Browse all posts or filter by tag
2025-12-28
A multi-layered reconnaissance challenge involving GitHub OSINT, nested subdomain enumeration, API discovery, and client-side authentication bypass to access a developer's unauthorized chatbot cont...
2025-11-21
A deep dive into the Wiz CTF challenge simulating the Midnight Blizzard attack - exploiting OAuth admin consent, dynamic group memberships, and guest user privileges to access Azure Blob Storage th...
2025-09-10
Exploiting network traffic capture, PostgreSQL command execution, and container misconfigurations to achieve a complete container escape and access the host filesystem.
2025-07-10
Exploiting Server-Side Request Forgery (SSRF) through Spring Boot Actuator to access AWS services, bypass data perimeter controls, and extract protected files using presigned URLs.
2025-01-30
Exploring how websites can identify visitors through browser characteristics, device information, and behavioral patterns. A deep dive into privacy implications.
2025-01-28
An analysis of current privacy technologies, browser implementations, and what users can do to protect their digital identity.
2025-01-25
Why less is more in web development. Exploring minimalist design principles and their impact on user experience and performance.