Building my own AI Agents
From frustration with existing frameworks to building my own agent in under 72 hours — what I learned about memory, SDKs, and the real complexity of AI agents.
Analysis, methodologies, and technical perspectives on contemporary security challenges.
From frustration with existing frameworks to building my own agent in under 72 hours — what I learned about memory, SDKs, and the real complexity of AI agents.
Diagnosing a WordPress site compromise that was redirecting visitors to adult content and pharmaceutical spam through injected malicious scripts.
Hookd - A simple webhook server for testing and debugging.
Setting up simple monitoring for your services.
Testing smart contracts using Remix IDE.
Solving the Ethernaut DEX Two challenge.
Solving The Rewarder challenge from Damn Vulnerable DeFi.
Solving the Side Entrance challenge from Damn Vulnerable DeFi.
Solving the Truster challenge from Damn Vulnerable DeFi.
Solving the Naive Receiver challenge from Damn Vulnerable DeFi.
Setting up a collaborative code auditing environment using code-server.
Solving the Unstoppable challenge from Damn Vulnerable DeFi.
Extracting and monitoring bug bounty scopes automatically.
My journey through various blogging platforms over seven years and why I finally settled on Hugo with GitHub Pages.
Comparing subdomain bruteforce and permutation techniques using Regulator, DNSGen, and AlterX to find the most effective reconnaissance strategy.
Exploiting command injection through Ruby string interpolation in a Rails application to achieve RCE via DNS exfiltration.
Comparing Amass, DNSX, and PureDNS for DNS resolution accuracy and performance in bug bounty reconnaissance.
How trusting my instincts led to discovering a critical RCE that everyone else missed on a popular bug bounty program.
A complete Docker-based infrastructure for bug bounty hunting featuring Traefik, XSS-Catcher, Rengine, and more.
How I discovered my first RCE through basic reconnaissance and exploiting a known Java deserialization vulnerability in Adobe ColdFusion.
Exploiting a Server-Side Request Forgery vulnerability through WKHTMLTOPDF to access AWS metadata and local files.
Exploiting a blind Out-of-Band XXE vulnerability to exfiltrate sensitive data despite misleading error messages.
Implementing binary search in Go to efficiently search through a 550 million line file in seconds instead of hours.
No articles match this filter.