Writing
Everything published here — research, writeups, and notes — newest first.
- Mar 2026 WinjaCTF 2026 Writeup Writeups for the WinjaCTF 2026 challenges - prototype pollution, git forensics, keras supply chain backdoor, React2Shell RCE, and MFA bypass via IDOR.
- Mar 2026 HTB: Pirate Hard-rated Windows Active Directory machine. A full walkthrough from recon to Domain Admin.
- Jan 2026 CVE-2025-9318: Authenticated SQL Injection in Quiz and Survey Master (QSM) Time-based blind SQL injection in Quiz and Survey Master (QSM) ≤ 10.3.1, allowing any authenticated user to extract sensitive data from the database.
- Jan 2023 eJPT Cheatsheet (2023) Cheatsheet/notes to prepare for the INE/eLearnSecurity eJPT certification.