Research
How the bugs
actually worked.
Technical case studies from real security research. Some targets are intentionally anonymized; the mechanisms, reasoning, and defensive lessons are preserved.
When localhost becomes a remote attack surface
An unauthenticated local WebSocket, a project-relative file write, and an auto-loaded plugin combined into one-click host code execution.
How an exported Android activity leaked a live session
A permissionless peer app supplied one serialized object and made a popular Indian food delivery app send its authenticated headers off-domain.
Two requests from backup file to database-superuser RCE
A restore routine treated CSV rows as SQL, while a pre-setup API exposed the entire path without authentication.
The redirect that disclosed a server's master key
A harmless-looking onboarding redirect exposed a long-lived cryptographic secret and opened a trusted device channel.