Skip to content

Web · Mobile · API

Security

I test web and mobile applications, and I write up what I find. The findings that interest me are the ones a scanner cannot reach.

Capabilities


Web application security

  • Burp Suite
  • OWASP Top 10
  • REST and GraphQL APIs
  • Access control testing
  • Business logic flaws

Mobile application security

  • Android
  • jadx
  • Frida
  • objection
  • Intent attack surface
  • Certificate pinning bypass

Infrastructure

  • Windows Server
  • Active Directory
  • DNS
  • DHCP
  • Network troubleshooting

Scripting

  • Python
  • Bash

Writeups


No infrastructure findings are published yet. The slots below show what will appear here.

  • WebNot yet published

    Access control and business logic findings

    Authorisation derived from a value the caller controls, and workflows that can be completed out of order. Each writeup will carry the request evidence, the impact, and the fix.

  • MobileNot yet published

    Android application findings

    Static analysis, SMALI modification, runtime hooking with Frida, and traffic interception through certificate pinning.

Goals


Deeper coverage of the Android attack surface, more published findings from bug bounty work, and a first CVE.

Certifications and background