INDEX / 02
Writing
Notes and write-ups, mostly on web application security.
- Note2 min read
Access control is the bug you will actually find
Injection gets the write-ups. Broken access control gets the incidents. Here is why it survives every framework, and how I look for it.
- access-control
- web-security
- methodology
- Note2 min read
The three JWT checks people skip
A signature that verifies is not the same as a token you should accept. Algorithm, audience, and the difference between decode and verify.
- jwt
- authentication
- web-security
- Research3 min read
Notes on running other people's code
What building HuntCode's sandbox taught me: the escape is rarely the first thing that breaks, and every performance shortcut is a reuse of something.
- docker
- architecture
- ctf
