Timeline

Timeline

Security research, CTF writeups, blog posts, CVEs, bug bounties, authored challenges, certificates, talks, and achievements ordered by date.

Common filters
More filters

Selected tags combine: results must match every selected tag.

Content type
Recognition
Difficulty
Severity
CTF competitions
Repositories
CVEs
CWEs
Categories
Topics, projects, and sources
65 / 65 items
  • 2026

    38 items
    • Upcoming
      Talk at BSides Munich. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • Talk at the OWASP Stammtisch Karlsruhe. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • FFmpeg Heap out-of-bounds write in the CFHD decoder via AVI demuxing
    • FFmpeg DVB subtitle parser heap buffer overflow via WTV file
    • FFmpeg Uninitialized heap memory read in the RSCC decoder
    • FFmpeg Uninitialized heap memory read in the Screenpresso decoder
    • FFmpeg Uninitialized heap memory read in the TIFF decoder
    • SuiteCRM Authenticated SQL injection in the map_markers distance parameter
    • Final presentation for the course. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • FFmpeg Uncontrolled resource consumption in the IAMF demuxer
    • FFmpeg Uninitialized memory disclosure in the LCL/Zlib video decoder
    • FFmpeg Integer overflow and heap out-of-bounds write in the MACE6 decoder
    • FFmpeg Heap out-of-bounds write in the PNG and APNG eXIf encoder
    • FFmpeg Heap out-of-bounds write in the vf_hqdn3d video filter
    • FFmpeg Heap out-of-bounds write in the vf_quirc video filter
    • FFmpeg Out-of-bounds write in the TDSC video decoder
    • FFmpeg Out-of-bounds write via the TY demuxer and Shorten decoder
    • FFmpeg Out-of-bounds write in the vf_floodfill video filter
    • FFmpeg Out-of-bounds write in the vf_swaprect video filter
    • Firedancer Race condition in the netshred module
    • Talk at KITCTF. How a manual SQLi hunt turned into an AI-assisted Joomla audit and multiple assigned CVEs for a university course.
    • Joomla CMS Privilege escalation through com_users batch task
    • Joomla CMS Authenticated blind SQL injection in com_tags
    • Joomla CMS Authenticated blind SQL injection in com_finder
    • Talk at KITCTF. Introductory web security talk for KITCTF.
    • ChurchCRM Authenticated blind SQL injection in SettingsUser.php
    • ChurchCRM Authenticated blind SQL injection in SettingsIndividual.php
    • ChurchCRM Authenticated blind SQL injection in PropertyTypeEditor.php
    • ChurchCRM Authenticated blind SQL injection in PropertyAssign.php
    • ChurchCRM Authenticated SQL injection in MemberRoleChange.php
    • ChurchCRM Second-order SQL injection via FundRaiserEditor.php
    • ChurchCRM Authenticated blind SQL injection in EventNames.php
  • 2025

    18 items
    • KITCTF #3 at GlacierCTF 2025 #3 at GlacierCTF.
    • FluxKITtens #6 at Google CTF 2025 #6 at Google CTF as the FluxKITtens merger team (FluxFingers and KITCTF), qualifying for the Hackceler8 finals in Mexico.
    • DHM 2025 participation Participated in the DHM finals.
    • CSCG 2025 top 10 global & DHM qualification Qualified for DHM again and finished top 10 globally.
    • KITCTF #3 at SwampCTF 2025 #3 at SwampCTF.
  • 2024

    9 items
    • KITCTF at SnakeCTF 2024 finals Qualified for and participated in the SnakeCTF finals in Italy.
    • KITCTF #3 at GlacierCTF 2024 #3 at GlacierCTF, qualifying for DHM 2025 as KITCTF team.
    • DHM 2024 #1 Placed #1 in the DHM finals.
    • CSCG 2024 DHM qualification Qualified for DHM through CSCG.
    • Firedancer v1 audit competition Participated in the Firedancer v1 audit competition.
    • KITCTF #1 at SwampCTF 2024 #1 at SwampCTF.