Long-form
6 entries
2 categories
// 02 — Recent writing
Field notes & writeups.
CVE disclosures, research notes, and engagement-grade writeups — published when they're cleared for release.
// mobile-pentest Mobile Pentest
iOS & Android pentesting tradecraft — Frida hooking, jailbreak/root-detection bypass, SSL pinning, runtime tampering.
// web-exploitation Web Exploitation
CVE disclosures and writeups against modern web targets — XSS, SQLi, SSRF, SSTI, broken auth.
№ 10
2026 · 04 · 28
Server-Side Template Injection — from leak to RCE across five engines
Read →
№ 11
2026 · 04 · 22
SSRF against cloud metadata in 2026 — IMDSv2, parser confusion, and DNS rebinding
Read →
№ 01
2024 · 09 · 15
CVE-2024-46638 — Stored XSS in HelpDeskZ v2.0.2
Read →
№ 02
2024 · 09 · 01
CVE-2024-44851 — Stored XSS in Perfex CRM File Sharing module
Read →