Xpl0itZ3r0X·May 8When a Ping Becomes a Weapon: Exploiting Command Injection in Azure App ServiceIt didn’t look dangerous. Just a text box, a button, and a result. But underneath that clean UI was a door left wide open one that led…
Xpl0itZ3r0X·Mar 28The Silent Threat: Exploiting Azure Container Registries (ACR) from Access to ExecutionWhy Blindly Trusting Your Registry Is a Mistake Waiting to Happen
Xpl0itZ3r0X·Mar 16From XML to Root: A Deep Dive into Struts S2–052 DeserializationWhy blindly trusting object reconstruction is a recipe for disaster.
Xpl0itZ3r0X·Feb 27Beyond the Trigger: Uncovering SSRF in Azure FunctionsIn the modern cloud era, Azure Functions are hailed as the gold standard for agility. We write our code, push it to the cloud, and let…
Xpl0itZ3r0X·Feb 18The eWPTX Odyssey: Why Mastery is Built in the Labs, Not the SlidesIntroduction: The Illusion of “Knowing” Web SecurityA response icon3A response icon3
Xpl0itZ3r0X·Feb 6Nothing Looked Wrong Until Defender XDR Connected the DotsA normal day, a normal emailA response icon1A response icon1
Xpl0itZ3r0X·Jan 2Exploiting Misconfigured AWS S3 Buckets: A Practical GuideImagine starting a routine security assessment for a company’s cloud infrastructure. Everything looks fine at first no obvious…
Xpl0itZ3r0X·Nov 19, 2025Wiz Cloud Security Championship — Breaking the BarriersAzure-focused CTFs don’t show up every day, so when Challenge 3 of the Wiz Cloud Security Championship dropped, I knew it was going to be…
Xpl0itZ3r0X·Aug 31, 2025Docker Gone Wrong: Escaping a Container in Wiz Cloud Security ChampionshipContainers promise isolation a neat little sandbox where applications run safely, cut off from the host. But what if that boundary isn’t as…
Xpl0itZ3r0X·Aug 31, 2025My eJPT Journey: From BlackHat MEA to Becoming a Certified Penetration TesterGetting certified in cybersecurity has always felt like more than just collecting badges it’s about growth, building confidence, and…