Second Order XXE Exploitation

A writeup about my finding on Synack that was an XXE that allowed me to read local files stored on the web server.
Read more →

NoSQL Injection in Plain Sight

A writeup about a recent NoSQL injection I found in Synack Red Team
Read more →

Path Traversal Paradise

A writeup about the path traversals that I found in Synack Red Team
Read more →

120 Days of High Frequency Hunting

A writeup about my journey to find 120 bugs in 120 days
Read more →

Prove Yourself as 1337 Null Ahmedabad

A short writeup on the ‘Prove Yourself as 1337’ challenge at Null Ahmedabad CTF
Read more →