Break it, Before They Do.
I specialize in offensive security — penetration testing, adversary simulation, web application exploitation, Active Directory exploitation, EDR & AV evasion, and building tooling for authorized engagements. Let's find the way in before it becomes someone else's story.
Open WebUI SSRF - Redirect-Based Validation Bypass (CVE-2026-45401)
SSRF in Open WebUI's web fetch: validate_url checks the original hostname but the loader follows redirects, letting a...
Open WebUI - Unauthenticated RAG Configuration Disclosure (CVE-2026-45397)
A single unauthenticated GET to /api/v1/retrieval/ leaks Open WebUI's full RAG pipeline config — chunk sizes, templat...
CTF - Time is but a Window
Writeup of the Time is but a Window binary exploitation CTF challenge
CTF - A Guilded Lily
Writeup of the A Guilded Lily binary exploitation CTF challenge
mRemoteNG-Crack
Offline password-recovery tool for mRemoteNG. Decrypts confCons.xml with the default key, or cracks a custom master password by dictionary attack (with a built-in hashcat-rule engine), then prints every stored credential. AES-256-GCM / PBKDF2-HMAC-SHA1.