Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Chaining Razor SSTI into RCE via Reflection and Runtime Strings- 2022

phsiPosted 3 Months Ago

Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor- 2021

socketPosted 3 Months Ago

COST, AI frontier models and more: A measured take on the future of security testing- 2020

YesWeHackPosted 4 Months Ago

Breaking Jolt’s Verifier with an Unbound Uni-skip Claim- 2019

Minsun KimPosted 4 Months Ago

Stealth Request That Bypasses CSP, Hides from DevTools, and Leaks the Real User-Agent- 2018

brokenbrowserPosted 4 Months Ago

Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama- 2017

CyeraPosted 4 Months Ago

The down fall of bug bounties- 2016

shubsPosted 4 Months Ago

Solving the Hack Problem in Web3 via Formal Verification- 2015

VitalikPosted 4 Months Ago

The Breaking Point of Ethical Security Research- 2014

Peter KacherginskyPosted 4 Months Ago

Light into Darkness: Demystifying Profit Strategies Throughout the MEV Bot Lifecycle- 2013

Feng LuoPosted 4 Months Ago