How Hotel Wi-Fi Broke My Tailscale Peer Relay
How to setup Tailscale peer relays to listen on multiple ports.
Personal blog, focused on information security. AWS, Web apps, offensive techniques, and more.
How to setup Tailscale peer relays to listen on multiple ports.
Public disclosure of a vulnerability in AWS Amplify which exposed IAM roles associated with Amplify projects to be assumed by anyone in the world.
Writeup for two minor cross-tenant vulnerabilities I found in AWS App Runner.
Writeup for a technique I found to leak an AWS account ID from an Amplify app.
An introduction to AWS API protocols and how they work.
Datadog: Technical analysis of a confused deputy vulnerability I found in AWS AppSync.
Datadog: A technical analysis of the OpenSSL punycode vulnerability.
Revisiting and building on the original Lambda persistence technique.
Writeup for a cross-site scripting bug I found in the AWS Console.
Research on post-exploitation techniques against SSM Agent abusing send-command and start-session.
Writeup for a bug I discovered in the AWS API that would allow you to enumerate certain permissions for a role without logging to CloudTrail.
Tunnel out of restricted security groups by abusing connection tracking.
Some research I did on abusing GitLab Runners to steal information by emulating a runner's behavior.
Writeup for CVE-2020-11108 covering how I found the vulnerability and how it can be exploited for fun/profit.
Demonstrating how to exploit deserialization attacks in Python 2/3
A guide on how to intercept Linux CLI tool traffic with Burp Suite
A guide to bypass the GuardDuty PenTest Finding Type
A guide on how to steal IAM role keys and use them without being detected
An introduction to IDOR attacks
An in depth overview of the Content Security Policy header
Some advice based on my experience with Angular Universal
My thoughts and experiences with the OSCP