Security Researcher | Bug Bounty Hunter | Ethical Hacker
Hunting vulnerabilities and securing the digital frontier, one bug at a time.
Security researcher specializing in web application security, API testing, and CI/CD pipeline vulnerabilities. Certified penetration tester with active profiles on major bug bounty platforms.
Currently building advanced reconnaissance and security analysis tools, with a focus on automating vulnerability discovery and responsible disclosure.
Comprehensive MCP toolkit integrating 40+ security tools with AI-powered natural language interface for penetration testing workflows.
Smart contract security analysis tool for identifying vulnerabilities in blockchain applications and DeFi protocols.
Automated reconnaissance framework for bug bounty hunting, featuring subdomain enumeration and vulnerability scanning.
Expert-level proficiency with nuclei, subfinder, httpx, and the complete ProjectDiscovery security toolkit.
A Windows Server 2025 domain controller rooted through ADCS: a low-priv user revives deleted-but-still-published certificate templates (ESC3), then beats Full strong-binding by forging a cert for the DC machine account — PKINIT to DCSync to Domain Admin.
Read Writeup →Full Active Directory domain compromise: anonymous LDAP enumeration into AS-REP Roasting, then nested-group and WriteDACL abuse to self-grant DCSync rights and Pass-the-Hash as Administrator.
Read Writeup →A Linux box built entirely around hand-rolled legacy printer protocols. Chains an LPD shell injection into a JetDirect path traversal for SSH key injection, then abuses a forensic honeypot's SCM_RIGHTS FD leak to reach root.
Read Writeup →A Next.js dashboard owned through a framework-level bug: unauthenticated RCE via CVE-2025-55182 ("React2Shell"), then SQLite credential theft and an MD5 crack, escalating to root by abusing a debug-mode Node.js process over the Chrome DevTools Protocol.
Read Writeup →A chain of corporate misconfigurations: an unauthenticated NFS share leaks onboarding creds, password reuse opens an OpenSTAManager CRM, and an authenticated file-upload RCE (CVE-2026-38751) lands a foothold — escalating to root via a shell-injectable OliveTin action running unauthenticated on localhost.
Read Writeup →A leaked DB password buried in Gitea commit history and a Krayin CRM file-upload RCE (CVE-2026-38526) chain into a foothold — then root falls to a hand-crafted git tree object smuggling a path-traversal filename past a root-run template sync script.
Read Writeup →An unauthenticated Craft CMS preauth RCE (CVE-2025-32432) via a Yii2 behavior gadget and access-log poisoning lands a foothold, then a cracked admin hash opens SSH — and root falls to a telnetd argument-injection auth bypass (CVE-2026-24061) where a crafted USER value becomes login -f root.
Read Writeup →A password-reset endpoint hands back the new password in its response, opening a log-viewer LFI that's poisoned via the User-Agent for RCE — then legacy rservices trust (hosts.equiv) and a sudo nano GTFOBins escape chain all the way to root.
Read Writeup →A MariaDB instance exposed on its default port with unauthenticated root access — no exploit chain, just SQL enumeration. A clean refresher on hunting an application database, with an information_schema cheatsheet for locating a target column across an unfamiliar schema fast.
Read Writeup →A Windows XAMPP host with an LFI in a page parameter is pivoted from file disclosure into NTLM coercion — feeding include() a UNC path forces the box to authenticate to a Responder listener, leaking an Administrator hash that cracks to a weak password and opens a WinRM shell via Evil-WinRM.
Read Writeup →Virtual-host fuzzing surfaces a hidden s3 subdomain backing the site from a publicly writable, misconfigured S3 bucket that doubles as the Apache web root — so uploading a PHP web shell with anonymous AWS creds is instant RCE as www-data, escalated to a reverse shell and the flag.
Read Writeup →> More writeups coming soon. Check back regularly for new content.
root@security:~$ [email protected]
For security disclosures, please use encrypted communication.