B.Sc/M.Sc Cybersecurity · Florence & Pisa

I build secure software.
Then I try to break it.

Full-stack web developer and cybersecurity researcher — from security-hardened, live e-commerce platforms to Android malware analysis. Based in Florence, working across Italy and Israel.

2026B.Sc. Computer Science
300hSecurity research — IMT Lucca
7+Shipped projects
4Languages spoken

Who I am

Security-minded.
Full-stack.

I'm Hosam A. Ghanima, a cybersecurity-focused Computer Science developer based in Florence, building custom websites and web applications for businesses across Italy and Israel.

I'm finishing my B.Sc. in Computer Science at the University of Florence (2022–2026) and starting an M.Sc. in Cybersecurity at the University of Pisa in September 2026. Alongside my studies I worked as a research intern at the IMT School for Advanced Studies Lucca, investigating Android malware obfuscation techniques under Prof. Gabriele Costa — research that fed directly into my thesis on APK malware detection.

That background shapes how I build: every site is fast, modern, and built with security in mind from the start — from database-level access policies to server-verified checkout logic — not bolted on afterward.

I work in English, Italian, Arabic, and Hebrew — so I can collaborate comfortably with clients across borders.

Education & research timeline

  1. 2022 – 2026
    B.Sc. Computer Science

    University of Florence

  2. Mar – Jun 2026
    Research Intern 300h

    IMT School for Advanced Studies Lucca — Android malware obfuscation research via ZIP header manipulation, supervised by Prof. Gabriele Costa

  3. From Sept 2026
    M.Sc. Cybersecurity

    University of Pisa

Real VAPT experience — command injection, XSS, and SQLi identified and documented on a live engagement.

  • English
  • Italiano
  • العربية
  • עברית

Tools & stack

  • Python
  • Java
  • C
  • SQL
  • PostgreSQL / Supabase
  • MySQL
  • Kali Linux
  • Burp Suite
  • Wireshark
  • Metasploit
  • Git
  • RISC-V Assembly

What I do

Comprehensive security & dev

Secure Web Development

Full-stack websites and web apps built security-first — from database access policies to hardened, server-verified checkout logic.

Learn more →

Penetration Testing

VAPT engagements identifying command injection, XSS, SQL injection, and other real-world vulnerabilities — documented end-to-end.

Learn more →

Malware Analysis

Android APK analysis and ZIP-header-based malware detection — research from my BSc thesis and a research internship at IMT Lucca.

Learn more →

Database Security

PostgreSQL/Supabase schema design with Row-Level Security policies and query optimisation — the real authorization boundary, not just UI checks.

Learn more →

Security Audits

Vulnerability assessments and hardening for existing sites and applications — input validation, auth practices, common attack surfaces.

Get an audit →

Security Consulting

Practical, jargon-free guidance on securing your stack — the fixes that actually matter, prioritised by real risk.

Talk to me →

Who I build for

Industries I serve

01

Business & Corporate

Professional sites that give small businesses and companies a credible presence and authority online.

02

Clinics & Wellness

Clean, trustworthy sites for clinics, studios, and practitioners — with appointment and contact forms built in.

03

Restaurants & Hospitality

Menus, reservations, and a vetrina that makes people want to book a table or a room.

04

E-commerce & Retail

Online shops built to sell — fast, secure, and easy for both you and your customers to use.

05

Booking & Web Apps

Custom platforms with accounts, dashboards, and databases — for businesses that need more than a brochure site.

06

Care & Maintenance

Hosting, updates, and security monitoring. You focus on your business; I keep the site fast, safe, and online.

Selected work

Featured Projects

A mix of client and academic work spanning full-stack development, databases, and offensive security — from a live e-commerce platform to Android malware research.

Full-Stack · Supabase / PostgreSQL

Secure E-Commerce Platform

A bilingual (Arabic/Hebrew) pet-shop storefront built end-to-end for a real client — guest checkout, an admin back office, and Row Level Security policies backing every table.

Finding

Checkout trusted the browser's local cart for both price and stock — nothing server-side re-verified either before an order was written, so a tampered price or a last-unit race could both go through.

Found by

Manual review of the checkout path, confirmed live: edited a cart's price in dev tools and submitted a real order at the tampered amount.

Fixed

Rewrote checkout around one atomic create_order() Postgres function that row-locks each item and re-reads the real price and stock server-side — the browser can no longer influence price or oversell stock.

Open live demo →
CREATE POLICY orders_insert
  ON orders FOR INSERT
  TO anon
  WITH CHECK (true);
premium-dog — live demo
0000 4A 41 4E 55 53 5F 41 50 4B
0009 50 4B 03 04 14 00 00 00
!! DEX magic before ZIP EOCD
parser_differential.py
def compare_lfh_cd(apk):
    for entry in apk.central_directory:
        lfh = read_local_header(entry.offset)
        if lfh.crc32 != entry.crc32:
            flag("CRC mismatch — possible Janus")
        if entry.offset == 0 and has_dex_magic(apk):
            flag("DEX prepended before ZIP")

Security Research · BSc Thesis

Android Malware Analysis

A ZIP-header-based detection and sanitization method for malicious APK files, built on research from a 300-hour internship at IMT School for Advanced Studies Lucca, supervised by Prof. Gabriele Costa. Detects Janus-style (CVE-2017-13156) parser-differential attacks by comparing Local File Header and Central Directory records.

View on GitHub →

Security · VAPT — UNIFI

Vulnerability Assessment Tool

Full vulnerability assessment of a Dockerized web app — command injection, XSS, SQL injection, a reverse shell, and database exposure, documented end-to-end.

View on GitHub →
CRITICAL  cmd injection  /api/ping
HIGH      reflected xss  /comment
INFO      db exposed     :5432
vapt_report.log
$ sqlmap -u target --batch
[+] injectable parameter: 'id'
[+] payload: UNION SELECT ...
[!] xss confirmed on /comment
[!] reverse shell via cmd injection

More projects

Ready to build something secure?

Whether it's a new website, a web app with a real database, or a security review of something that already exists — let's talk.

Get in touch →

Get in touch

Let's build something.

Have a project in mind, or checking real credentials before a hire? Both are welcome here — I usually reply within 24 hours.