How a poke around Spur.us's authenticated dashboard led to a full GraphQL schema dump of their billing provider, a free subscription upgrade to Enterprise, and leaked Stripe secrets, all from client-side credentials.
Understanding a common configuration issue with Microsoft tenants.
Breaking down a security issue with the store.fun platform.
Using bit entropy pattern analysis to determine the actual subnet ranges of rotating IPv6 proxies.
Exploring Argon2 Proof of Work and WASM to build a Captcha.
An in-depth analysis of the Spur.us Monocle captcha system, exploring its architecture, browser fingerprinting techniques, and the IPv6 connectivity patterns that make it vulnerable to automation.
Utilizing the power of semantic cosine similarity with python to make a cat search engine.