A collection of thoughts, tutorials, and write-ups.
How a simple header injection flaw bypassed all protections and led to full account takeover.
Learn how a legacy endpoint bypassed OTP security, leading to full account takeover in a social media app.
Explore prompt injection strategies to solve Lakera's Gandalf challenge and learn how user input overrides AI prompts.
Explore the security risks of Prompt Injection, a vulnerability that manipulates LLM inputs, leading to unintended and potentially harmful responses. This part will only cover the reconnaissance.
Writeup for FINCII2024 STEGANOGRAPHY DEEP SEA
Writeup for FINCII2024 OSINT MALVERTISING
Writeup for FINCII2024 BOOT2ROOT
Writeup for Hack The Box LoveTok