Web · Mobile · API
Security
I test web and mobile applications, and I write up what I find. The findings that interest me are the ones a scanner cannot reach.
Capabilities
Web application security
- Burp Suite
- OWASP Top 10
- REST and GraphQL APIs
- Access control testing
- Business logic flaws
Mobile application security
- Android
- jadx
- Frida
- objection
- Intent attack surface
- Certificate pinning bypass
Infrastructure
- Windows Server
- Active Directory
- DNS
- DHCP
- Network troubleshooting
Scripting
- Python
- Bash
Writeups
No bug-bounty findings are published yet. The slots below show what will appear here.
- WebNot yet published
Access control and business logic findings
Authorisation derived from a value the caller controls, and workflows that can be completed out of order. Each writeup will carry the request evidence, the impact, and the fix.
- MobileNot yet published
Android application findings
Static analysis, SMALI modification, runtime hooking with Frida, and traffic interception through certificate pinning.
Goals
Deeper coverage of the Android attack surface, more published findings from bug bounty work, and a first CVE.