Security researcher focused on web exploitation and CTF challenges. I spend my time crafting payloads, building exploit PoCs, and digging into web application vulnerabilities.
- Build offensive tooling: SSTI-Exploit (Flask/Jinja2 SSTI to RCE) and Lepton7-Exploit (LeptonCMS 7.0.0 authenticated RCE)
- CVE-2025-6019: local privilege-escalation PoC with automated exploit scripts
- On the defensive side: phishion, a full-stack anti-phishing platform (Flask + React)
- Into pentest tooling (sqlmap, John the Ripper, PayloadsAllTheThings)
- Also build side projects: Task-Reminder, Notepad, Personal-Cloud, KiniBusApps
