Resources

People often ask me "How did you learn how to hack?" The answer: by reading. This page is a collection of the blog posts and other articles that I have accumulated over the years of my journey. Enjoy!

Advanced Client Side Hacking- 1940

XSS Doctor & Jason HaddixPosted 1 Month Ago

Impossible XXE in PHP- 1939

Aleksandr Zhurnakov - Swarm PTPosted 1 Month Ago

Don’t trust, verify- 1938

Daniel StenbergPosted 1 Month Ago

The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance- 1937

mehmetincePosted 1 Month Ago

How We Broke Exchanges: A Deep Dive Into Authentication And Client-Side Bugs- 1936

OtterSecPosted 1 Month Ago

SharePoint ToolShell – One Request PreAuth RCE Chain- 1935

viettelPosted 1 Month Ago

One Missing Check, $500M at Risk: MsgBatchUpdateOrders Let Anyone Drain Any Account on Injective- 1934

al-f4lc0nPosted 1 Month Ago

Exploiting aToken liquidity addition in stableswap - post mortem- 1933

Jakub PanikPosted 1 Month Ago

Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs- 1932

v4belPosted 1 Month Ago

How to Harden GitHub Actions: The Unofficial Guide- 1931

WizPosted 1 Month Ago