Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Advanced Client Side Hacking- 1940

XSS Doctor & Jason HaddixPosted 3 Months Ago

Impossible XXE in PHP- 1939

Aleksandr Zhurnakov - Swarm PTPosted 3 Months Ago

Don’t trust, verify- 1938

Daniel StenbergPosted 3 Months Ago

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance- 1937

mehmetincePosted 3 Months Ago

How We Broke Exchanges: A Deep Dive Into Authentication And Client-Side Bugs- 1936

OtterSecPosted 3 Months Ago

SharePoint ToolShell – One Request PreAuth RCE Chain- 1935

viettelPosted 3 Months Ago

One Missing Check, $500M at Risk: MsgBatchUpdateOrders Let Anyone Drain Any Account on Injective- 1934

al-f4lc0nPosted 3 Months Ago

Exploiting aToken liquidity addition in stableswap - post mortem- 1933

Jakub PanikPosted 3 Months Ago

Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs- 1932

v4belPosted 3 Months Ago

How to Harden GitHub Actions: The Unofficial Guide- 1931

WizPosted 3 Months Ago