Dev Lahrani
Breaking, building, and documenting. Vulnerability research, applied cryptographic protocol engineering, and threat intelligence.
Featured — Veli Chat
Veli Chat — E2EE, serverless, ephemeral terminal chat over Tor
v0.4.2 • live… ↻ downloads… ↻ stars… MIT
Two-party, end-to-end encrypted, serverless terminal chat that leaves nothing on disk. Every session generates an ephemeral X3DH bundle + Tor v3 onion, exchanges a single invite code out-of-band, completes a Double Ratchet handshake, then speaks XChaCha20-Poly1305 over padded 6-bucket frames. Keys, ratchet state and history live in RAM only and are wiped on /quit.
npx veilchat — or — npm i -g veilchat && veil
gen X3DH bundle + onion → share one invite code OOB → dial .onion via Tor → X3DH → Double Ratchet → chat → /quit wipes all state. Verify with /whois safety numbers (4×4 grid) aloud.
Technical Domains & Skillset
Full Bio & Journey →Latest Security Write-ups
All Write-ups (3) →Ghost Track — BreachLab: Fundamentals to Graduation (0 → 22) Complete Walkthrough
BreachLab Ghost Track end-to-end — 22 Linux wargame levels from hidden files, permissions and grep to env leaks, SUID, cron, git history and final shard reassembly. Every command, password and defensive lesson from Fundamentals through Graduation, reproduced from a full playthrough at 204.168.229.209:2222.
Reconnaissance & OSINT: mapping a target before touching it
How internet-wide scanners work, the legal boundary in India, and why opting out of Shodan doesn't actually protect anything.
NotPetya: how a leaked NSA exploit became a nation-state weapon
The 2017 attack chain broken down — supply-chain entry via M.E.Doc, Mimikatz credential theft, EternalBlue — and why it's the canonical CTI case study.
Internship Objective & Contact
Seeking Security Internships for 2026 in Application Security, Penetration Testing, or Applied Cryptography.