Writeups
Everything I've broken, passed, or built — in reverse chronological order. Full articles live on Medium.
↑↑↓↓←→←→ba — you went looking. most people just scroll. now go break something of your own.
- How an Unpatched N-Day Let Any Anonymous Visitor Rewrite WooCommerce Prices in ND Booking
This is a write-up of a vulnerability I independently discovered in ND Booking, a WordPress hotel/room booking plugin by Nicdark with WooCommerce integration.
- Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints…
This is a write-up of a vulnerability I independently discovered in Convert Pro (WordPress.org slug: convertpro), an A/B testing and conversion-optimization plugin, in version 1.
- How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
Any enrolled student could read another student's private quiz results and extract the correct answers to quiz questions — before or during an attempt.
- ReadPEAS: I Was Tired of Reading LinPEAS Output, So I Built a Tool That Reads It For Me
Every LinPEAS run ends the same way: a wall of green, yellow, and red text scrolling past faster than you can read it.
- I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin
Walking through an unauthenticated attachment disclosure bug in a WordPress support plugin — from initial recon to responsible disclosure.
- Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up
My full walkthrough of the Certified AD Red Team Specialist exam — the attack path, methodology, and the techniques that got me through.
- API-RTA Exam Walkthrough — Passed | CyberWarFare Labs
CyberWarFare Labs' dedicated API security exam — one target, thirteen flags, and a deliberate push toward chaining smaller logic flaws together.
- I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin
Walking through an unauthenticated file disclosure bug I found in a WordPress plugin — and what I learned during the disclosure process.
- Beating LinkedIn's Mini Sudoku in 3 Seconds: A Parameter Tampering Case Study
A parameter tampering case study: how a simple client-side trust flaw let me beat LinkedIn's Mini Sudoku in three seconds.
- MCRTA Exam Walkthrough — Multi-Cloud Red Teaming on AWS, Azure & GCP
Documenting my methodology, the rabbit holes I fell into, and the key techniques that actually worked across AWS, Azure, and GCP.
- 7 Critical. 4 High. Zero Credentials. Full AI Chatbot Pentest.
A full black-box penetration test walkthrough — from recon to remote code execution.
- I Found 3 Critical Vulnerabilities in an AI-Powered SOC Platform — Full Attack Chain
An authorized pentest of an AI-powered SOC platform, chaining three critical vulnerabilities into a full attack chain.
- Web-RTA Exam Write-Up: Passed — CyberWarFare Labs
My exam write-up for the CyberWarFare Labs Web Red Team Analyst (Web-RTA) — the attack path and methodology that got me through.
- GreatXML: How a Setup File Unlocked BitLocker — And Why Microsoft Can't Stop This Researcher
If you've ever clicked 'Scan with Windows Defender Offline,' your BitLocker encryption may already be quietly compromised — and there's no patch for it yet.
- My Instructor Said You Can't Get a Shell — I Got Root: Full Web Pentest Exam Write-Up
A full web pentest exam write-up — proving a shell was possible and escalating all the way to root.
- CRTA Exam Write-Up: Passed — CyberWarFare Labs
My exam write-up for the CyberWarFare Labs Certified Red Team Analyst (CRTA) — the approach, methodology, and what it took to pass.
- TryHackMe — Linux Agency: Complete Write-Up & Walkthrough
A complete TryHackMe walkthrough of the Linux Agency room, covering enumeration through to privilege escalation.
- TryHackMe — Break Out The Cage: Full Write-Up
A full TryHackMe write-up of the Break Out The Cage room, worked from enumeration through to root.
- TryHackMe — CheckMate: Full Walkthrough
A full TryHackMe walkthrough of the CheckMate room, covering exploitation through privilege escalation.
- TryHackMe — Mr. Robot CTF: Full Write-Up
A full TryHackMe write-up of the Mr. Robot CTF room, from initial web enumeration to root.
- RedSEC
How a red teamer's logs can tell a defender exactly what they missed — and generate the SEC rules that would have caught it.
- TryHackMe — Blog CTF: Full Write-Up
A full TryHackMe write-up of the Blog CTF room, covering exploitation through to privilege escalation to root.
- TryHackMe — Wonderland: Full Walkthrough
A full TryHackMe walkthrough of the Wonderland room, from initial foothold to root.
- TryHackMe — Biohazard: Full Write-Up
A full TryHackMe write-up of the Biohazard room, worked from enumeration through to root.
- eJPT v2 — My First Certification, Passed in 8 Hours. Here's Everything You Need to Know.
An honest account of taking the eLearnSecurity Junior Penetration Tester exam from Baku, Azerbaijan — and clearing it in eight hours.
- VulnHub — Sunset: Dawn Full Walkthrough
A full VulnHub walkthrough of the Sunset: Dawn machine, worked from enumeration through to root.
- VulnHub — Sunset: Twilight Full Walkthrough
A full VulnHub walkthrough of the Sunset: Twilight machine, worked from enumeration through to root.
- VulnHub — Shenron: 1 Full Walkthrough
A full VulnHub walkthrough of the Shenron: 1 machine, worked from enumeration through to root.
- I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here's the Full Attack Chain
An authorized black-box pentest of a real CRM system, chaining four critical vulnerabilities into a complete attack chain.
- Real Estate CRM Pentest: Broken Auth + IDOR + Stored XSS — Full Attack Chain
An authorized black-box penetration test of a real estate CRM, chaining three high-severity findings — broken authentication, IDOR, and stored XSS — into a complete account-takeover path.
- VulnHub — chatME: Write-Up
A medium-difficulty black-box CTF: SQL injection auth bypass, SQLMap credential dumping, stored XSS, and a sudo-binary privilege escalation.
- VulnHub — Warzone: 3 (Exogen) Write-Up
A hard-difficulty VulnHub machine demanding Java reverse engineering: decompile a JAR, decrypt AES-encrypted credentials, and unlock a GPG-protected archive to reach root.
- whoami
A 16-year-old's honest account of breaking into systems, building tools, and figuring out who he is along the way.