// 1. WHAT I DO // OPERATIONAL DIRECTIVES
Four primary disciplines define my daily operational cycle: whitebox vulnerability research, automated AST variant analysis, enterprise adversary simulation, and low-level binary dissection.
CMS & Source Driven Exploit Research
Deep source-code auditing across Java, Python, JavaScript, and PHP runtimes. Targeting high-value flaws in CMS platforms, web APIs, frameworks, and third-party plugin ecosystems. Extensive focus on widely-deployed Joomla extensions (including Balbooa Forms and iCagenda) uncovering pre-auth remote code execution (RCE), unauthenticated arbitrary file uploads, file reads, and dangerous shortcode eval primitives.
Variant Analysis & Patch Archaeology
For every vendor patch released, I deconstruct the git commit history, diff the syntax trees, and enumerate missed call sites across sibling controllers. When vendors fix one instance of a bug class, they frequently overlook sibling functions. Findings only count toward the ledger once they survive rigorous dedup against NVD, GitHub Advisories, and the Joomla Security Tracker.
Offensive Security Consulting & Red Teaming
Comprehensive adversary emulation: web and mobile security audits (OWASP Top 10 / Mobile Top 10), internal Active Directory compromise, lateral movement, Kerberos ticket abuse, and post-exploitation. Full-scope physical security assessments and social engineeringโfrom pretext crafting to on-site covert badge cloning and physical perimeter ingress.
Binary RE & Off-Duty CTF Dominance
Competitive CTF operator and active bug bounty hunter. Champion of the Fugitive of Justice CTF during my CTI operations tenure. Low-level systems research in Ghidra dissecting x64 and ARM assembly, dynamic process instrumentation via Frida, and static struct recovery on embedded firmware targets.
// 2. TECHNICAL SKILLS & ARSENAL
Weaponized research tooling, low-level architecture proficiencies, and offensive capabilities in active rotation. Filter the matrix or select an operational subsystem below:
// 3. CVE RESEARCH & DISCLOSURE LOG
The form's optional custom-PHP post-submission handler executes dynamically via server-side eval(). The [URL parameter = X] shortcode token is substituted directly with the raw, unescaped value of an incoming HTTP query parameter, enabling an unauthenticated attacker to inject arbitrary PHP payloads that execute immediately under webserver privileges. The application's CSRF token is disclosed anonymously via a separate unauthenticated task endpoint, completely bypassing token protection.
The stripeCharges and payAuthorize payment controller endpoints accept transaction totals directly from an untrusted client-controlled HTTP request parameter, forwarding the manipulated sum to the payment gateway without recalculating it from configured database product rates. Neither endpoint enforces user authentication or CSRF tokens. An unauthenticated attacker can purchase any priced product catalog for an arbitrary amount (e.g. $0.01), and can forge arbitrary line items, quantities, and shipping charges.
The frontend "Submit an Event" submission controller stores the image and file input fields as raw strings into the database without output-side HTML-attribute context escaping. When administrators review submitted event calendars or render public schedules, the injected payload triggers arbitrary JavaScript execution within privileged administrative sessions, permitting session theft and administrative action forgery.
// 4. CVE RESEARCH METHODOLOGY
Every campaign runs through four strict verification gates. A finding is never published, submitted to a CNA, or claimed as a vulnerability until it clears every single gate:
3/3 Cleanroom Reproduction
Must reproduce 3 out of 3 times anonymously against the latest official release in a pristine, default installation with zero custom preconditions. Vulnerable-version diffs are strictly for root-causing and hypotheses, never for validation.
Novelty & Variant Dedup
Exhaustive deduplication against the National Vulnerability Database (NVD), GitHub Advisory Database, vendor security bulletins, and security trackers. If a primitive matches an existing record or known duplicate, it is cataloged in the discard pile and discarded.
Deterministic Weaponization
Construct a deterministic, minimized Proof of Concept that conclusively proves operational security impact (arbitrary code execution, unauthorized data read, or state tampering). Scanner output screenshots are strictly rejected.
Advisory Packaging & Coordinated Disclosure
Complete technical package delivered to vendor security contacts and assigned CNAs: root cause analysis, code diffs, CVSS 4.0 vector computation, reproduction test harness, and vendor patch recommendations.
// 5. THE RESEARCH LAB INFRASTRUCTURE
Autonomous, air-gapped virtualization testbeds, AST tokenizers, and low-level dynamic debugging workstations configured for high-throughput vulnerability analysis:
Self-Hosted CMS Ecosystem Cluster
Self-hosted Joomla, WordPress, Apache, and Nginx environments with pinned component versions, git commit branches, and live database snapshots for rapid rollback, patch diffing, and zero-day exploit replay.
AST Parsers & Vulnerability Diffing Harnesses
Bespoke Python tokenizers and AST analyzers for bulk extension extraction, automated vulnerability-to-patch git diffing, parameter sink tracking, and target-specific replay and grammar fuzzing workflows.
Low-Level Static & Dynamic RE Rig
Ghidra headless cluster for batch static decompilation, paired with a lightweight x64 and ARMv7/ARMv8 dynamic debugging environment (GDB/GEF, Frida runtime instrumentation, QEMU user emulation).
Enterprise Consulting & Physical SE Kit
Battle-tested offensive tooling for web, mobile, and internal Active Directory engagements. Includes full physical security kit: Proxmark3 RDV4 RFID/NFC cloner, pretext dossiers, and covert drop boxes.
Competitive CTF & Speed Triage Rig
Optimized for rapid challenge triage: pwntools, custom heap visualizers, automated deobfuscators, and scriptable protocol decoders pointed at scoreboards rather than client infrastructure.
// 6. OFF THE CLOCK // HYPERFIXATIONS
When disconnected from target terminals, cognitive bandwidth shifts to competitive reflexes, physical momentum, and algorithmic puzzle solving:
Competitive Gaming Rig
Mortal Kombat 1 (high-frame-data execution), The Finals, and a library of 1,000+ titles. Testing mechanical reflexes and strategic timing under competitive pressure.
Street Skateboarding
Carving street lines and working on board control. The ultimate analog reset for clearing mental cache between deep disassembly marathons.
Rubik's Cubes & Speedcubing
Algorithmic pattern recognition: CFOP methods on 3x3, 4x4, and non-Euclidean polyhedra. Muscle-memory execution of permutation algorithms.
Rotating 7-Day Obsessions
Fifty other distinct disciplines hyperfocused on for exactly seven days with maniacal obsession before rotating back into research rotation.
// 7. CONTACT & SECURE TRANSMISSION
Signals welcome from vendors, fellow vulnerability researchers, CTF teammates, bug bounty triagers, and offensive security clients. Use encrypted channels for any disclosure-sensitive communication:
2C36 6F2D 98D5 0400 26B2 8F83 8586 899D 1C00 5542
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: Kleopatra Neo
Comment: https://kleopatra.app
xsFNBGq6KYABEAC5rxLqBftjw3QOXyt813IAZ1Upllpkxy56ql61jRbUp8EQ
SKp5GwZBvYzR7vSSiWlNXT+ysnhdzq1pqCGwJ3TAAR9GWLAw+vsfB8i+nIdH
RzF4eyaOMkJ89YBj8MhLehOSvKC9mzfJb8W+nOAvPxabpUkB9FXYpEj4/ZkA
PWeAOBhRVNWKUnaI+sVKDu7UxMgyQg7g7lP3ARirI0+QUeWcrU7M2LNOJdDW
ybd0bCMXyTnsgReeIrLWFmhY/4OScHyeUZNaujYBXbNHZfyzhY0kQoCUQR1+
7W/c0LhsSaGT6D8JLER7urml1keqBFNgcvnXk2Ii8A5o1rUBoriGLHS9tD7t
wbvVxqvvAjL/gop+/P8ooLj3+eLkvlfGCY4nhMd6h5HOQp7i1ClrDpIIq5b5
Nysn199/gD9mMA1DriHylmCRyWojROYzfxDB9ripDGgiocN1efTUr5IhkOC3
85peOmHrSfce+jW9n04voEKxVTNt15MSgaTAF4xZfKgKcxpsdKPTUxSKYD4g
0Wirt9AVXro1sdGVcHp0pNyY33ghWxURGDVJYtI4amdxjJHn437rq4H0QvlR
v+bid0I+i5TlV+K65B46aAgddBWA6sW3LQHKsZd4WoGHvCWL8hOM/IkhlkFL
mFxMuPRkYOLPmad7Rdmf4N+t/OumufB0dRTpGQARAQABzSdBa2lubGFiaSBP
bW9vZ3VuIDxvbW9ha2luNzQ5QGdtYWlsLmNvbT7CwYoEEAEIAD4Fgmq6KYAE
CwkHCAmQhYaJnRwAVUIDFQgKBBYAAgECGQECmwMCHgEWIQQsNm8tmNUEACay
j4OFhomdHABVQgAA1JkQAIjXcw80X5JXtUxNVmHndfEHqS1w7AWrySjPwO+Z
5tBnWGyVrrzXYXljcZM21s/FYVLYWu1ZgFqr7ChDEbwKS9svHX1TMItu3vB+
7ZdrjvqxsvWkL8L10hA9dkGVb5BM/dX7ZVAEwvvcIv+cAeGBZpy+xJzsUIXm
BVf2nemjgXA+Vfl7RzfAOnxcDVJe+CSHR4GGYPYJj9t51eZBtT/819EyW7IL
P4Q6KXCYXix8gKz+V5rpX5i2VjancA0bGpmtxq1bo4yEswUrj+gfLxedeUNX
SXt1wIr1P49l1SnFd9J5+lSovV9iZokt0/+Y0mQvN32qRKNmMoiqdKUxAgF5
B0nU+Dn3uMUtdT6f8b9NQNObTtih1mBwYikFKfTEtssIiNuZIVswnxAuNwoc
+N/b7c8HS6rTkqKpRHyqVnZj07HiJfOXlqweTe6M8oKUC+tcV5MDhHManVlo
m6sIkflNehMlDb/dz2T7WIBlW0TXu9V9QoyKNRzaXLcLRn9p+pKW1YOGBJjh
wMt/Spen9Dq9eOyfSj0ffSVHvyHFSTn5Y57Ukd0T48c7yi3j1Dn4TyOo5rYi
FRosvuoNmMo7m187WlGmX1fddDVXO0ZfwCRAgMnpakI69B0V18W6PAqxQTYM
PCen6PKPxkVYLZIxRJpp/6spq8mpePNy5Z6qgjw3v6bMzsFNBGq6KYABEACl
LQcsL3htz20GWJdLCDMYNp0PJ3zKyuRcveAenA9qLY9sIwsn+TqKIblr3mK5
fbVU3RsCkTIt+HMJGFAUm2nbIC4JcrJIqUS6DyO0TwQVPx4zwYcU7gIeRWse
9cl7LZTvymWhVIf84XVX4O46TfwI0bEP+0kqzQpSTAbWEAt+Pv4qEggft+eC
b9D9H6hePc5SYi6Dlwyj+2z7dhB6pSwdGhmxkZcq38AgKATUZbmhucTbZgzJ
eXfeY4S1sAnCG6qoMmvUHtW4KTqtNy+fNafA+30DfgX1Xvhiqmbj+Jdou9vw
/Gb5YEzlzFm1EdSe3ggUV4b7XysdoPiZQsx70kPylIg91AWqN90Lp8omjWnB
ebnjkkgqGihWNwu+ITbcqwLWqtc9K7EjWS077Drn1N8ykyUI5RxoFyPah6p0
DtmuCpFUpCX+uqQ5VLaX65PpJxk8qL1zd5fdYx5rSC4/mY2xsm8KwGA69Vk5
qFoF3SyuUzdK1rGcmjEqqp5QY4zq1ncICEiXImo6CK/2uRTq0Zyhtde/U1Sa
2TGglISU0MxJYjKI8b1rk0ZtUkaLNfaXcj0BAM+U+CsNmSYFy7GXpNOrZF4D
B/UHmJZIfkXb7WPfyrRAKYiM6568pcOrPxMKehIvwJhr9cWpn9Epdh5ICbnT
xMAmA7ECiR9Ry62nsd/1pwARAQABwsF2BBgBCAAqBYJquimACZCFhomdHABV
QgKbDBYhBCw2by2Y1QQAJrKPg4WGiZ0cAFVCAACRDhAAtDwvdJYpIIG2qyqo
zn3u+zG2bcaLIGxQKBcP1ivmYv5Z4KLHIcgmKsbfng+prVYYM2cRj5SmMCq8
6/j2ep/uDJcd20208wtyf00BYH0S+e7ohjf15Lr+eUYhh4VlupuZulea5Tpm
TA3mbZdqGO0qtNNU0VwHc0cxw9RtBTBECWESvXWOhuFJBP4ZoN0stXAAuHjs
NRC/reZslu40ybXhKPeVc1vqXMGpyP/RMBaSAQ4FCvVKNdUOun1kdjCZNjTW
R28PSxmwsvG7ML0uQaPlV7gaZIMR6cQD7qcB/CGCAH0JatlfrjWFiKF1HwM+
NFfoe9Y+1kxKE197c20eANvILc2nHHrKqNYb1VjqfuqlwmHH6fDIuqU+AKLR
GHu24IjK9zlwP/bMVWWvLy/3bxmmE2YV3ydxT8ALWimh23E1ZLFoTblVlZ/2
FIJUuMXdd1lxdLtc5sxuo6o0zrItXD+Z7IIlhMeHXCFzdo86y94bEadC63af
gt/Muk7KdT6sAUlytOz9sVsshML8VMhMBDvY8mA/ucUAzLSZBJqTOcaSuMNl
8XA5zzhBmbTNcl27VfHliNt40AlfnleegGtPx7TUeAoX+3ctpy6FhRDvO8jB
sjnn8u8OqznjHNF23NJeOxEFXhcS8CY7DiyDRqSd3/3fzczBymNPlgO9Vilv
6b2GCtM=
=5Kj7
-----END PGP PUBLIC KEY BLOCK-----