Code reviews, CTF solutions, and vulnerability research — written up while the details were still fresh. 12 posts across 4 categories.
Learn about race conditions, their types, exploitation techniques, and mitigation strategies.
A brief story of how a Type Confusion vulnerability allowed privilege escalation in a real-world scenario.
A step-by-step guide to reverse engineering and exploiting an exported Android AIDL-based bound Service from another app.
A short write-up on exploiting an Android Service vulnerability involving Messenger IPC and state management to retrieve a hidden flag.
A file upload endpoint accepted folder traversal sequences, enabling unauthorized file placement and abuse of signed Google Cloud Storage URLs.
A critical CORS misconfiguration allowed stealing authentication tokens by abusing a wildcard-like origin match and Access-Control-Allow-Credentials: true.
A real-world case where UI-level permission controls were not enforced at the API level, allowing message sending and user impersonation.