0% found this document useful (0 votes)
101 views1 page

Cybersecurity Achievements of Sujal Machhale

Sujal Machhale is a B.Tech Aerospace Engineering student at IIT Bombay with notable achievements in competitive exams and cybersecurity competitions. He has developed multiple security-focused projects, including a Website Security Testing Suite and an E-Commerce website, while also completing a professional certificate in Cybersecurity from IBM. His technical skills encompass various programming languages and tools related to web exploitation and security analysis.

Uploaded by

sujalmachhale704
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
101 views1 page

Cybersecurity Achievements of Sujal Machhale

Sujal Machhale is a B.Tech Aerospace Engineering student at IIT Bombay with notable achievements in competitive exams and cybersecurity competitions. He has developed multiple security-focused projects, including a Website Security Testing Suite and an E-Commerce website, while also completing a professional certificate in Cybersecurity from IBM. His technical skills encompass various programming languages and tools related to web exploitation and security analysis.

Uploaded by

sujalmachhale704
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Sujal Machhale 22B0001

Aerospace Engineering [Link]


Indian Institute of Technology Bombay Male
GitHub

ACHIEVEMENTS
• Ranked 18,052 out of 0.25 Million Candidates in JEE Advanced . [2022]
• Ranked 48,988 out of 1.02 Million Candidates in JEE Mains. [2022]
• Achieved a 91.6 Percentage score in the CBSE Class X Examination. [2020]
• Ranked 346 out of 12,000 participants globally in Cyber Apocalypse 2024, organized by HackTheBox.[2024]
• Achieved a rank of 382 out of 10,000+ participants globally in the picoCTF 2024 competition. [2024]
• Ranked 12,577 on the Hall of Fame for Web Exploitation on PortSwigger. [2024]
• Identified and reported Incorrect Default Permissions on Netflix during a successful Bug Bounty. [2024]

KEY PROJECTS
Website Security Testing Suite [July’24 - Aug’24]
Self - Project | Ongoing
• Developed a comprehensive Flask application for security testing, including SQL and XSS injection detection.
• Added features for Nmap scanning and subdomain discovery to enhance security analysis.
• Implemented detailed logging for SQL and XSS vulnerabilities, with results saved in output files.
• Designed and integrated RESTful API endpoints for automated security testing and results management.

Website Security | Course Project [Jan’24 - Apr’24]


Project Guide: Prof. Veerendrababu Vakkapatla, Department of Computer Science Engineering, IIT Bombay
• Implemented a transparent SSL-proxy server to intercept encrypted traffic between browser and web server.
• Developed and mitigated XSS and CSRF attacks on a custom Website using Apache2 and MySQL.
• Configured single sign-on authentication and client-side digital certificates for web application access.

E-Commerce Website [Feb’24 - Present]


Self - Project | Ongoing
• Implementing secure authentication using JavaScript, and MySQL for e-commerce login and sign-up.
• Developing dynamic home page displaying SQL-based product inventory with JavaScript for improved browsing.
• Engineering checkout page for users to review, input shipping/payment details, and securely process orders,
showcasing front-end and back-end development skills.
COURSES UNDERTAKEN
IBM CyberSecurity Analyst | Professional Certificate [Dec’23 - Jan’24]
Course By : IBM Company ,Coursera
• Experienced in cybersecurity practices including breach response, threat intelligence, network security, and
compliance frameworks. Completed IBM Cybersecurity Analyst Assessment. Proficient in penetration testing,
incident response, and forensics
TECHNICAL SKILLS
• Programming Languages: Python, C++, C, SQL, JavaScript, x86 Assembly, GoLang, Bash.
• Software: Burp Suit, WireShark, ZAP, Ghidra, Cutter, NMAP, AMASS, Hashcat, JohnTheRipper, sqlmap etc .
• Operating System: Windows, Linux.
• Web Exploitation: SQL Injection, Cross Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Remote
Command Execution, JWT Attacks, Web LLM, GraphQL Vulnerability, File Path Traversal, Access Control Test-
ing, Authentication Testing, Business Logic Vulnerability, Information Disclosure Vulnerability, File Upload
Vulnerability, Race Condition Vulnerability, NoSQL Injection, API Testing.

EXTRA-CURRICULAR ACTIVITIES
• Achieved a PicoGym Score of over 15,000+ on the picoCTF platform. [2024]
• Completed 40% of the Web Application Vulnerability Labs on PortSwigger Academy. [2024]
• Secured the 6th position in the TyroCTF competition organized by CSec at IITB. [2023]
• Ranked 87,588 out of 1,000,000 participants globally for Python Programming on HackerRank. [2024]
• Successfully finished the Advent of Cyber 2023 program organized by TryHackMe. [2023]
• Participated in a Capture The Flags Event organized by IITB Trust Lab with over 500 participants. [2023]

Common questions

Powered by AI

Sujal Machhale has demonstrated a comprehensive understanding of web-based vulnerabilities through his work on projects and completion of various labs and competitions. His projects involved implementing security measures against vulnerabilities such as XSS and CSRF attacks and developing robust authentication systems . His thorough exploration of web vulnerabilities through platforms like PortSwigger Academy, where he completed significant portions of the Web Application Vulnerability Labs, also showcases his methodical study and practical application of defenses against web-based threats . These experiences underscore his in-depth knowledge and active engagement with web exploitation scenarios.

Sujal Machhale's extracurricular activities significantly enhance his technical skills in cybersecurity by providing practical, competitive challenges that extend beyond the classroom. His participation in CTF events like TyroCTF, where he secured a high ranking, and activities on platforms like PortSwigger Academy, where he completed 40% of the labs, offer practical testing grounds for his skills in web vulnerabilities and exploits . Completing events like the Advent of Cyber program organized by TryHackMe also provided intensive real-world scenarios to apply his cybersecurity knowledge .

Sujal Machhale's achievements in diverse competitions significantly enhance his professional profile by validating his technical skills and elevating his reputation within the cybersecurity community. High rankings in competitive events like Cyber Apocalypse 2024 and TyroCTF reflect his proficiency and competitiveness, highlighting his capability to solve complex cybersecurity challenges under pressure . These accomplishments demonstrate not just depth in technical expertise but also a commitment to continuous learning and excellence, attributes that are highly valued in the professional sphere.

Sujal Machhale integrates security measures into his web development projects by implementing robust authentication processes and actively mitigating potential attacks. For instance, in his E-Commerce Website project, Sujal is developing secure authentication mechanisms using JavaScript and MySQL to ensure safe user login and signup processes . Moreover, his emphasis on secure data handling during the checkout process demonstrates a careful consideration of web security best practices. In his course project, he also developed and mitigated XSS and CSRF attacks, adding an additional layer of protection against common web vulnerabilities .

Sujal Machhale's expertise in cybersecurity is reflected in his proficiency with a broad array of programming languages and tools. He is adept in languages such as Python, C++, C, SQL, JavaScript, and x86 Assembly, which are essential for coding, scripting, and exploiting vulnerabilities . His experience with cybersecurity tools like Burp Suite, Wireshark, ZAP, and NMAP highlights his practical skill in network scanning, penetration testing, and vulnerability analysis . Additionally, his familiarity with operating systems like Windows and Linux further enhances his capability to navigate diverse computing environments essential for cybersecurity tasks.

Sujal Machhale's educational background highlights significant achievements in cybersecurity through both formal education and competitive participation. He has completed the IBM CyberSecurity Analyst Professional Certificate, which emphasizes practical skills such as breach response, threat intelligence, and penetration testing . His active participation in cybersecurity competitions like the Cyber Apocalypse 2024 and the picoCTF 2024, where he achieved top global rankings, underlines his practical expertise and deep understanding of the field .

Practical project experience is a critical component of Sujal Machhale's profile, demonstrating his ability to apply theoretical knowledge to real-world problems. His development of a Website Security Testing Suite showcases his skills in building applications for security testing, incorporating tools like Flask, SQL, and XSS injection detection, and implementing Nmap scanning for enhanced analysis . His course project involved implementing a transparent SSL-proxy server to intercept encrypted web traffic, which required a detailed understanding of cybersecurity protocols . These projects reflect his hands-on approach and competency in cybersecurity.

Sujal Machhale’s high rankings in global cybersecurity competitions such as Cyber Apocalypse 2024 and picoCTF 2024 are significant as they indicate a mastery of complex problem-solving and adaptability in high-pressure environments . These achievements demonstrate his ability to apply theoretical knowledge in practical scenarios, working through real-time cybersecurity challenges that require innovative thinking and technical acumen. Moreover, consistently performing well against thousands of participants globally showcases his dedication and understanding of contemporary cybersecurity threats and solutions .

Sujal Machhale's projects reflect his ability to integrate knowledge from multiple areas of expertise by combining programming, cybersecurity, and web development skills. For instance, his Website Security Testing Suite involves using Flask (software development) alongside SQL and XSS injection detection (cybersecurity). His course project further illustrates this integration by addressing web vulnerabilities within an SSL-proxy server environment, requiring a deep understanding of networking and security protocols. Such interdisciplinary approaches showcase his capability in synthesizing diverse skillsets to address complex technological issues.

Sujal Machhale's contributions to cybersecurity are marked by his innovative projects and high performance in competitions. His creation of a Website Security Testing Suite underscores a proactive stance in developing tools aimed at identifying and mitigating vulnerabilities . His success in competitions like picoCTF and Cyber Apocalypse exemplifies his skill in addressing security challenges, influencing the broader cybersecurity community by setting high standards in problem-solving and technical excellence . These contributions reflect both his individual capabilities and his potential to advance practices in the cybersecurity domain.

You might also like