تیم قرمز // محقق امنیت
Alireza Bolbolabadi

علیرضا
بلبل آبادی

شکستن چیزها برای قوی‌تر کردن آن‌ها...

محقق امنیت تیم قرمز با تخصص در امنیت برنامه‌های وب، تست API و امنیت LLM. شکارچی باگ و توسعه‌دهنده ابزارهای متن‌باز امنیتی.

19+
ستاره‌های گیت‌هاب
8
ابزارهای امنیتی
7+
سال فعالیت

آخرین مطالب وبلاگ

تحقیقات امنیتی، تحلیل آسیب‌پذیری و تکنیک‌های امنیت تهاجمی.

مشاهده همه مطالب

آخرین آسیب‌پذیری‌ها

آخرین آسیب‌پذیری‌های شناخته شده در سراسر جهان.

CVE-2025-1234 2026-06-15
CRITICAL CVSS: 9.8

Critical Remote Code Execution in Apache HTTP Server mod_proxy

A critical vulnerability in Apache HTTP Server mod_proxy allows unauthenticated remote attackers to execute arbitrary code via crafted HTTP requests. ...

CVE-2025-1235 2026-06-14
HIGH CVSS: 8.1

SQL Injection in WordPress Plugin WPForms

The WPForms plugin for WordPress is vulnerable to SQL Injection via the form_id parameter in versions before 1.8.9. This allows authenticated attacker...

CVE-2025-1237 2026-06-10
CRITICAL CVSS: 9.1

Authentication Bypass in Jenkins Core

Jenkins Core contains an authentication bypass vulnerability that allows unauthorized users to access administrative functions. Affects LTS versions p...

CVE-2025-1236 2026-06-10
HIGH CVSS: 7.2

Cross-Site Scripting in GitLab CE/EE

An XSS vulnerability in GitLab CE/EE allows attackers to inject malicious scripts via the markdown renderer. Affects versions 16.0 to 16.11.2.

CVE-2025-1238 2026-05-31
HIGH CVSS: 8.2

Buffer Overflow in OpenSSL TLS Handshake

A buffer overflow vulnerability in OpenSSL during TLS handshake processing can lead to denial of service or remote code execution. Affects OpenSSL 3.0...

مشاهده همه آسیب‌پذیری‌ها

آموزش‌ها

آموزش‌های گام‌به‌گام امنیت و محتوای آموزشی.

مشاهده همه آموزش‌ها

ابزارهای امنیتی

ابزارهای متن‌باز توسعه داده شده برای جامعه امنیت.

⚔️
★ 10

swagger2burp

Import Swagger/OpenAPI (Swagger 2.0 and OpenAPI 3) and generate example HTTP requests per operation, ready to send to Repeater.

Python
⚔️
★ 3

llm-security-checker

Comprehensive Security Assessment Tool for LLM Endpoints - 371 Attack Payloads, 100+ Prompt Injection Variants, 13 Security Tests, Parallel Scanning, Resume Capability

Python
⚔️
★ 2

unicode-decoder-burp

Burp Suite extension that automatically converts escaped Unicode sequences (like \u0627\u06cc...) into readable characters inside all Burp tools (Proxy, Repeater, Intruder, etc.).

Python
⚔️
★ 2

unicode-inline-decoder-burp

Burp Suite extension that intercepts the raw HTTP traffic (requests & responses), decodes any \uXXXX Unicode sequences, and then replaces the content before it reaches Burp’s UI.

Python
⚔️
★ 1

https-finder

HTTPS Finder is a lightweight multithreaded Python tool designed for internal reconnaissance. It scans a list of IPs or CIDRs using Nmap to detect open web-related ports and then runs HTTPX to identify live HTTP/HTTPS services, grab titles, status codes, and technologies.

Python
⚔️
★ 1

plugin-checker

Plugin Checker is a Python tool to enumerate WordPress plugins on target sites by checking for plugin `readme.txt` files and comparing detected versions with the latest versions from the WordPress Plugins API.

Python
مشاهده همه ابزارها

مهارت‌ها و تخصص

شایستگی‌های اصلی در امنیت تهاجمی و توسعه ابزار.

⚔️ Penetration Testing 95%
🌐 Web Application Security 95%
🐍 Python 95%
🛠️ Burp Suite 95%
💉 SQL Injection 95%
🔌 API Security Testing 92%
📜 XSS 92%
🎯 Red Team Operations 90%
🔍 Nmap 90%
🐛 Bug Bounty Hunting 88%
🕵️ OSINT 88%
🤖 LLM/AI Security 85%

آمار سریع

root@bolbolabadi:~
root@bolbolabadi:~$ whoami
Alireza Bolbolabadi - Red Team Security Researcher
root@bolbolabadi:~$ cat skills.txt
[+] Web Application Pentesting
[+] API Security Testing
[+] LLM/AI Security Assessment
[+] Bug Bounty Hunting
[+] Security Tool Development (Python)
[+] Burp Suite Extension Development
root@bolbolabadi:~$ ls tools/
swagger2burp/ llm-security-checker/ unicode-decoder-burp/
unicode-inline-decoder-burp/ https-finder/ plugin-checker/
root@bolbolabadi:~$ _