Walkthrough of an Outlook / Exchange information-disclosure issue reachable by sending a crafted PDF that abuses a file-download token via an OAST-style callback.
Read more →Tag
Video
7 items across research, projects, awards, and talks.
Demonstration of spoofing display names when sending polls or surveys inside Microsoft Teams groups — messages appear to come from other members.
Read more →Integrity failure in Microsoft Teams polls / Forms voting — because vote limits are missing, ballots can be cast under other people’s names and appear legitimate in the manager’s voter list.
Read more →Deep dive into professional network port-scanning techniques — TCP flags, handshake behavior, Scapy packet crafting, Wireshark validation, and idle scan implementation.
Read more →Practical vulnerability assessment training — VAPT and VAPTRT concepts, VA scopes, hands-on tools (AppSpider, HCL AppScan, ReconFTW), and one-liner automation for recurring assessments.
Read more →Demo of CVE-2023-36845 — a PHP external variable modification flaw in Juniper J-Web (EX / SRX) that lets an unauthenticated attacker set PHPRC and achieve remote code execution.
Read more →Automating Shodan-driven reconnaissance to surface high-signal targets and vulnerability clues across bug-bounty attack surfaces — queries, filters, and practical hunter workflows.
Read more →Browse sections: Research · Projects · Award · Discoveries and Talk