// Write-ups03 logs
Write-ups
Practical & reproducible technical work — step-by-step digital lab notes detailing CTF walkthroughs, CVE/vulnerability analysis, malware reverse engineering, and custom security tooling breakdowns.
>
Domain Difficulty - [TARGET]
- Real World
- [SEVERITY]
- high
- [CLASS]
- Malware & RE
Static-first analysis of a staged Windows loader — where the second stage is decrypted, how its key is derived, and what the import stubs give away.
- [TARGET]
- HackerOne
- [SEVERITY]
- critical
- [CLASS]
- Vuln & CVE
The object reference was only half of it. This follows the OAuth binding that trusted a client-supplied identifier, and the full takeover it allowed.
- [TARGET]
- HackTheBox
- [DIFFICULTY]
- Easy
- [CLASS]
- CTF & Labs
How an unauthenticated request-basket service reaches an internal Maltrail instance, and why the loopback restriction never applied to it at all.
[!] No matching intelligence logs found