Practical playbook for Email Address Manipulation — equivalence quirks, validation bypass, header/parser gaps, and staged Probe → Observe → Encode → Exploit testing, with the companion EAMG payload generator.
Read more →Tag
Bug Bounty
5 items across research, projects, awards, and talks.
Offline payload generator for authorized testing of email-address handling bugs — equivalence quirks, validation bypass, header/parser discrepancies, and related probes.
Read more →Practical IPv6-based SSRF techniques, real-world payloads, and testing notes for penetration testers and bug bounty hunters — where IPv4-only filters fail.
Read more →Automating Shodan-driven reconnaissance to surface high-signal targets and vulnerability clues across bug-bounty attack surfaces — queries, filters, and practical hunter workflows.
Read more →Invited talk on bug bounty hunting — methodology, reporting quality, and practical lessons from real programs. Hosted on the Security Talks channel.
Read more →Browse sections: Research · Projects · Award · Discoveries and Talk