Writings
Technical writeups on engineering, web exploitation, and security research.
2026
Forging service_role From an Anon Key: Chaining Two Supabase Bugs Into a CVSS 10.0 RLS Bypass
supabase postgrest jwt
14 min read
01
Three Unauthenticated Ways to Introspect a Supabase Database Schema
supabase postgrest graphql
10 min read
02
2024
SDCTF 2024: SNOWfall - ServiceNow Prototype Pollution
sdctf-2024 web-security prototype-pollution
7 min read
03
SDCTF 2024: fancy_text_viewer - DOMPurify Bypass via CSS Injection
sdctf-2024 web-security dompurify
11 min read
04
SDCTF 2024: Blackjack Card Counting and Python 3.11 Bytecode Cache Exploitation
sdctf-2024 python bytecode
14 min read
05
LACTF 2024: ctf-wiki - CSP Bypass via Cookieless Iframe
web-security xss csp-bypass
5 min read
06
2023
NewportBlakeCTF 2023: sudoku-revenge - Idempotent Latin Squares
combinatorics latin-squares mathematics
5 min read
07
CryptoCTF 2023: Bertrand - Breaking Image Encryption with Hilbert Curves and Z3
cryptography z3-solver hilbert-curves
12 min read
08