skip to content

Gaya KACI

cybersecurity student · web security researcher

Master’s student at Efrei Paris Panthéon-Assas Université. I work in web development and cybersecurity at Société Générale Assurance, where I research web security and build security tools.

/paris/fr

about

I build security tools and web software, backed by experience in network and systems administration.

At Société Générale Assurance, I research complex web targets, reverse engineer anti-bot systems, and study browser fingerprinting.

Outside work, I build small CLIs, browser tools, and AI projects. I work across Linux, macOS, and Windows, and usually read the source before the docs.

roleweb dev · cybersecurity
degreeM. cybersecurity, Efrei Paris Panthéon-Assas Université
locationParis, FR
langsfr · en

projects

selected open-source work · demos where available

contributions

1441 contributions in the last year · via github

Less
More

writing

7 entries · notes and write-ups

  • Fix Vivaldi sidebars staying open after switching windows

    An experimental local patch for stuck auto-hide sidebars in macOS Vivaldi 8.2.4133.52, with bundle checks, a backup, and restoration.
    · 3 minmacosvivaldijavascripttroubleshooting
  • Fix missing Gmail notifications on Android

    A practical checklist for restoring Gmail alerts on Android, including notification channels, sound settings, Gmail sync, and an ADB fix for inconsistent permissions.
    · 3 minandroidgmailnotificationsadbtroubleshooting
  • Unlock Brave Origin Without Paying

    The Android Origin gate verifies subscription credentials against a public key the server hands back, with no issuer pinning. A local policy path never redeems them, so a forged credential is enough.
    · 4 minbravevoprfreverse-engineeringandroidsecurity-research
  • Tuning Patchright for fingerprint-stats pages

    Why AmiUnique and WebRTC leak tests need a different approach than bot-detection demos, and how WebSkrap handles them with native Chromium flags and opt-in context metadata instead of JavaScript spoofing.
    · 5 minbrowser-automationstealthpatchrightchromiumwebrtc
  • Passing Bot Detection in Headless Chrome

    Making headless Chromium clear the same bot-detection suite as headed mode with a simulated screen and a masked user agent, no JavaScript spoofing.
    · 4 minbrowser-automationstealthplaywrightchromium
  • Teensy BadUSB reverse shell POC

    HID keyboard injection on a Teensy 3.2 chains into a fileless PowerShell reverse shell on Windows.
    · 4 minbadusbpowershellwindowsred-team
  • Skia Graphite compositing bug in Chromium on macOS

    A GPU rendering synchronization bug causing visual corruption on macOS, and how to fix it.
    · 4 minmacoschromiumgpuelectron

skills

filled: regular use · outlined: occasional use

security
burp suitewiresharknmapmetasploitsnortsuricatahydrajohn
dev
rustpythontypescriptreactnext.jscasmjavascripthtmlcssphp
cloud / devops
dockerbashkubernetesazureawspowershell
scraping / automation
playwrightcamoufoxhttpxseleniumcrawleepuppeteerscrapybeautifulsoup
ai / ml
openroutertensorflowpytorchscikit-learnhugging face
data
postgresqlmongodbmysqlfirebaseoracle
os
debianarchkalimacoswindowsandroidios

certifications

linked rows verify on credly

course badges

  • Networking Basics
  • Industrial Networking Essentials
  • Introduction to Cybersecurity
  • Introduction to IoT
  • Introduction to Modern AI
  • Digital Safety and Security Awareness
  • Cybersecurity Awareness Learner

contact

email works best