CVE-2025-25205
Auxiliary scanner module detecting a vulnerable Audiobookshelf instance.
View pull requestsSecurity research
Authorized penetration testing, CVE detection modules submitted to the Metasploit Framework, and peer-reviewed research. Everything here is lab-verified and benign — the goal is to prove a defense holds, not just to claim it does.
Open source
Auxiliary scanner modules authored and submitted to the Metasploit Framework (Rapid7).
Auxiliary scanner module detecting a vulnerable Audiobookshelf instance.
View pull requestsDetection for the Next.js middleware authorization bypass.
View pull requestsDetection for an unauthenticated SQL injection in LiteLLM.
View pull requestsField notes
An authorized, ten-round penetration test of MoodHaven Journal — 65+ targets, 41 confirmed-and-fixed vulnerabilities, and the bespoke tooling it took to prove the encryption actually holds.
ReadThe unrooted phone told us our encryption held. Root let us check whether we were telling ourselves the truth. We weren't, entirely — and that was the point.
ReadA weekend attacking my own encrypted journaling app. The only foothold I got was my own debug build, my standard MITM playbook failed completely, and figuring out why taught me the most.
ReadCrash-safe master-password rotation in a zero-knowledge journaling app: re-encrypting across two layers and two runtimes with a single atomic flip a kill -9 can't corrupt.
ReadPeer-reviewed
International Journal of Advanced Computer Science and Applications (IJACSA)