical security flaws...
Read More
Exploiting an Insecure Android Activity for Arbitrary File Theft and Account Takeover
Discover how an exported Android Activity with improper input validation led to sensitive file theft and full account compromise through WebView exploitation...
Read More
Unveiling Secrets: Masterful Hacks to Defeat Android SSL Pinning
Complete guide to bypassing SSL pinning on Android apps using Frida, Objection, Burp Suite, and HTTP Toolkit. Learn ethical hacking techniques for security testing...
Read More
Top Android Apps Security Flaws: What You Need to Know!
Deep dive into common Android security vulnerabilities through hands-on analysis of the Beetlebug application. Learn about hardcoded secrets, insecure data storage, SQL injection, and more...
Read MoreGet In Touch
Interested in collaboration, security research, or just want to connect? Feel free to reach out.
Contact Information
I'm always open to discussing security research, bug bounty collaboration, tool development, or sharing knowledge with the cybersecurity community.