Posts are loaded from the Jekyll _posts folder and styled with this site's retro terminal theme.
>>> BLOG / NOTES / RESEARCH <<<
Posts are loaded from the Jekyll _posts folder and styled with this site's retro terminal theme.
picoCTF 2026 · Reverse Engineering · Medium Educational walkthrough documenting the analysis process used on bypassme.bin.
Read Writeup
Cracking the 2D Perceptron: My “Aha!” Moment in Cylab Security Academy
Read Writeup
A university’s online registration portal asks students to upload their ID cards for verification. The developer put some filters in place to ensur...
Read Writeup
When we accessed the website, we found this: It appears to be a normal chess game. Even though I don’t know much about how to play this game, I’m g...
Read Writeup
I made a cool website where you can announce whatever you want! I read about input sanitization, so now I remove any kind of characters that could ...
Read Writeup
Check the admin scratchpad! We can’t log in as admin, so let’s log in as Jose. Now, let’s use Burp Suite for this. At the end of the website, it sh...
Read Writeup
I made a cool website where you can announce whatever you want! Try it out!I heard templating is a cool and modular way to build web apps! If we ty...
Read Writeup
Bookstore â–▃▅ MEDIUM Objective: understand how a vulnerable API can be exploited Web Exploitation 🔗 Start Challenge → Part 1 I accessed ...
Read Writeup
Injectics â–▃▅ MEDIUM Objective: Use your injection skills to take control of a web app. Web Exploitation 🔗 Start Challenge → Part 1 I ac...
Read Writeup
As a Forensics Lab Analyst, you analyse the artefacts from crime scenes. Occasionally, the law enforcement agency you work for receives “intelligen...
Read Writeup
This blog documents my hands-on investigations using Splunk. I walk through real-world challenges step by step, explaining my thought process, sear...
Read Writeup
Bookstore â–▃▅ MEDIUM Objective: understand how a vulnerable API can be exploited Web Exploitation 🔗 Start Challenge → Part 1 I accessed ...
Read Writeup
Injectics â–▃▅ MEDIUM Objective: Use your injection skills to take control of a web app. Web Exploitation 🔗 Start Challenge → Part 1 I ac...
Read Writeup
picoCTF 2026 · Reverse Engineering · Medium Educational walkthrough documenting the analysis process used on bypassme.bin.
Read Writeup
As a Forensics Lab Analyst, you analyse the artefacts from crime scenes. Occasionally, the law enforcement agency you work for receives “intelligen...
Read Writeup
This blog documents my hands-on investigations using Splunk. I walk through real-world challenges step by step, explaining my thought process, sear...
Read Writeup
We will explore the different ways to protect an Ubuntu Server. Disabling Root Access You can do this through several methods: Disabling the root l...
Read Writeup
This server, SUBCA01, is the “worker bee.” It will stay online, join the domain, and issue certificates to every user and computer in my bank. This...
Read Writeup
For my latest home lab project, I am building a Two-Tier Public Key Infrastructure (PKI) to simulate a high-security banking environment. Today, I ...
Read Writeup
A university’s online registration portal asks students to upload their ID cards for verification. The developer put some filters in place to ensur...
Read Writeup
When we accessed the website, we found this: It appears to be a normal chess game. Even though I don’t know much about how to play this game, I’m g...
Read Writeup
I made a cool website where you can announce whatever you want! I read about input sanitization, so now I remove any kind of characters that could ...
Read Writeup
Check the admin scratchpad! We can’t log in as admin, so let’s log in as Jose. Now, let’s use Burp Suite for this. At the end of the website, it sh...
Read Writeup
I made a cool website where you can announce whatever you want! Try it out!I heard templating is a cool and modular way to build web apps! If we ty...
Read Writeup
Bookstore â–▃▅ MEDIUM Objective: understand how a vulnerable API can be exploited Web Exploitation 🔗 Start Challenge → Part 1 I accessed ...
Read Writeup
Injectics â–▃▅ MEDIUM Objective: Use your injection skills to take control of a web app. Web Exploitation 🔗 Start Challenge → Part 1 I ac...
Read Writeup
picoCTF 2026 · Reverse Engineering · Medium Educational walkthrough documenting the analysis process used on bypassme.bin.
Read Writeup
A university’s online registration portal asks students to upload their ID cards for verification. The developer put some filters in place to ensur...
Read Writeup
When we accessed the website, we found this: It appears to be a normal chess game. Even though I don’t know much about how to play this game, I’m g...
Read Writeup
I made a cool website where you can announce whatever you want! I read about input sanitization, so now I remove any kind of characters that could ...
Read Writeup
Check the admin scratchpad! We can’t log in as admin, so let’s log in as Jose. Now, let’s use Burp Suite for this. At the end of the website, it sh...
Read Writeup
I made a cool website where you can announce whatever you want! Try it out!I heard templating is a cool and modular way to build web apps! If we ty...
Read Writeup
As a Forensics Lab Analyst, you analyse the artefacts from crime scenes. Occasionally, the law enforcement agency you work for receives “intelligen...
Read Writeup
This blog documents my hands-on investigations using Splunk. I walk through real-world challenges step by step, explaining my thought process, sear...
Read Writeup
We will explore the different ways to protect an Ubuntu Server. Disabling Root Access You can do this through several methods: Disabling the root l...
Read Writeup
This server, SUBCA01, is the “worker bee.” It will stay online, join the domain, and issue certificates to every user and computer in my bank. This...
Read Writeup
For my latest home lab project, I am building a Two-Tier Public Key Infrastructure (PKI) to simulate a high-security banking environment. Today, I ...
Read Writeup
One of the Desktops in the research lab at Organization X is suspected to have been accessed by someone unauthorized. Although they generally have ...
Read Writeup
Developers should never trust user input. Even when you think you’ve sanitized everything and even when you’re using the familiar ? placeholder in ...
Read Writeup
This post begins a short series about authentication mistakes I often see in Node.js/Express applications. We’ll look at a real-but-safe example wh...
Read Writeup
You’ve definitely run msfvenom, uploaded the payload, and watched it get nuked instantly by Windows Defender. It’s frustrating. It makes you th...
Read Writeup
In this guide, I’m breaking down how to “live off the land.” We’re talking about taking standard commands and turning them into tunnels. Whethe...
Read Writeup
Cracking the 2D Perceptron: My “Aha!” Moment in Cylab Security Academy
Read Writeup
Cracking the 2D Perceptron: My “Aha!” Moment in Cylab Security Academy
Read Writeup
Cracking the 2D Perceptron: My “Aha!” Moment in Cylab Security Academy
Read Writeup
picoCTF 2026 · Reverse Engineering · Medium Educational walkthrough documenting the analysis process used on bypassme.bin.
Read Writeup