bmdyy/tudo 16 August 2024·1653 words·8 mins An OSWE-style source code review of the tudo web app, ending in a single all-in-one exploit script.
SSTI in ERPNext 12 2 January 2024·324 words·2 mins Server-side template injection in ERPNext 12 leading to RCE.
ATutor account take over using type juggling 1 January 2024·1138 words·6 mins Abusing PHP loose comparison in ATutor’s password reset flow to take over an arbitrary account.