DOSSIER: LZ-994 STATUS: ONLINE
SHORTCUT: [T] THEME / [/] SEARCH
[ABOUT ME]

Hi my name is Akinlabi pronounced (Hacking lah bee) Glad you're here. I break things for a living and then write about it: CMS internals, network perimeters, red teaming, and the humans who click the wrong link. Outside client work, I run a solo CVE hunting lab, mostly Joomla, Apache and its extension ecosystem (just kidding, nothing is truly safe from me). Pull the source apart, diff the patch, chain the primitive, ship a PoC. Pwn all the things. Document everything.

// 1. WHAT I DO

  • CMS / Source Driven Exploit Research : I perform source-code-driven security research across Java, Python, JavaScript, and PHP applications. My work focuses on finding exploitable weaknesses in web applications, APIs, CMS platforms, frameworks, plugins, and extension ecosystems. Extensive research has focused on Joomla widely deployed third-party components, including iCagenda, Balbooa Forms etc. The broader focus is on uncovering source-level vulnerabilities with practical security impact, including unauthenticated file upload, arbitrary file read, and remote code execution primitives in default or commonly deployed configurations.
  • Variant Analysis: For every patched CVE, diff the fix, enumerate missed call sites and sibling code paths, and hunt for the bug the vendor almost fixed. Findings only count when they survive dedup against NVD, GitHub, and the Joomla Security Tracker.
  • Offensive Security Consulting: Web and mobile application security testing (source review, OWASP Top 10, and OWASP Mobile Top 10), internal network penetration tests, lateral movement, and post-exploitation. Physical security assessments and social engineering, from pretexting to on-site entry testing. Perimeter device research.
  • Off Duty Hunting: Active in bug bounty programs and a regular CTF participant, including winning the Fugitive of Justice CTF during my CTI days. I also enjoy reverse engineering and low-level research, particularly working with x64 and ARM architectures through both static and dynamic analysis in Ghidra.

// 2. CVE RESEARCH & DISCLOSURE LOG (i have like 15 to upload, hang around)

[CVE-2026-48939 // PRE-AUTH RCE]

iCagenda (Joomla component) — Unauthenticated Remote Code Execution

Deterministic PoC · exploit + full writeup incoming

[CVE-2026-56291 // PRE-AUTH RCE]

Balbooa Forms (Joomla component) — Unauthenticated Remote Code Execution

Deterministic PoC · exploit + full writeup incoming

[EMBARGOED // COORDINATED DISCLOSURE]

Additional novel findings in commercial extensions and softwares are currently in coordinated disclosure with vendors. Root-cause analysis, PoCs, and detection guidance land on this page the day the patches ship. No details before then — that's the deal.

// 3. CVE METHOD

Every campaign runs the same gates. A finding is not a finding until all of them pass:

  • G1 — REPRO: 3/3 anonymous reproduction against the latest release, default install, zero preconditions. Vulnerable-version diffs are for root-causing only, never for validation.
  • G2 — NOVELTY: Dedup against NVD, GitHub, and the Security Tracker. Duplicates are documented and discarded.
  • G3 — WEAPONIZE: A deterministic, minimized PoC that proves impact — not a scanner output screenshot.
  • G4 — REPORT: Root cause, reproduction, and detection rules, packaged for the vendor and the CVE assigner.

Dead ends get logged with the same rigor as findings. The discard pile is part of the method.

// 4. THE LAB

  • CMS Bench: Self-hosted Joomla, WordPress, and Apache environments with pinned component versions and source trees for vulnerability research, patch diffing, and exploit replay.
  • Source-First Tooling: Custom tooling for extracting extension codebases, performing vulnerability-to-patch diffs, and developing target-specific replay, bypass, and fuzzing workflows..
  • RE Bench: Ghidra for static analysis, complemented by a lightweight x64/ARM dynamic debugging environment.
  • Consulting & Red Team Kit: Standard offsec tooling for web, mobile, and internal AD engagements, plus a physical/SE kit (pretext material, cloned badges, the usual) for on-site work.
  • CTF Rig: Nothing exotic, mostly the same source-first and RE tooling above, pointed at a scoreboard instead of a client.

// 5. OFF THE CLOCK

Gaming(MK1, The Finals and 1000 more games). Skate-boarding, Rubik Cubes, and 50 other things i obssess on for just a week.

// 6. CONTACT & COLLABORATION

Vendors, fellow researchers, CTF teams, bug bounty programs — signals welcome. Prefer encrypted mail for anything disclosure-sensitive.

Email: omoakin749@gmail.com
GitHub: github.com/lulztigre
Linkedin: Linkedin
Website: https://lulztigre.pw