Peeking into Attacker's Web Server
A new writeup is on the way. Check back soon.
Blogs
Clear, practical writeups on the vulnerabilities I find and the tools I use to find them, across web, cloud, and hardware security.
A custom script environment variable rendered with dangerouslySetInnerHTML turned a configuration value into stored XSS and a full account takeover in Lunary.

A portable multitool for pentesters and geeks in a toy like body, and the cool things you can actually do with it.
Privilege escalation and cross site scripting I found in the eScan Management Console during a VAPT engagement.
A rare cloud takeover where a forgotten CNAME record let me deploy my own app on another organization's domain.
More than 6000 instances exposed on Shodan, and a set of CSRF flaws hiding in the phone system nobody tests.
My first subdomain takeover writeup, where a script left running overnight handed me three claimable subdomains.
My very first writeup on SQL injection, and how I turned it into a command shell on a live target overnight.
A new writeup is on the way. Check back soon.
A new writeup is on the way. Check back soon.
Building in the open
Open source work where security testing meets automation.
An offensive auditor for Model Context Protocol servers. It detects tool poisoning, credential leaks, remote code execution vectors, server side request forgery, session hijacking, and supply chain weaknesses across stdio, HTTP, and SSE transports.
Explore on GitHubA field tested approach to finding dangling DNS records and reclaiming abandoned cloud services. I have used it to safely demonstrate takeovers across Shopify and AWS Elastic Beanstalk, then reported each one for remediation.
Read the writeups