Walkthrough of an Outlook / Exchange information-disclosure issue reachable by sending a crafted PDF that abuses a file-download token via an OAST-style callback.
Read more →Discoveries and Talk
Research demos, training & stages
YouTube walkthroughs on Microsoft research, vulnerability assessment, network scanning, and Shodan — plus Security Talks episodes and university workshops.
Invite to speakVideos
Watch demos and training sessions inline — or open them on YouTube.
Demonstration of spoofing display names when sending polls or surveys inside Microsoft Teams groups — messages appear to come from other members.
Read more →Integrity failure in Microsoft Teams polls / Forms voting — because vote limits are missing, ballots can be cast under other people’s names and appear legitimate in the manager’s voter list.
Read more →Deep dive into professional network port-scanning techniques — TCP flags, handshake behavior, Scapy packet crafting, Wireshark validation, and idle scan implementation.
Read more →Practical vulnerability assessment training — VAPT and VAPTRT concepts, VA scopes, hands-on tools (AppSpider, HCL AppScan, ReconFTW), and one-liner automation for recurring assessments.
Read more →Demo of CVE-2023-36845 — a PHP external variable modification flaw in Juniper J-Web (EX / SRX) that lets an unauthenticated attacker set PHPRC and achieve remote code execution.
Read more →Automating Shodan-driven reconnaissance to surface high-signal targets and vulnerability clues across bug-bounty attack surfaces — queries, filters, and practical hunter workflows.
Read more →Talks & workshops
Conference workshops and invited talks — open the event page or watch the recording when available.
Invited talk on Windows security — hardening concepts, common misconfigurations, and attacker-relevant paths defenders should watch. Hosted on the Security Talks channel.
Watch on YouTube →Invited talk on bug bounty hunting — methodology, reporting quality, and practical lessons from real programs. Hosted on the Security Talks channel.
Watch on YouTube →Hands-on workshop at SGC 2018 (University of Kurdistan APA Center) on IoT architectures, protocols, cyber threats, and live attack scenarios against constrained connected devices.
Open event page →Free webinar with the University of Kurdistan APA / e-learning center on penetration testing methodology — CEH-oriented techniques, security checklists, discovery tooling, and lawful ethical hacking for organizational assessments (12 Mar 2018).
Open event page →