馃憢 Welcome to r4bbithole!

  • This is my research, writeup and personal blog.
  • You’ll find here a wide variety of posts about results of Vulnerability Research, CTF Writeups, Hacking techniques I put together while working, Bug Bounties and even my personal thoughts and opinions.
  • This blog does not represent my employer. All views and opinions expressed here are my own.

PWNSECCTF 2024 - Jinja Mastery

A writeup for the Jinja Mastery challenge from PWNSECCTF 2024

November 16, 2024 路 4 min 路 r4bbithole blog

PWNSECCTF 2024 - Taco Shop

A writeup for the Taco Shop challenge from PWNSECCTF 2024

November 16, 2024 路 4 min 路 r4bbithole blog

TL-WR741 - Part I: Command injection vulnerability

An outline of a smaller vulnerability research project leading to the discovery of a command injection vulnerability in an older TP-Link router

August 5, 2023 路 11 min 路 r4bbithole blog

HTB Weather App - Perfect weather to surf

An easy WEB challenge from HackTheBox. A Unicode encoding fault in NodeJS leads to an SQLi via SSRF

June 2, 2022 路 7 min 路 r4bbithole blog

HTB Restaurant - ROP It Till You Make It

Restaurant is an easy PWN challenge on HackTheBox about exploiting ROP simple buffer to do ROP

May 27, 2022 路 8 min 路 r4bbithole blog

HTB Forge

Forge is a medium machine on HackTheBox mainly revolving around SSRF and LFI

January 3, 2022 路 11 min 路 r4bbithole blog