~/0xGaphy

$ whoami

0xGaphy

$ cat mission.txt

 

Offensive SecurityRed Team TradecraftSOC Awareness

Latest Writeups

View all →

[2026-08-23]::Web App Pentest::4 min read

Change Somebody Else's Password, Why Don't You

A password-change endpoint that trusted the email in the request body instead of the session that sent it.

Broken Access ControlIDORAuthenticationAPI SecurityWriteup

[2026-08-23]::Web App Pentest::5 min read

None of Your Business — Bypassing JWT Signature Validation

How a forgotten 'alg: none' code path turned a read-only audit token into full admin access.

JWTAuthentication BypassAPI SecurityPrivilege EscalationWriteup