$ whoami
Offensive research, CVEs and hacking notes.
I work in offensive security: I find vulnerabilities, write the exploit and document how they get fixed. Here I collect CVEs, writeups and technical notes. No hype: just what I broke, how, and how it's closed.
- Published CVEs
- 3
- Highest CVSS
- 9.8
- Certifications
- 7
Focus areas
- Web application penetration testing
- Vulnerability research
- Active Directory
- .NET / ViewState deserialization
- File upload & RCE
- Responsible disclosure
Latest posts
CVE-2023-32268: cleartext LDAP credentials in MicroFocus Filr ApplianceCVE-2023-32268
A Filr administrator can retrieve, in cleartext, the LDAP service password used to synchronise Active Directory, opening a path to full domain controller compromise.
CVE-2022-39983: arbitrary file upload in the Instant Developer RD3 frameworkCVE-2022-39983
A library in Instant Developer's RD3 framework allows arbitrary file upload and remote code execution on every web app built with versions prior to 22.5 r23.
CVE-2022-30422: ViewState deserialization in Proietti Planet Time EnterpriseCVE-2022-30422
A default validationKey in Planet Time Enterprise's web.config lets an unauthenticated attacker forge a malicious ViewState and execute commands remotely on the server.