# >_ majix.site - [Resume - Max Randhahn, Web Penetration Tester](https://maajix.github.io/resume/) ## Posts - [When the Lights Go Out: YekCity](https://maajix.github.io/posts/yekcity/) - [Catching the users session](https://maajix.github.io/posts/catching-the-user-session/) - [Account Takeover via flawed reset mechanism](https://maajix.github.io/posts/ato-via-flawed-password-reset/) - [Inside Our Car Hacking Demonstrator](https://maajix.github.io/posts/demonstrator/v1/) - [CORS Misconfiguration to Account Takeover](https://maajix.github.io/posts/cors-to-ato/) - [Introduction to Cache Poisoning Attacks](https://maajix.github.io/posts/intro-to-cache-poisoning/) - [Reflected XSS to Account Takeover](https://maajix.github.io/posts/reflected-xss-to-ato/) - [Introduction to NoSQL Injection Attacks](https://maajix.github.io/posts/intro-to-nosql/) - [Bluetooth Low Energy Hacking 101](https://maajix.github.io/posts/ble/) ## Ctfs - [Securinets CTF 2025 Writeup: SQL Injection, SSRF and IDOR Chain](https://maajix.github.io/ctfs/securinets/) - [CrewCTF 2025 Writeup: Bypassing a Strict CSP in Love Notes](https://maajix.github.io/ctfs/crewctf-2025/) - [FortID CTF 2025 Writeup: Document Upload IDOR via target_user](https://maajix.github.io/ctfs/fortid/) - [Nullcon CTF 2025 Writeup: Password Oracle Brute Force and Source Disclosure](https://maajix.github.io/ctfs/nullcon-2025/) - [TFCCTF 2025 Writeup: ZIP Symlink File Read and DOM Clobbering](https://maajix.github.io/ctfs/tfcctf-2025/) - [HTB Cyber Apocalypse 2025 Writeup: Web, Reversing and OSINT](https://maajix.github.io/ctfs/cyber-apocalypse/) - [ACECTF 2025 Writeup: JWT, S3 Buckets, WebCrypto and XOR Keystream Reuse](https://maajix.github.io/ctfs/acectf/) - [1337UP CTF 2024 Writeup: Cold Storage Crypto and OSINT](https://maajix.github.io/ctfs/1337up-2024/) - [Glacier CTF 2024 Writeup: Extracting a Hidden PNG from a PDF Stream](https://maajix.github.io/ctfs/glacier-2024/)