Writeups & Research

Practical observations from penetration tests, bug bounty programs, exploit chains, and the tools used to investigate them.

Using Burp Suite MCP with AI to Assess a Supabase Application

A practical case study in AI-assisted application testing, from assessment through exploitation.

Read ↗

Chaining OSINT, IDOR, and RCE

How several moderate signals became a complete penetration-testing exploit chain.

Read ↗

A Weird Bug That Leaked PII

An unusual data exposure found through ordinary application behavior.

Read ↗

Blind SQL Injection on a DELETE Request

An uncommon injection point discovered during an authorized Synack Red Team engagement.

Read ↗

How to Hunt on Host-Based Bug Bounty Programs

A practical approach to reconnaissance, service enumeration, and network-level targets.

Read ↗

How I Found Blind SQL Injection Just by Browsing

A manual discovery that began with one unusual URL and led to a confirmed critical finding.

Read ↗