Github
Linkedin
Instagram
An exploration of the security risks that emerge when using AI coding agents to build full-stack applications.
A review of The Web Application Hacker's Handbook - the 800-page classic that shaped web security testing methodology.
An exploration of the limitations of Burp Suite's Active Scanner for XSS, and how to close the gap with manual testing.
A review of Vickie Li's Bug Bounty Bootcamp - a fantastic introduction to web testing for bug hunters and penetration testers alike.
A deep dive into Client-Side Prototype Pollution, how to detect it, and how to remediate it.
A deep dive into the postMessage API, its vulnerabilities, and how to use it securely.
A structured methodology for testing web applications for Cross-Site Scripting (XSS).
A deep dive into JWT Algorithm Confusion Attacks, explaining how they work and how to prevent them.
A tutorial on how to quickly build web app labs using docker and google gemini's CLI tool.
A deep dive into the web application infrastructure.
Why am I writing a blog and what will it be about?
No posts found matching your criteria.