Posts

2026
CVE-2026-33186: Bypassing gRPC-Go Authorization with a Missing Slash
2025
2025 Wrapped
Some thoughts around Django SQL Injection CVE-2025-64459
Claude Code for Security Analysis: Introducing SecureFlow CLI to Hunt Security Vulnerabilities
Exploring fun parts of Neural Network
Rethinking MCP or Tool Calling Through Permission Based System
Static Analysis Isn't Enough: Understanding Library Interactions for Effective Data Flow Tracking
Lessons from Building Sherlock: Automating Security Code Reviews with Sourcegraph
LLM-Powered Security Reviews: Insights and Challenges
How I Use AI to Streamline/Assist My Work
2024
2024 Wrapped
Books I read in 2024
CodeQL: Eindhoven Quantifier Notation
Sherlock: Automate security code reviews with Cody AI
Defining Boundaries & Sinks for Inter-procedural Source Sink Analysis - Part 3
Deep dive on Android Java / Kotlin Deserialization Code Execution with Semgrep Detection
2023
2023 Wrap - Year in Review
Building Inter-procedural Source Sink Analysis from Scratch - Part 2
Building A Simple Source-Sink Analysis in Java from Scratch - Part 1
From ArcGIS to Mapbox: How Cody AI Made My Web App Shine
Building A Simple OpenAI Powered Personal Assistant
Heap Two Writeup - Exploit Education Lab Exercise
Heap One Writeup - Exploit Education Lab Exercise
Heap Zero Writeup - Exploit Education Lab Exercise
Format Four Writeup - Exploit Education Lab Exercise
Format Three Writeup - Exploit Education Lab Exercise
Format Two Writeup - Exploit Education Lab Exercise
Format One Writeup - Exploit Education Lab Exercise
CVE-2023-23397 - Zero Click Net-NTLMv2 Credential Hash Leak on Outlook Client
HackTheBox Active Writeup - Active Directory - OSCP Practice
Format Zero Writeup - Exploit Education Lab Exercise
Stack Six Writeup - Exploit Education Lab Exercise
HackTheBox Jerry Writeup - OSCP Practice
HackTheBox OSCP Writeups - Shivasurya.me
HackTheBox Bashed Writeup - OSCP Practice List
Detecting Android WebView Vulnerable Configurations with Semgrep Rules - Part 1
Stack Five Writeup (Code Execution) - Exploit Education Lab Exercise
Stack Four Writeup - Exploit Education Lab Exercise
Stack Three Writeup - Exploit Education Lab Exercise
Stack Two Writeup - Exploit Education Lab Exercise
Stack One Writeup - Exploit Education Lab Exercise
Stack Zero Writeup - Exploit Education Lab Exercise
Exploit Education Lab Setup - Windows & MacOS
2022
Binary Search and Hidden Overflow 🪲
Detecting Android Content Provider APIs with Semgrep Rules
2020
Cross-Site Scripting attack on Leetcode
Securing an ExpressJS server - Part 1