SekaiCTF'24 htmlsandbox - Author Writeup
HTML parsing differentials are fun!
vulnerability research and ctf writeups
HTML parsing differentials are fun!
Research on how browsers encode & send cookies, how they are parsed by various web frameworks, and some bugs
Winning SECCON Finals, writeups, and some Tokyo pictures.
writeups for the challenges I wrote for dicectf 2023
abusing long http headers for cache probing
a bit of research on security of the shadow DOM
Thoughts on running UIUCTF21, competition decisions, and infrastructure writeup
chrome extensions are bad, use firefox
race condition + prototype pollution + SSRF via fetch() redirect
Error-Based XS Leak
Bypassing PyYAML filtering and getting a CVE (2020-14343)
Exploiting a chrome extension that allows you to debug binaries via RPC
Bypassing heavily filtered python code evaluation
Short list and collection of links to learn about vulns used in PHP CTF Challenges