Writeups & Research
Practical observations from penetration tests, bug bounty programs, exploit chains, and the tools used to investigate them.
Using Burp Suite MCP with AI to Assess a Supabase Application
A practical case study in AI-assisted application testing, from assessment through exploitation.
Chaining OSINT, IDOR, and RCE
How several moderate signals became a complete penetration-testing exploit chain.
A Weird Bug That Leaked PII
An unusual data exposure found through ordinary application behavior.
Blind SQL Injection on a DELETE Request
An uncommon injection point discovered during an authorized Synack Red Team engagement.
How to Hunt on Host-Based Bug Bounty Programs
A practical approach to reconnaissance, service enumeration, and network-level targets.
How I Found Blind SQL Injection Just by Browsing
A manual discovery that began with one unusual URL and led to a confirmed critical finding.