DOSSIER: LZ-994 CLEARANCE: LEVEL-4 // TOP SECRET UTC: --:--:--
SHORTCUT: [T] THEME / [/] SEARCH
DOSSIER // CLASSIFIED OPERATIVE RECORD LZ-994-ALPHA

AKINLABI "[LULZTIGRE]"

๐Ÿ”Š PRONUNCIATION: "HACKING-LAH-BEE" // HEAD OF RED TEAM & FORENSICS OPS

"I break complex systems for a living, reverse-engineer proprietary binaries, and engineer weaponized zero-day exploit chains across CMS architectures, enterprise runtimes, and hardened network perimeters. Outside client operations, I run an autonomous CVE research lab dissecting software ecosystems, diffing vendor patches, and chaining low-level primitives into deterministic Proof-of-Concepts. Pull the source apart. Diff the patch. Chain the primitive. Ship the PoC. Document everything."

15+ CVE DISCLOSURES
10.0 MAX CVSS CRITICAL
100% CLEANROOM REPRO
5x OFFSEC CREDS
CHASSIS: PHANTOM-HUD-994 ACTIVE_SCAN
LZ-994
RADAR_TARGET: 3 VERIFIED // 15 PIPELINE
KERNEL_STATUS: SE_LINUX_ENFORCING
OP_DISCIPLINE: 0-DAY EXPLOIT ENG.
DEPLOY_ZONE: LAGOS // GLOBAL (REMOTE)
[01] TACTICAL DIRECTIVES

// 1. WHAT I DO // OPERATIONAL DIRECTIVES

Four primary disciplines define my daily operational cycle: whitebox vulnerability research, automated AST variant analysis, enterprise adversary simulation, and low-level binary dissection.

WHITEBOX // SOURCE AUDIT 0x01

CMS & Source Driven Exploit Research

Deep source-code auditing across Java, Python, JavaScript, and PHP runtimes. Targeting high-value flaws in CMS platforms, web APIs, frameworks, and third-party plugin ecosystems. Extensive focus on widely-deployed Joomla extensions (including Balbooa Forms and iCagenda) uncovering pre-auth remote code execution (RCE), unauthenticated arbitrary file uploads, file reads, and dangerous shortcode eval primitives.

JAVA / PHP / PYTHON AST UNAUTH RCE SHORTCODE EVAL() DESERIALIZATION
RESEARCH // AST DIFFING 0x02

Variant Analysis & Patch Archaeology

For every vendor patch released, I deconstruct the git commit history, diff the syntax trees, and enumerate missed call sites across sibling controllers. When vendors fix one instance of a bug class, they frequently overlook sibling functions. Findings only count toward the ledger once they survive rigorous dedup against NVD, GitHub Advisories, and the Joomla Security Tracker.

COMMIT AUTOPSY MISSED SINK SITES SIBLING CODE PATHS DEDUP GATES
ADVERSARY // EMULATION 0x03

Offensive Security Consulting & Red Teaming

Comprehensive adversary emulation: web and mobile security audits (OWASP Top 10 / Mobile Top 10), internal Active Directory compromise, lateral movement, Kerberos ticket abuse, and post-exploitation. Full-scope physical security assessments and social engineeringโ€”from pretext crafting to on-site covert badge cloning and physical perimeter ingress.

ACTIVE DIRECTORY LATERAL MOVEMENT BADGE CLONING PHYSICAL ENTRY
LOW-LEVEL // RE & HUNTING 0x04

Binary RE & Off-Duty CTF Dominance

Competitive CTF operator and active bug bounty hunter. Champion of the Fugitive of Justice CTF during my CTI operations tenure. Low-level systems research in Ghidra dissecting x64 and ARM assembly, dynamic process instrumentation via Frida, and static struct recovery on embedded firmware targets.

GHIDRA DECOMP x64 / ARMv7/v8 CTF CHAMPION BOUNTY HUNTING
NODE: LZ-994 // ARSENAL REGISTRY

// 2. TECHNICAL SKILLS & ARSENAL

Weaponized research tooling, low-level architecture proficiencies, and offensive capabilities in active rotation. Filter the matrix or select an operational subsystem below:

ACTIVE_SUBSYSTEM PRIMARY LANGUAGES & RUNTIMES
SECURITY_PROFILE Target environments, exploit scripting engines, and low-level architectures.
DEPLOYED_MODULES [7 CAPABILITIES]
SYSTEMS // NATIVE 0x01

C

Memory corruption & exploit development

ARCH // AMD64 0x02

x64 Assembly

ROP chains, shellcode & stack pivoting

ARCH // AARCH64 0x03

ARM Assembly

ARMv7/ARMv8 reversing & perimeter devices

SCRIPT // OFFSEC 0x04

Python

PoC weaponization, parsers & custom fuzzers

ENTERPRISE // JVM 0x05

Java

Deserialization gadgets & enterprise audits

AUTOMATION // SCRIPT 0x06

Ruby

Exploit prototyping, C2 scripting & protocol fuzzing

CLIENT // ENGINE 0x07

Javascript

DOM XSS, prototype pollution & Node.js

[03] VULNERABILITY REGISTRY

// 3. CVE RESEARCH & DISCLOSURE LOG

Documented novel zero-days and coordinated vulnerability disclosures. Findings are validated with deterministic 3/3 cleanroom reproduction, minimal PoC payloads, and verified vendor remediation:

PIPELINE: 15+ DISCLOSURES QUEUED
CVE: 2026-67364 โ†— PRE-AUTH PHP CODE INJECTION VIA EVAL()
CVSS 4.0 // 10.0 CRITICAL
TARGET: Balbooa Forms (Joomla Component) < 2.4.3.2

The form's optional custom-PHP post-submission handler executes dynamically via server-side eval(). The [URL parameter = X] shortcode token is substituted directly with the raw, unescaped value of an incoming HTTP query parameter, enabling an unauthenticated attacker to inject arbitrary PHP payloads that execute immediately under webserver privileges. The application's CSRF token is disclosed anonymously via a separate unauthenticated task endpoint, completely bypassing token protection.

PRIMITIVE: UNAUTH RCE VECTOR: [URL PARAM = X] EVAL() BYPASS: ANONYMOUS CSRF DISCLOSURE STATUS: VENDOR PATCHED
CVE: 2026-67363 โ†— PRE-AUTH PAYMENT AMOUNT TAMPERING
CVSS 4.0 // 7.7 HIGH
TARGET: Balbooa Forms (Joomla Component) < 2.4.3.2

The stripeCharges and payAuthorize payment controller endpoints accept transaction totals directly from an untrusted client-controlled HTTP request parameter, forwarding the manipulated sum to the payment gateway without recalculating it from configured database product rates. Neither endpoint enforces user authentication or CSRF tokens. An unauthenticated attacker can purchase any priced product catalog for an arbitrary amount (e.g. $0.01), and can forge arbitrary line items, quantities, and shipping charges.

PRIMITIVE: PAYMENT INTEGRITY BYPASS VECTOR: CLIENT PRICE FORGERY ($0.01) ENDPOINTS: stripeCharges / payAuthorize STATUS: VENDOR PATCHED
CVE: 2026-75948 โ†— AUTHENTICATED STORED CROSS-SITE SCRIPTING (XSS)
CVSS 4.0 // 8.6 HIGH
TARGET: iCagenda (Joomla Component) 4.0.8โ€“4.0.12

The frontend "Submit an Event" submission controller stores the image and file input fields as raw strings into the database without output-side HTML-attribute context escaping. When administrators review submitted event calendars or render public schedules, the injected payload triggers arbitrary JavaScript execution within privileged administrative sessions, permitting session theft and administrative action forgery.

PRIMITIVE: STORED SCRIPT INJECTION VECTOR: RAW ATTRIBUTE INJECTION SINK: EVENT SUBMISSION CONTROLLER STATUS: VENDOR PATCHED
[EMBARGOED // 15 NOVEL ZERO-DAYS IN COORDINATED DISCLOSURE PIPELINE] ๐Ÿ”’

Additional novel findings across widely deployed commercial extensions, enterprise web platforms, and server runtimes are currently held under responsible coordinated disclosure agreements with vendor engineering teams. Root-cause vulnerability dissections, deterministic reproduction harnesses, and intrusion detection signatures land on this ledger the moment official vendor patches ship. Zero leaks prior to fix availability.

[04] RESEARCH PROTOCOL

// 4. CVE RESEARCH METHODOLOGY

Every campaign runs through four strict verification gates. A finding is never published, submitted to a CNA, or claimed as a vulnerability until it clears every single gate:

G1 DETERMINISTIC

3/3 Cleanroom Reproduction

Must reproduce 3 out of 3 times anonymously against the latest official release in a pristine, default installation with zero custom preconditions. Vulnerable-version diffs are strictly for root-causing and hypotheses, never for validation.

VERIFICATION: 100% REPRODUCIBLE
G2 CROSS-CHECK

Novelty & Variant Dedup

Exhaustive deduplication against the National Vulnerability Database (NVD), GitHub Advisory Database, vendor security bulletins, and security trackers. If a primitive matches an existing record or known duplicate, it is cataloged in the discard pile and discarded.

VERIFICATION: ZERO-COLLISION
G3 MINIMAL PoC

Deterministic Weaponization

Construct a deterministic, minimized Proof of Concept that conclusively proves operational security impact (arbitrary code execution, unauthorized data read, or state tampering). Scanner output screenshots are strictly rejected.

VERIFICATION: RAW SINGLE-REQUEST PoC
G4 PACKAGING

Advisory Packaging & Coordinated Disclosure

Complete technical package delivered to vendor security contacts and assigned CNAs: root cause analysis, code diffs, CVSS 4.0 vector computation, reproduction test harness, and vendor patch recommendations.

VERIFICATION: ISO/IEC 29147 COMPLIANT
[05] SYSTEM TESTBED

// 5. THE RESEARCH LAB INFRASTRUCTURE

Autonomous, air-gapped virtualization testbeds, AST tokenizers, and low-level dynamic debugging workstations configured for high-throughput vulnerability analysis:

NODE-01 // CMS BENCH 10.99.4.11

Self-Hosted CMS Ecosystem Cluster

Self-hosted Joomla, WordPress, Apache, and Nginx environments with pinned component versions, git commit branches, and live database snapshots for rapid rollback, patch diffing, and zero-day exploit replay.

DOCKER-ISOLATED PHP 7.4 - 8.4 MATRIX MARIADB SNAPSHOTS
NODE-02 // SOURCE-FIRST PIPELINE 10.99.4.12

AST Parsers & Vulnerability Diffing Harnesses

Bespoke Python tokenizers and AST analyzers for bulk extension extraction, automated vulnerability-to-patch git diffing, parameter sink tracking, and target-specific replay and grammar fuzzing workflows.

AST SINK TRACKING CUSTOM FUZZERS GIT DIFF AUTOMATION
NODE-03 // RE WORKSTATION 10.99.4.13

Low-Level Static & Dynamic RE Rig

Ghidra headless cluster for batch static decompilation, paired with a lightweight x64 and ARMv7/ARMv8 dynamic debugging environment (GDB/GEF, Frida runtime instrumentation, QEMU user emulation).

GHIDRA DECOMP x64 / ARM EMULATION FRIDA HOOKS
NODE-04 // RED TEAM FIELD KIT 10.99.4.14

Enterprise Consulting & Physical SE Kit

Battle-tested offensive tooling for web, mobile, and internal Active Directory engagements. Includes full physical security kit: Proxmark3 RDV4 RFID/NFC cloner, pretext dossiers, and covert drop boxes.

PROXMARK3 RDV4 AD BLOODHOUND COVERT HARDWARE
NODE-05 // CTF RIG 10.99.4.15

Competitive CTF & Speed Triage Rig

Optimized for rapid challenge triage: pwntools, custom heap visualizers, automated deobfuscators, and scriptable protocol decoders pointed at scoreboards rather than client infrastructure.

PWNTOOLS HEAP SOLVERS FUGITIVE OF JUSTICE CTF
[06] LEISURE TELEMETRY

// 6. OFF THE CLOCK // HYPERFIXATIONS

When disconnected from target terminals, cognitive bandwidth shifts to competitive reflexes, physical momentum, and algorithmic puzzle solving:

๐ŸŽฎ

Competitive Gaming Rig

Mortal Kombat 1 (high-frame-data execution), The Finals, and a library of 1,000+ titles. Testing mechanical reflexes and strategic timing under competitive pressure.

๐Ÿ›น

Street Skateboarding

Carving street lines and working on board control. The ultimate analog reset for clearing mental cache between deep disassembly marathons.

๐Ÿงฉ

Rubik's Cubes & Speedcubing

Algorithmic pattern recognition: CFOP methods on 3x3, 4x4, and non-Euclidean polyhedra. Muscle-memory execution of permutation algorithms.

โšก

Rotating 7-Day Obsessions

Fifty other distinct disciplines hyperfocused on for exactly seven days with maniacal obsession before rotating back into research rotation.

[07] COMMUNICATION LINK

// 7. CONTACT & SECURE TRANSMISSION

Signals welcome from vendors, fellow vulnerability researchers, CTF teammates, bug bounty triagers, and offensive security clients. Use encrypted channels for any disclosure-sensitive communication:

PRIMARY DISCLOSURE MAIL omoakin749@gmail.com
SOURCE REPOSITORIES // GITHUB github.com/lulztigre
OPEN REPOS โ†—
PROFESSIONAL CONSULTING // LINKEDIN linkedin.com/in/akinlabi-o-400893183
CONNECT โ†—
OFFICIAL DOMAIN // BLAAAG https://lulztigre.pw
ORIGIN ROOT
๐Ÿ” PGP PUBLIC ENCRYPTION KEY [RSA 4096-BIT]
RAW KEY (.ASC)