Security tooling, experiments, and CTF writeups from HexCipher Security.
Abusing __defineSetter__ to leak a Fastify app's flag function through Node's error handler, then bypassing a WAF with JSON unicode escapes to land it in production.
Chaining AES-CBC bit-flipping into a blind SQL injection to log in as admin, then abusing a broken upload manifest check to get a webshell and read the flag.
Flipping bits in an AES-CBC IV to rewrite a decrypted filename, then brute-forcing a 2-byte HMAC gap to read an arbitrary file off the server.
Need help with security testing?
CONTACT US →