Notes and write-ups, mostly on web application security.
What building HuntCode's sandbox taught me: the escape is rarely the first thing that breaks, and every performance shortcut is a reuse of something.