Security researcher • CTF enthusiast • Pentest student
Breaking things, learning, and sharing writeups on penetration testing, AD security, CTF challenges, and red teaming.
Multi-step exploitation chain: LFR → JWT forgery → SSRF → SQLi → RCE
From Active Directory to bug bounties — my CWES certification journey
SSRF bypass using redirect rebinding to access internal endpoints
SQL injection, LFI, and PHP filter chain to gain RCE
Simple command injection in a ping utility
SQL injection on a banking application