/blog
Field notes
Research and security engineering notes.
Pinned / 01
From Search Results to Two CERT-In Recognitions
A restrained account of using indexed government-domain pages as reconnaissance leads, preserving evidence, and separating two CERT-In recognitions from unsupported conclusions.
- My Honeypot Dashboard Was Lying to Me for Two Weeks (and I Wrote It)16 min read
- From an Exposed Service to an Unresolved SQL Injection Lead6 min read
- Five Findings That Looked Small Until I Followed the State8 min read
- I Thought I Found a Subdomain Takeover. I Had Not.7 min read
- When Object Authorization and Output Encoding Fail Together8 min read
- The Invoice Number Changed. Did the Authorization Decision?6 min read
- How a Pirate "Free Netflix" App Smuggles Video Inside .jpg Files9 min read
- I Built a Honeypot Framework, Deployed It for 5 Days, and the Internet Showed Up With Malware and Opinions22 min read
- I Mass-Accepted SSH Logins for 48 Hours and Catalogued Everything That Walked In18 min read
- SSH Under Siege: 30 Days of Brute-Force Telemetry on an Exposed VM 🌐6 min read