Timeline

Timeline

Security research, CTF writeups, blog posts, CVEs, bug bounties, authored challenges, certificates, talks, and achievements ordered by date.

Year
Filters
Recognition
Difficulty
Severity
Content type
CTF competitions
Repositories
CVEs
CWEs
Categories
Topics, projects, and sources
65 / 65 items
  • 2026

    38 items
    • Upcoming
      Talk at BSides Munich. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • Talk at the OWASP Stammtisch Karlsruhe. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • FFmpeg DVB subtitle parser heap buffer overflow via WTV file
    • FFmpeg Uninitialized heap memory read in the RSCC decoder
    • FFmpeg Uninitialized heap memory read in the Screenpresso decoder
    • FFmpeg Uninitialized heap memory read in the TIFF decoder
    • FFmpeg Heap out-of-bounds write in the CFHD decoder via AVI demuxing
    • SuiteCRM Authenticated SQL injection in the map_markers distance parameter
    • Final presentation for the course. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • FFmpeg Heap out-of-bounds write in the vf_quirc video filter
    • FFmpeg Heap out-of-bounds write in the PNG and APNG eXIf encoder
    • FFmpeg Integer overflow and heap out-of-bounds write in the MACE6 decoder
    • FFmpeg Uninitialized memory disclosure in the LCL/Zlib video decoder
    • FFmpeg Uncontrolled resource consumption in the IAMF demuxer
    • FFmpeg Heap out-of-bounds write in the vf_hqdn3d video filter
    • FFmpeg Out-of-bounds write via the TY demuxer and Shorten decoder
    • FFmpeg Out-of-bounds write in the TDSC video decoder
    • FFmpeg Out-of-bounds write in the vf_floodfill video filter
    • FFmpeg Out-of-bounds write in the vf_swaprect video filter
    • Firedancer Race condition in the netshred module
    • Talk at KITCTF. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • Joomla CMS Authenticated blind SQL injection in com_finder
    • Joomla CMS Authenticated blind SQL injection in com_tags
    • Joomla CMS Privilege escalation through com_users batch task
    • Talk at KITCTF. Introductory web security talk for KITCTF.
    • ChurchCRM Second-order SQL injection via FundRaiserEditor.php
    • ChurchCRM Authenticated blind SQL injection in SettingsUser.php
    • ChurchCRM Authenticated blind SQL injection in PropertyTypeEditor.php
    • ChurchCRM Authenticated SQL injection in MemberRoleChange.php
    • ChurchCRM Authenticated blind SQL injection in EventNames.php
    • ChurchCRM Authenticated blind SQL injection in PropertyAssign.php
    • ChurchCRM Authenticated blind SQL injection in SettingsIndividual.php
  • 2025

    18 items
    • KITCTF #3 at GlacierCTF 2025 #3 at GlacierCTF.
    • FluxKITtens #6 at Google CTF 2025 #6 at Google CTF as the FluxKITtens merger team (FluxFingers and KITCTF), qualifying for the Hackceler8 finals in Mexico.
    • DHM 2025 participation Participated in the DHM finals.
    • CSCG 2025 top 10 global & DHM qualification Qualified for DHM again and finished top 10 globally.
    • KITCTF #3 at SwampCTF 2025 #3 at SwampCTF.
  • 2024

    9 items
    • KITCTF at SnakeCTF 2024 finals Qualified for and participated in the SnakeCTF finals in Italy.
    • KITCTF #3 at GlacierCTF 2024 #3 at GlacierCTF, qualifying for DHM 2025 as KITCTF team.
    • DHM 2024 #1 Placed #1 in the DHM finals.
    • CSCG 2024 DHM qualification Qualified for DHM through CSCG.
    • Firedancer v1 audit competition Participated in the Firedancer v1 audit competition.
    • KITCTF #1 at SwampCTF 2024 #1 at SwampCTF.