Writeups

September 2026

The search box that gave up the whole database

A single unescaped parameter in a travel booking app's search page turned into five separate findings: full database exposure, remote code execution, stored credential theft, and a working exploit chain between all three. Here's what actually changes once each one gets fixed.

September 2026

The best finding in my investigation was the one that turned out to be nothing

Investigating a staged insider data theft, I built a table rating every finding as conclusive or merely indicative, based on how many independent evidence sources actually backed it up. The single most useful row in that table is the one that says a suspicious lead was actually benign.