$ whoami
0xGaphy
$ cat mission.txt
Offensive SecurityRed Team TradecraftSOC Awareness
Latest Writeups
View all →Change Somebody Else's Password, Why Don't You
A password-change endpoint that trusted the email in the request body instead of the session that sent it.
None of Your Business — Bypassing JWT Signature Validation
How a forgotten 'alg: none' code path turned a read-only audit token into full admin access.