Security research, CTF writeups, blog posts, CVEs, bug bounties, authored challenges, certificates, talks, and achievements ordered by date.
Common filters
More filters
Selected tags combine: results must match every selected tag.
Content type
Recognition
Difficulty
Severity
CTF competitions
Repositories
CVEs
CWEs
Categories
Topics, projects, and sources
64 / 64 items
2026
39 items
Upcoming
Talk at BSides Munich.How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
SuiteCRMSQL injection through the legacy SOAP portal_get_entry_list method
Talk at the OWASP Stammtisch Karlsruhe.How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
FFmpegHeap out-of-bounds write in the CFHD decoder via AVI demuxing
FFmpegDVB subtitle parser heap buffer overflow via WTV file
FFmpegUninitialized heap memory read in the RSCC decoder
FFmpegUninitialized heap memory read in the Screenpresso decoder
FFmpegUninitialized heap memory read in the TIFF decoder
SuiteCRMAuthenticated SQL injection in the map_markers distance parameter
Final presentation for the course.How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
FFmpegUncontrolled resource consumption in the IAMF demuxer
FFmpegUninitialized memory disclosure in the LCL/Zlib video decoder
FFmpegInteger overflow and heap out-of-bounds write in the MACE6 decoder
FFmpegHeap out-of-bounds write in the PNG and APNG eXIf encoder
FFmpegHeap out-of-bounds write in the vf_hqdn3d video filter
FFmpegHeap out-of-bounds write in the vf_quirc video filter
FFmpegOut-of-bounds write in the TDSC video decoder
FFmpegOut-of-bounds write via the TY demuxer and Shorten decoder
FFmpegOut-of-bounds write in the vf_floodfill video filter
FFmpegOut-of-bounds write in the vf_swaprect video filter
Talk at KITCTF.How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
Climbing Stairs from Two AnglesLeetCode's Climbing Stairs problem looks like a simple dynamic-programming challenge, but a closer look connects Fibonacci numbers, binomial coefficients, and Pascal's triangle.12 min read
Teaching AI to hack Joomla so I can skip my homeworkHow a manual SQLi hunt turned into an AI-assisted Joomla audit, two assigned CVEs, and a surprisingly valid way to pass a university lab.16 min read
Scanwich StationA table-side QR reader for hungry guests and suspicious menus. One special order can make the scanner serve more than dinner.14 min read
Funny Java Strings?Java Strings are immutable, interned, optimized, and surprisingly easy to misunderstand when secrets are involved. This post digs into String pooling, reflection, Base64 copies, library APIs, and why heap dumps are bad news for secrets.9 min read
Joomla CMSPrivilege escalation through com_users batch task
Joomla CMSAuthenticated blind SQL injection in com_tags
Joomla CMSAuthenticated blind SQL injection in com_finder
xmallocAll of our slot machines switched from using the very insecure libc heap implementation to something much more secure internally. Surely this new heap implementation is unbreakable :D9 min read
Talk at KITCTF.Introductory web security talk for KITCTF.
Firedancer v1 audit competitionParticipated in the Firedancer v1 audit competition.
ChurchCRMAuthenticated blind SQL injection in SettingsUser.php
ChurchCRMAuthenticated blind SQL injection in SettingsIndividual.php
ChurchCRMAuthenticated blind SQL injection in PropertyTypeEditor.php
ChurchCRMAuthenticated blind SQL injection in PropertyAssign.php
ChurchCRMAuthenticated SQL injection in MemberRoleChange.php
ChurchCRMSecond-order SQL injection via FundRaiserEditor.php
ChurchCRMAuthenticated blind SQL injection in EventNames.php
HTB CPTSMy experience completing the Hack The Box Certified Penetration Testing Specialist (HTB CPTS) certification. I share the journey, rough timeline, exam tips, and tools that helped me succeed.8 min read
2025
18 items
KITCTF #3 at GlacierCTF 2025#3 at GlacierCTF.
My Flask AppA small Flask application from an easy SekaiCTF web challenge.7 min read
Fancy WebThe Ministry of Information and Communications Technology of Konoha has recently launched their new official website. While it appears to be a standard government portal showcasing public services and announcements, our intelligence sources have indicated that this WordPress-based website contains hidden information that could expose corruption and human rights violations. The website features a unique table processing system that displays various government data, but our analysts suspect that the developers have hidden sensitive information within the table structures themselves. The site's administrators are known for their sophisticated obfuscation techniques, making it difficult to distinguish between legitimate public data and concealed evidence. Your mission is to investigate this website and uncover the hidden information by looking beyond the surface-level content and examining how the tables are processed and displayed - the truth might be hidden, waiting for someone with the right skills to reveal it.15 min read
Smile at meMy hard web challenge for GPNCTF 2025.11 min read
FluxKITtens #6 at Google CTF 2025#6 at Google CTF as the FluxKITtens merger team (FluxFingers and KITCTF), qualifying for the Hackceler8 finals in Mexico.
DHM 2025 participationParticipated in the DHM finals.
LeafI always think leaf ~= tea. Please allow remote to have some time to boot the browser.6 min read
Everyone loves canteen foodWelcome to the canteen's online menu, where you can check out the daily specials and their prices. But is everything as appetizing as it seems?5 min read
vidplowWe recently stumbled upon an exposed SVN server of a large multimedia corporation, containing some of their backend application and internal tooling code. However, the access keys seem to not be the ones used in production - the real ones should fetch us quite a high price though, if we manage to get our hands on them that is. Just one problem - the tech stack seems to be really obscure, and no one on our team seems to have any clue what the heck is going on. Can you take a look, and maybe find some vulnerabilities in this thing?4 min read
KDF dreamWe've managed to insert ourselves into a secure channel between two covert agents, however we overplayed our hand and they have become suspicious that their channel is compromised. Realising that there is no way to restablish trust over the compromised network, Alice called for them to carry out a NIST Certified KDF protocol to generate a symmetric OTP, and then for them to use this to encrypt a physical message at a dead drop location. We want to control the message she leaves, can you influence their conversation to control what Bob reads at the dead drop?9 min read
Air smellerI found this website where you can rate the smell of the air, after purification. Do you know a good purifier, maybe you can recommend some purifier to the people.7 min read
CSCG 2025 top 10 global & DHM qualificationQualified for DHM again and finished top 10 globally.
Fantastic DoomDoctor Doom, the monarch of Latveria has made many doombots. You working with the Fantastic 4 have to access doombot machine and foil his plans of releasing doombots.5 min read
Cash MemoI have a really hard time managing my cash, am afraid someone might steal my memos...10 min read
KITCTF #3 at SwampCTF 2025#3 at SwampCTF.
Tar boomWithin the Louvre Museum's intranet, there is a service that allows trusted users to upload .tar files and view their content. However, this service has been exploited by a hacker. He was able to retrieve crucial information about the Louvre's security, hidden within the flag.txt.4 min read
GamedevYou've heard of rogue-likes, but have you heard of heap-likes?5 min read
A Minecraft MovieI...AM STEVE!9 min read
2024
7 items
KITCTF at SnakeCTF 2024 finalsQualified for and participated in the SnakeCTF finals in Italy.
KITCTF #3 at GlacierCTF 2024#3 at GlacierCTF, qualifying for DHM 2025 as KITCTF team.
CORS PlaygroundAn easy FCSC web challenge centered on browser cross-origin policies.5 min read
DHM 2024 #1Placed #1 in the DHM finals.
HosterYou gained access to a Linux server. Can you also gain privileges?4 min read
PhotoeditorA medium CSCG web challenge built around ASP.NET Core and dynamic application behavior.5 min read
CSCG 2024 DHM qualificationQualified for DHM through CSCG.