Writeups

Everything I've broken, passed, or built — in reverse chronological order. Full articles live on Medium.

  1. How an Unpatched N-Day Let Any Anonymous Visitor Rewrite WooCommerce Prices in ND Booking
    This is a write-up of a vulnerability I independently discovered in ND Booking, a WordPress hotel/room booking plugin by Nicdark with WooCommerce integration.
  2. Unauthenticated Disclosure of A/B Test Data in Convert Pro — How Two Forgotten AJAX Endpoints…
    This is a write-up of a vulnerability I independently discovered in Convert Pro (WordPress.org slug: convertpro), an A/B testing and conversion-optimization plugin, in version 1.
  3. How I Found a Cross-Student IDOR in Academy LMS That Leaked Correct Quiz Answers
    Any enrolled student could read another student's private quiz results and extract the correct answers to quiz questions — before or during an attempt.
  4. ReadPEAS: I Was Tired of Reading LinPEAS Output, So I Built a Tool That Reads It For Me
    Every LinPEAS run ends the same way: a wall of green, yellow, and red text scrolling past faster than you can read it.
  5. I Found an Unauthenticated Attachment Disclosure Bug in a WordPress Support Plugin
    Walking through an unauthenticated attachment disclosure bug in a WordPress support plugin — from initial recon to responsible disclosure.
  6. Certified AD Red Team Specialist (AD-RTS): Full Exam Write-Up
    My full walkthrough of the Certified AD Red Team Specialist exam — the attack path, methodology, and the techniques that got me through.
  7. API-RTA Exam Walkthrough — Passed | CyberWarFare Labs
    CyberWarFare Labs' dedicated API security exam — one target, thirteen flags, and a deliberate push toward chaining smaller logic flaws together.
  8. I Found an Unauthenticated File Disclosure Bug in a WordPress Plugin
    Walking through an unauthenticated file disclosure bug I found in a WordPress plugin — and what I learned during the disclosure process.
  9. Beating LinkedIn's Mini Sudoku in 3 Seconds: A Parameter Tampering Case Study
    A parameter tampering case study: how a simple client-side trust flaw let me beat LinkedIn's Mini Sudoku in three seconds.
  10. MCRTA Exam Walkthrough — Multi-Cloud Red Teaming on AWS, Azure & GCP
    Documenting my methodology, the rabbit holes I fell into, and the key techniques that actually worked across AWS, Azure, and GCP.
  11. 7 Critical. 4 High. Zero Credentials. Full AI Chatbot Pentest.
    A full black-box penetration test walkthrough — from recon to remote code execution.
  12. I Found 3 Critical Vulnerabilities in an AI-Powered SOC Platform — Full Attack Chain
    An authorized pentest of an AI-powered SOC platform, chaining three critical vulnerabilities into a full attack chain.
  13. Web-RTA Exam Write-Up: Passed — CyberWarFare Labs
    My exam write-up for the CyberWarFare Labs Web Red Team Analyst (Web-RTA) — the attack path and methodology that got me through.
  14. GreatXML: How a Setup File Unlocked BitLocker — And Why Microsoft Can't Stop This Researcher
    If you've ever clicked 'Scan with Windows Defender Offline,' your BitLocker encryption may already be quietly compromised — and there's no patch for it yet.
  15. My Instructor Said You Can't Get a Shell — I Got Root: Full Web Pentest Exam Write-Up
    A full web pentest exam write-up — proving a shell was possible and escalating all the way to root.
  16. CRTA Exam Write-Up: Passed — CyberWarFare Labs
    My exam write-up for the CyberWarFare Labs Certified Red Team Analyst (CRTA) — the approach, methodology, and what it took to pass.
  17. TryHackMe — Linux Agency: Complete Write-Up & Walkthrough
    A complete TryHackMe walkthrough of the Linux Agency room, covering enumeration through to privilege escalation.
  18. TryHackMe — Break Out The Cage: Full Write-Up
    A full TryHackMe write-up of the Break Out The Cage room, worked from enumeration through to root.
  19. TryHackMe — CheckMate: Full Walkthrough
    A full TryHackMe walkthrough of the CheckMate room, covering exploitation through privilege escalation.
  20. TryHackMe — Mr. Robot CTF: Full Write-Up
    A full TryHackMe write-up of the Mr. Robot CTF room, from initial web enumeration to root.
  21. RedSEC
    How a red teamer's logs can tell a defender exactly what they missed — and generate the SEC rules that would have caught it.
  22. TryHackMe — Blog CTF: Full Write-Up
    A full TryHackMe write-up of the Blog CTF room, covering exploitation through to privilege escalation to root.
  23. TryHackMe — Wonderland: Full Walkthrough
    A full TryHackMe walkthrough of the Wonderland room, from initial foothold to root.
  24. TryHackMe — Biohazard: Full Write-Up
    A full TryHackMe write-up of the Biohazard room, worked from enumeration through to root.
  25. eJPT v2 — My First Certification, Passed in 8 Hours. Here's Everything You Need to Know.
    An honest account of taking the eLearnSecurity Junior Penetration Tester exam from Baku, Azerbaijan — and clearing it in eight hours.
  26. VulnHub — Sunset: Dawn Full Walkthrough
    A full VulnHub walkthrough of the Sunset: Dawn machine, worked from enumeration through to root.
  27. VulnHub — Sunset: Twilight Full Walkthrough
    A full VulnHub walkthrough of the Sunset: Twilight machine, worked from enumeration through to root.
  28. VulnHub — Shenron: 1 Full Walkthrough
    A full VulnHub walkthrough of the Shenron: 1 machine, worked from enumeration through to root.
  29. I Pentested a Real CRM System and Found 4 Critical Vulnerabilities — Here's the Full Attack Chain
    An authorized black-box pentest of a real CRM system, chaining four critical vulnerabilities into a complete attack chain.
  30. Real Estate CRM Pentest: Broken Auth + IDOR + Stored XSS — Full Attack Chain
    An authorized black-box penetration test of a real estate CRM, chaining three high-severity findings — broken authentication, IDOR, and stored XSS — into a complete account-takeover path.
  31. VulnHub — chatME: Write-Up
    A medium-difficulty black-box CTF: SQL injection auth bypass, SQLMap credential dumping, stored XSS, and a sudo-binary privilege escalation.
  32. VulnHub — Warzone: 3 (Exogen) Write-Up
    A hard-difficulty VulnHub machine demanding Java reverse engineering: decompile a JAR, decrypt AES-encrypted credentials, and unlock a GPG-protected archive to reach root.
  33. whoami
    A 16-year-old's honest account of breaking into systems, building tools, and figuring out who he is along the way.