Internal Affairs 1 & 2
Virtual-host discovery, PHP source disclosure, and PHAR deserialization
Echoes of Runtime
Spring Boot Actuator, heap analysis, and credential leakage
DevSecOops - Linked Flaws - Rebirth
Mobile metadata, GitLab OSINT, Grafana SSRF, and Loki log analysis
Total Recall
Qdrant enumeration, model fingerprinting, and embedding inversion
archive
technical writings
Only actual writeups live here. Projects stay on the homepage where they belong.
01 THE LIBRARY
Secret left inside native app code
02 THE DATABASE
Firebase anonymous auth and exposed database path
03 THE VAULT
App Check debug token and trusted app identity
04 THE ENDPOINT
Native request signing and admin-only clearance
05 THE VAULT DOOR
JWT role bypass using alg:none
06 THE CLOUD
Debug webhook SSRF to IMDSv2 and S3