5 الالتزامات

المؤلف SHA1 الرسالة التاريخ
ecea5ad1a4 docs: add reverse engineering report for Ghaymah CLI v2 binary 2026-08-23 19:30:56 +03:00
21e1f1ea51 feat: implement Ghaymah CLI Pre-Deployment Scanner and add associated audit and integration documentation 2026-08-23 18:39:08 +03:00
e823358715 docs: add binary audit and reverse engineering reports with supporting screenshots and fuzzing scripts 2026-08-23 17:42:15 +03:00
e635566bc5 feat: add security audit automation scripts and detailed vulnerability documentation 2026-08-20 20:13:14 +03:00
a7a479141b 🛡️ feat: Ghaymah CLI v2 — Security & QA Audit Repository
Comprehensive security audit of the Ghaymah CLI v2 and web platform.

Findings:
  - [CRITICAL] T1552: Dockerfile & .env Credential Leakage
  - [CRITICAL] OWASP A07: Missing OTP & Unverified Password Change
  - [HIGH]     T1539: Session Token Revocation Bypass
  - [MED/HIGH] CWE-400: Configuration Poisoning DoS (Pipeline Hang)

Includes:
  - 8 Proof-of-Concept applications (PoC_Apps/)
  - Visual evidence & screenshots (Assets/Screenshots/)
  - Full PDF audit report (Reports/)
  - Mermaid.js attack flow diagrams in README

Auditor: Ziad Mahmoud Ahmed Abdelgwad — Cybersecurity Specialist
2026-08-19 17:59:26 +00:00