A running record of what I find, report and get paid for. Newest first.
OIDC login token can be redirected to an attacker-controlled URL
The OIDC login flow accepted an attacker-supplied redirect target, handing the issued token to a URL outside the application.
Transcoder serves uncataloged files from the media directory
The transcoder streamed any file under the media directory, including files never added to the library.
YekCity
A physical OT security demonstrator that makes cyberattacks visible when the city goes dark.
Securinets CTF 2025
Chaining a username SQL injection, an SSRF and a broken collaboration-request check into admin access, plus the MD7 misc challenge.
CrewCTF 2025
Getting XSS past a strict Content Security Policy and exfiltrating the result to a Burp Collaborator callback.
FortID CTF 2025
Abusing the target_user parameter on the admin upload endpoint to plant files as another user, plus reversing and misc.
Nullcon CTF 2025
Brute forcing grandmas_notes character by character through a password oracle, and pwgen leaking its source via ?source=1.
TFCCTF 2025
SLIPPY abuses a ZIP symlink for arbitrary file read, DOM NOTIFY uses DOM clobbering against a Puppeteer admin bot.
HTB Cyber Apocalypse 2025
The Trial by Fire and Whispers of the Moonbeam web challenges, SealedRune reversing and Echoes in Stone OSINT.
ACECTF 2025
WebCrypto, JWT forgery in Token of Trust, an S3 bucket misconfiguration, plus reversing and XOR keystream reuse crypto.
Car hacking demonstrator
Emulating real CAN bus communication to train automotive attack and defense hands-on.
1337UP CTF 2024
Solving Cold Storage by unwinding the XOR and RSA layers protecting the key, plus the OSINT challenges.
Glacier CTF 2024
Using peepdf to inspect PDF object streams and recover a PNG image embedded inside the document.
