Secure Web Development
Full-stack websites and web apps built security-first — from database access policies to hardened, server-verified checkout logic.
Learn more →Full-stack web developer and cybersecurity researcher — from security-hardened, live e-commerce platforms to Android malware analysis. Based in Florence, working across Italy and Israel.
Who I am
I'm Hosam A. Ghanima, a cybersecurity-focused Computer Science developer based in Florence, building custom websites and web applications for businesses across Italy and Israel.
I'm finishing my B.Sc. in Computer Science at the University of Florence (2022–2026) and starting an M.Sc. in Cybersecurity at the University of Pisa in September 2026. Alongside my studies I worked as a research intern at the IMT School for Advanced Studies Lucca, investigating Android malware obfuscation techniques under Prof. Gabriele Costa — research that fed directly into my thesis on APK malware detection.
That background shapes how I build: every site is fast, modern, and built with security in mind from the start — from database-level access policies to server-verified checkout logic — not bolted on afterward.
I work in English, Italian, Arabic, and Hebrew — so I can collaborate comfortably with clients across borders.
University of Florence
IMT School for Advanced Studies Lucca — Android malware obfuscation research via ZIP header manipulation, supervised by Prof. Gabriele Costa
University of Pisa
Real VAPT experience — command injection, XSS, and SQLi identified and documented on a live engagement.
What I do
Full-stack websites and web apps built security-first — from database access policies to hardened, server-verified checkout logic.
Learn more →VAPT engagements identifying command injection, XSS, SQL injection, and other real-world vulnerabilities — documented end-to-end.
Learn more →Android APK analysis and ZIP-header-based malware detection — research from my BSc thesis and a research internship at IMT Lucca.
Learn more →PostgreSQL/Supabase schema design with Row-Level Security policies and query optimisation — the real authorization boundary, not just UI checks.
Learn more →Vulnerability assessments and hardening for existing sites and applications — input validation, auth practices, common attack surfaces.
Get an audit →Practical, jargon-free guidance on securing your stack — the fixes that actually matter, prioritised by real risk.
Talk to me →Who I build for
01
Professional sites that give small businesses and companies a credible presence and authority online.
02
Clean, trustworthy sites for clinics, studios, and practitioners — with appointment and contact forms built in.
03
Menus, reservations, and a vetrina that makes people want to book a table or a room.
04
Online shops built to sell — fast, secure, and easy for both you and your customers to use.
05
Custom platforms with accounts, dashboards, and databases — for businesses that need more than a brochure site.
06
Hosting, updates, and security monitoring. You focus on your business; I keep the site fast, safe, and online.
Selected work
A mix of client and academic work spanning full-stack development, databases, and offensive security — from a live e-commerce platform to Android malware research.
Full-Stack · Supabase / PostgreSQL
A bilingual (Arabic/Hebrew) pet-shop storefront built end-to-end for a real client — guest checkout, an admin back office, and Row Level Security policies backing every table.
Checkout trusted the browser's local cart for both price and stock — nothing server-side re-verified either before an order was written, so a tampered price or a last-unit race could both go through.
Manual review of the checkout path, confirmed live: edited a cart's price in dev tools and submitted a real order at the tampered amount.
Rewrote checkout around one atomic create_order() Postgres function that row-locks each item and re-reads the real price and stock server-side — the browser can no longer influence price or oversell stock.
CREATE POLICY orders_insert ON orders FOR INSERT TO anon WITH CHECK (true);
0000 4A 41 4E 55 53 5F 41 50 4B 0009 50 4B 03 04 14 00 00 00 !! DEX magic before ZIP EOCD
def compare_lfh_cd(apk): for entry in apk.central_directory: lfh = read_local_header(entry.offset) if lfh.crc32 != entry.crc32: flag("CRC mismatch — possible Janus") if entry.offset == 0 and has_dex_magic(apk): flag("DEX prepended before ZIP")
Security Research · BSc Thesis
A ZIP-header-based detection and sanitization method for malicious APK files, built on research from a 300-hour internship at IMT School for Advanced Studies Lucca, supervised by Prof. Gabriele Costa. Detects Janus-style (CVE-2017-13156) parser-differential attacks by comparing Local File Header and Central Directory records.
View on GitHub →Security · VAPT — UNIFI
Full vulnerability assessment of a Dockerized web app — command injection, XSS, SQL injection, a reverse shell, and database exposure, documented end-to-end.
View on GitHub →CRITICAL cmd injection /api/ping HIGH reflected xss /comment INFO db exposed :5432
$ sqlmap -u target --batch [+] injectable parameter: 'id' [+] payload: UNION SELECT ... [!] xss confirmed on /comment [!] reverse shell via cmd injection
More projects
interface PricingStrategy { double calculate(Booking b); } class DiscountDecorator implements PricingStrategy { … }
Application · Java / OOP
A coach-ticketing prototype applying five design patterns — Strategy, Decorator, Composite, Observer, and Chain of Responsibility — for clean, extensible booking logic.
View on GitHub →CREATE INDEX idx_listing_price ON listings(city, price); CREATE TABLE agents ( id SERIAL PRIMARY KEY, …
Database · MySQL
A normalised relational schema for a real-estate platform, with complex queries and index optimisation for fast search across listings, agents, and bookings.
View on GitHub →typedef struct { int priority; char subject[64]; } Ticket; void enqueue(Ticket t) { … }
CLI · C
A command-line ticketing system with priority-queue scheduling and file-based persistence — no dependencies, just C.
View on GitHub →infix_to_postfix: lw a0, 0(sp) beq a0, t1, push_stack bgtu a1, a2, overflow_check
Systems · RISC-V Assembly
An infix-to-postfix parser with stack-based evaluation and overflow detection, written directly in RISC-V assembly.
View on GitHub →Get in touch
Have a project in mind, or checking real credentials before a hire? Both are welcome here — I usually reply within 24 hours.