Computer Science · Information Security · 5th year · Technical University Graz

Teodor Zlatar

I break things to understand them — specializing in binary exploitation, mobile security, and penetration testing.

open to: junior penetration testing, mobile application security, security engineering, and security research roles

binary exploitation active directory testing linux server testing web application testing mobile security cryptography security engineering trust systems

about

Who I am

Teodor Zlatar

I'm Teodor Zlatar, a fifth-year Information Security student at Technical University Graz, expected to graduate in February 2028. My focus sits at the intersection of low-level systems and real-world attack surface — understanding not just that something is vulnerable, but precisely why and how.

I've conducted hands-on penetration tests against Active Directory forests and Linux servers, performed Android application security analysis including MITM interception and APK reverse engineering, and solved web application security challenges spanning SQL injection, path traversal, JWT attacks, and cryptographic weaknesses.

I'm continuously pushing deeper — currently focused on binary exploitation, with the longer-term goal of diving into Android and iOS internals to understand mobile platform security at a deeper level. When I'm not at a terminal, I'm on the tennis court. I find the same deliberate practice mindset applies to both.

I also care about the defensive side of security: threat modeling, secure application design, and building development processes that reduce vulnerabilities before code reaches production.

languages

🇭🇷 Croatian native
🇬🇧 English fluent
🇩🇪 German A2

skills

Technical Skills

Exploitation & Reverse Engineering

Binary Exploitation ROP Chains GDB / pwndbg Ghidra pwntools

Active Directory Testing

Kerberoasting ADCS BloodHound Impacket Privilege Escalation Nmap / NetExec Golden Tickets / DCSync MSSQL

Linux Server Security

Linux Privilege Escalation SUID / SGID Abuse sudo Misconfiguration Reverse Shells Hashcat / John LinPEAS / pspy

Web Application Security

JWT Attacks SQL Injection XSS SSTI Auth Bypass Path Traversal File Upload Attacks Remote Code Execution AUTH / TOTP Bypass API Testing

Android Security

APK Reverse Engineering Static / Dynamic Analysis Mobile Traffic Interception MITM Testing APK Repackaging adb apktool Burp Suite jadx / jadx-gui Android Studio

Digital Identity & Trust Systems

Threat Modeling Secure Application Design Secure SDLC ID Austria + eIDAS Web PKI Software & Code Transparency

Cryptography

Symmetric Encryption (AES-GCM) Asymmetric Encryption (RSA, ECC) Hashing (SHA-3, MD5) Key Exchange (DH) TLS Post-Quantum Crypto

Programming Languages

C / C++ Python x86 Assembly Bash HTML/CSS/JS + SQL PHP

currently

What I'm Working On

Active Practice

Binary Exploitation

Working through pwn.college's binary exploitation track — heap corruption, tcache poisoning, ROP chain construction, and bypassing modern mitigations like PIE, ASLR, and stack canaries.

Planned Next

Android Internals

Planning a deeper dive into the Android platform from a security perspective — ART runtime internals, Binder IPC, and native library analysis to understand what actually needs protecting.

Planned Next

iOS Internals

Intending to go beyond app-layer security into XNU kernel internals, Mach-O parsing, and sandbox architecture — understanding the platform deeply enough to reason about its defenses.

self-study

pwn.collegepwn.college · Binary exploitation modules (active)
PortSwigger Web Security Academyportswigger.net · Web application security labs (active)
Algorithms Specializationcoursera.org · Stanford University · Coursera · Certificate earned
ML Foundationscodebasics.io · foundational ML/data science workflow, model training, and evaluation

security-work

Selected Security Work

Pentesting Lab — Linux Server

TU Graz · 2026

Full compromise of a Linux web server from unauthenticated access to root. Found 5 vulnerabilities including SSTI, exposed .git repo, SUID misconfiguration, and Ansible sudo abuse.

SSTI privesc SUID abuse Ansible git-dumper

Pentesting Lab — Active Directory

TU Graz · 2026

Full forest compromise of AD environment. 22 vulnerabilities found — including ADCS ESC8, Golden Ticket forgery, Kerberoasting, AS-REP roasting, and DLL hijacking.

ADCS ESC8 Golden Ticket Kerberoasting BloodHound PrintSpoofer

Mobile Security Hacklets — reyammer.io

TU Graz · 2026 · challs.reyammer.io ↗

Solved Android security challenges across app development, reversing, and exploitation categories — including DEX class loading, native library reversing with Ghidra, PIN cracking, and calling app components that were implicitly exported through intent filters.

APK reversing Ghidra jadx dynamic code loading Intent exploitation

SEAD Web Security Challenges

TU Graz · 2026

Solved 9 web security challenges including JWT algorithm confusion, cookie forgery, SQL injection with WAF bypass, path traversal via Unicode normalization, file upload RCE, and TOTP brute force.

JWT attacks SQL injection WAF bypass file upload RCE side-channel timing

Android App Analysis — Mobile Security

TU Graz · 2026

Intercepted and analysed HTTPS traffic from 3 real Android apps using Burp Suite, APK patching, and static analysis. Cross-referenced findings with Google Play Data Safety claims.

MITM APK patching apktool Burp Suite network sec config

Due to academic and course policies, full reports are confidential — but I'm happy to discuss methodologies, tools used, and lessons learned. Feel free to reach out if you have questions or want to talk through any of these.


projects

Projects

Alongside security-focused work, I keep several software and machine learning projects here to show broader engineering ability, data handling, and model-building fundamentals.

dino-duel

Capstone project at Harding University — a full Battle Sheep board game built in the Godot engine with local, LAN multiplayer, and AI opponents at multiple difficulty levels. I led game core development and co-led AI, implementing Monte Carlo Tree Search with parallelisation for the strongest difficulty.

GDScript Godot 4 MCTS AI UDP Networking
↗ GitHub

ultimate-tictactoe

AI opponent for Ultimate Tic Tac Toe built as part of an Artificial Intelligence course. Uses Minimax with Alpha-Beta Pruning and time-limited recursion for real-time intelligent play across a 9×9 meta-board.

Python Minimax Alpha-Beta Pruning
↗ GitHub

real-estate-price-prediction

Machine learning model for real estate price prediction. Built as part of an end-to-end ML course covering data cleaning, feature engineering, model training, and evaluation.

Python Jupyter scikit-learn
↗ GitHub

sport-person-image-classifier

Image classification model that identifies athletes from photos. Explores CNN architectures and transfer learning as part of a computer vision module.

Python Jupyter OpenCV sklearn
↗ GitHub

potato-disease-classifier

Deep learning model trained to detect potato plant diseases from leaf images. Applied data augmentation and CNN training for agricultural computer vision use cases.

Python Jupyter TensorFlow
↗ GitHub

More on github.com/tzlatar



contact

Get in Touch

Whether you have a question about my research, want to discuss a challenge I've worked on, need help understanding a security concept, or are interested in working together — I'm happy to hear from you.

I can't share confidential course reports, but I'm always glad to talk through methodology, tools, or findings. No question is too basic — feel free to reach out.

I typically respond within a day or two.

or email directly → zlatar.teodor1@gmail.com