Josias Fabián
Penetration Tester · Web · API · Mobile · Cloud · Network
Experience
View all2025 - Present
Thoropass
Penetration Tester
I conduct end-to-end penetration testing engagements across a wide range of targets including web applications, APIs, mobile apps (iOS & Android), internal networks (Windows & Linux), and cloud environments (AWS, Azure, GCP). I deliver detailed technical and executive-level reports with clear remediation guidance, working closely with clients throughout scoping, execution, and remediation validation.
2024 - 2025
Cybersecurity Blue Team & Red Team
Penetration Tester
I work as a Penetration Tester, conducting comprehensive offensive security assessments across cloud infrastructures, web platforms, mobile applications, and internal networks. My role involves simulating real-world cyberattacks to identify and exploit vulnerabilities before malicious actors can. I specialize in Azure security, where I uncover misconfigurations and abuse identity mechanisms to demonstrate risk impact. I also develop custom payloads tailored to specific environments and automate reconnaissance, exploitation, and post-exploitation workflows to maximize efficiency. My findings are documented in detailed technical reports and high-level executive summaries, providing clear remediation guidance and strategic risk mitigation insights for stakeholders.
2023 - 2024
Grey Matter Technologies / Hotel W&P Santo Domingo
Infrastructure Manager - Outsourced to Hotel W&P
I served as the Infrastructure Manager, where I led the end-to-end design, deployment, and lifecycle management of secure, high-performance IT systems across both on-premises and cloud environments. My responsibilities included architecting resilient network and server infrastructures, implementing robust cybersecurity controls, and optimizing system performance for critical business operations. I ensured high availability and business continuity through strategic backup, monitoring, and disaster recovery solutions. Additionally, I directed cross-functional teams in delivering infrastructure upgrades, enforced compliance with industry security standards, and continuously evaluated emerging technologies to enhance operational efficiency and scalability.
Latest write-ups
View allMay 26, 2025
Compromising an Azure Tenant via XXE OOB and web.config Exfiltration
An exposed API documentation directory, an out-of-band XXE, and Azure App Service path mappings that together exposed a corporate mailbox used for password resets.
2025
Authorization Code Interception via Open Redirect in an AWS Cognito OAuth Flow
An unvalidated post-login redirect plus a public Cognito app client combined into an account takeover that required no phishing page and no victim password.
2025
From Zero to Admin: Account Takeover via GraphQL Enumeration and Authorization Bypass
A chain of GraphQL introspection, a leaked OTP, and broken function-level authorization that led to full administrative account takeover from an unauthenticated position.