The kindness that leaks
Every polite touch on a login or password-reset flow is also a signal an attacker reads. A tour of how helpful auth UX leaks — and why the fix is to be gloriously boring.
I like to understand how things work — which means I spend a lot of time breaking them, mostly on purpose. Currently going deep into CTFs, sharing writeups and notes here.
I also do tech things with the family. We always have something cooking that's going to revolutionize the world, at least that's the plan.
Welcome to my personal space.
Net Sec Challenge
The Network Security capstone as a question sheet: a full-port sweep, flags tucked into service banners, an FTP brute-force, and a stealth scan, answered end to end.
Interceptor
MediaHub hides its logic in the traffic: a leaked backup gives the admin password format, a forged is_verified field skips the OTP, and a decimal-IP curl injection reads the flag off disk.
Operation Coldstart
A forgotten staging box: anonymous FTP leaks the source, an allow-list that resolves to localhost turns the URL previewer into an SSRF, and a tar wildcard in a root backup cron finishes the job.