Security Research & Writeups

Sharing knowledge through detailed vulnerability research and tool development insights.

From a Simple Client-Side Mistake to Full Read/Write Access of an Internal Support System
Feb 23, 2026
Web SecurityToken GenerationAPI SecurityBug Bounty

From a Simple Client-Side Mistake to Full Read/Write Access of an Internal Support System

Discover how exposed client-side token generation with a hardcoded secret key led to complete compromise of an internal support system. A detailed analysis of a critical cryptographic flaw...

Frozen Fingers & Hot Bugs: How a Small Dork Turned Into Full Support Panel Access
Dec 13, 2025
Web SecurityXSSBug BountyPenetration Testing

Frozen Fingers & Hot Bugs: How a Small Dork Turned Into Full Support Panel Access

A winter night of curiosity led to discovering unauthenticated access to a support panel with XSS vulnerabilities. See how dorks and fuzzing revealed critical security flaws...

Exploiting an Insecure Android Activity for Arbitrary File Theft and Account Takeover
Oct 18, 2025
AndroidWebViewAccount TakeoverBug Bounty

Exploiting an Insecure Android Activity for Arbitrary File Theft and Account Takeover

Discover how an exported Android Activity with improper input validation led to sensitive file theft and full account compromise through WebView exploitation...

Unveiling Secrets: Masterful Hacks to Defeat Android SSL Pinning
Jan 15, 2025
AndroidSSL PinningFridaBurp Suite

Unveiling Secrets: Masterful Hacks to Defeat Android SSL Pinning

Complete guide to bypassing SSL pinning on Android apps using Frida, Objection, Burp Suite, and HTTP Toolkit. Learn ethical hacking techniques for security testing...

Top Android Apps Security Flaws: What You Need to Know!
Apr 5, 2024
AndroidMobile SecurityCTF

Top Android Apps Security Flaws: What You Need to Know!

Deep dive into common Android security vulnerabilities through hands-on analysis of the Beetlebug application. Learn about hardcoded secrets, insecure data storage, SQL injection, and more...

Built with v0